PRIVACY

Privacy Policy

Your privacy matters. This page explains what data we collect, how it is used, and how it is protected.

Last updated: April 2025

Information We Collect

We collect the minimum data required to operate the platform:

  • Email address — used for OTP authentication and order notifications.
  • Display name / nickname — used on your profile and in the dashboard.
  • OAuth data (if signing in with Google) — name, email, avatar URL from your Google account.

How Your Data Is Used

Your data is used exclusively for:

  • Authenticating your identity via passwordless OTP or Google OAuth.
  • Associating purchases with your account and delivering licensed files.
  • Sending transactional emails (OTP codes, purchase confirmations).
  • Displaying your profile information in the dashboard.

Payment Data

We never see or store your card details. Payments are processed entirely by our certified gateways:

  • Paddle — handles cards (Visa, Mastercard) and PayPal. PCI DSS compliant.
  • NowPayments — handles cryptocurrency (BTC, ETH, USDT, and more).
  • We only receive a transaction reference ID and status — never full card data.

Data Storage & Security

Your data is stored securely on Supabase infrastructure:

  • All sessions use HTTPS. Auth tokens are stored in HTTP-only cookies — never in localStorage.
  • Row Level Security (RLS) ensures you can only access your own data.
  • Passwords do not exist on this platform — OTP codes expire after a single use.

Third-Party Services

We use the following trusted third-party services that may process your data under their own privacy policies: Supabase (database & authentication), Paddle (payments), NowPayments (crypto payments), Google OAuth (optional sign-in). We do not sell your data to advertisers or any third party.

Your Rights

You may request deletion of your account and associated personal data at any time via the dashboard settings. Upon deletion, your profile and purchase history are permanently removed from our systems. Note: transaction records may be retained by payment processors per their own legal requirements.