PRIVACY POLICY
TABLE OF CONTENTS
1. INFORMATION WE COLLECT
We collect information necessary to provide and improve our Service. This includes:
- Account Information: Username, email address, hashed password, and profile details provided during registration.
- Usage Data: API calls, license validations, session activity, feature usage, and interaction patterns with the platform.
- IP Addresses: Collected on every request for security, rate limiting, and abuse prevention. We process originating IPs from headers including X-Forwarded-For and CF-Connecting-IP.
- Hardware ID (HWID) Data: When your end users authenticate through our Service, hardware identifiers may be collected and stored for license enforcement purposes.
- Payment Information: Billing details processed securely through our payment partners. We do not store full credit card numbers on our servers.
- Application Metadata: Application names, settings, license key configurations, webhook URLs, and variable data you create within the platform.
2. HOW WE USE YOUR DATA
We use collected data for the following purposes:
- Providing, maintaining, and improving the Service's core functionality.
- Authenticating users and managing sessions.
- Processing license validations and enforcing hardware locks.
- Enforcing tier limits, rate limiting, and abuse prevention.
- Processing payments and managing subscriptions.
- Sending service-related notifications (security alerts, billing, updates).
- Generating anonymized, aggregate analytics to improve platform performance.
- Complying with legal obligations and responding to lawful requests.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
3. DATA STORAGE & ENCRYPTION
Your data is stored in Supabase (PostgreSQL) databases hosted on secure, SOC 2-compliant infrastructure. Key security measures include:
- All data in transit is encrypted via TLS 1.2+ (HTTPS).
- Sensitive data at rest is encrypted using AES-256 encryption.
- Passwords are hashed using industry-standard bcrypt algorithms.
- Database access is restricted via role-based access controls (Row Level Security).
- Encrypted file delivery uses AES-256-CBC with per-file keys.
File-based caching is used for performance optimization (rate limiting, session data) and is stored in a secured, non-publicly accessible directory on our servers.
4. THIRD-PARTY SERVICES
We integrate with the following third-party services to deliver our platform:
- Supabase — Primary database and backend infrastructure (PostgreSQL, PostgREST API, Authentication). Data is processed under Supabase's privacy policy and Data Processing Agreement.
- Payment Processors — Handle billing transactions. Card data never touches our servers directly.
- Cloudflare — CDN, DDoS protection, and DNS services. May collect anonymized traffic data.
- Analytics Providers — We may use privacy-respecting analytics to understand usage patterns.
We do not share your personal data with third parties except as described in this policy or as required by law.
5. COOKIES & TRACKING
We use minimal cookies and similar technologies:
- Session Cookies: Required to maintain your authenticated session across page loads. These are essential and cannot be disabled.
- CSRF Tokens: Stored to prevent cross-site request forgery attacks.
- Analytics Cookies: Optional, used to understand how users interact with our platform. These are anonymized.
We do not use advertising cookies or third-party tracking pixels. You can control cookie behavior through your browser settings.
6. DATA RETENTION
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained until account deletion is requested or the account is terminated.
- Usage Logs: Retained for up to 90 days for security and debugging, then automatically purged.
- Billing Records: Retained for a minimum of 7 years as required by financial regulations.
- License & HWID Data: Retained for the lifetime of the associated application, deleted when the application is removed.
Upon account deletion, we will remove or anonymize your personal data within 30 days, except where retention is required by law.
7. YOUR RIGHTS
Depending on your jurisdiction, you may have the following rights regarding your data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Export: Request an export of your data in a structured, machine-readable format (JSON/CSV).
- Objection: Object to processing of your data for specific purposes.
- Restriction: Request that we limit the processing of your data in certain circumstances.
To exercise any of these rights, contact us at [email protected]. We will respond to verifiable requests within 30 days.
8. SECURITY MEASURES
We implement comprehensive security measures to protect your data:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Two-factor authentication (2FA) available and required for administrative access.
- Row Level Security (RLS) on database tables to enforce data isolation.
- Rate limiting and IP-based abuse detection.
- Regular security audits and dependency updates.
- Strict access controls — only authorized personnel can access production systems.
While we strive to protect your data, no system is completely secure. We encourage you to use strong passwords and enable 2FA.
9. CHILDREN'S PRIVACY
Our Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we discover that a child under 18 has provided us with personal information, we will take steps to delete such information immediately.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].
10. INTERNATIONAL DATA TRANSFERS
Your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to such transfers.
We ensure that appropriate safeguards are in place, including:
- Using data processors that provide adequate levels of data protection.
- Implementing Standard Contractual Clauses (SCCs) where required.
- Ensuring data is processed only for the purposes for which it was collected.
QUESTIONS ABOUT YOUR PRIVACY?
Contact our Privacy team at [email protected]