Data collected
- Account name, email address, password hash, verification state, and optional Google account identifier.
- Hashed session and API-key material; full API keys are displayed once and are not stored.
- Request counts, key identifiers, timestamps, route-level usage, security logs, and service errors.
- Cookie-free website page views, page paths, external referrer domains, campaign labels, device class, and a daily rotating visitor hash. Raw IP addresses and full user-agent strings are not stored for website analytics.
- Polar customer, order, and subscription identifiers plus verified webhook payloads.
- Transactional email delivery metadata when email is configured.
How data is used
Account data is used to authenticate users, issue keys, enforce plan limits, provide support, prevent abuse, reconcile billing, and operate the service. First-party website counts are used to understand traffic and improve pages; they are not used for advertising or sold.
Service providers
The planned production stack uses Hetzner for hosting, Polar for checkout and subscriptions, SendGrid for transactional email, and Google only when a user chooses Google sign-in. Final subprocessor locations and agreements must be recorded before launch.
Retention and security
- Expired sessions and one-time account tokens are removed by scheduled retention cleanup.
- Successfully processed webhook payloads are retained for a bounded reconciliation window, then removed.
- Raw website page-view events are removed on the configured short retention schedule. Daily visitor hashes rotate at the UTC date boundary.
- Application secrets stay in environment configuration and are excluded from version control.
- Passwords use bcrypt and API/session tokens are hashed at rest.
Your choices
A production privacy notice will explain how to request access, correction, export, or deletion and when records must be kept for tax, fraud, security, or legal obligations. A verified privacy contact is required before accounts are opened publicly.