Privacy Policy
Scope
This policy applies whenever personal information is collected, stored, or processed in connection with the service. It details how we handle data on web, mobile, and API channels. Continued use signifies acceptance of these terms. Please review it regularly.
Data Collected
We collect only the personal data needed for operation—email, user ID, IP address, device info, and usage logs. Collection occurs through user forms and automated logs. Sensitive personal data is never requested. Collection points clearly state their purpose.
Usage
Collected data is used to authenticate login, secure accounts, and troubleshoot issues. Anonymized insights help improve performance and inform new features. No personal data is sold or shared for marketing without consent. Any new data use will require opt‑in.
Cookies
Essential cookies ensure session security and core functionality. Analytics cookies are off by default and require opt‑in. Third‑party advertising cookies are not used without permission. Cookie preferences are manageable in your browser.
Security
Data in transit is encrypted using TLS. Data at rest is encrypted with industry‑standard algorithms. Internal access is governed by least‑privilege controls and multi‑factor authentication. Regular security assessments and audits uphold protection.
Retention
Data is retained only as long as necessary—typically 24 months from last user action. Thereafter it is deleted or anonymized. Backups are purged within 90 days post‑expiry. Retention policies are reviewed annually.
Rights
You may request access to, correction of, or deletion of your personal data at any time. We process valid requests within 30 days, subject to law. Data necessary for regulatory or legal obligations may be retained in anonymized form. Consent can be withdrawn for optional features.
Breach Notification
In a confirmed breach, affected users will receive notice within 72 hours of verification. Notifications include incident details, data categories affected, and next steps. Authorities will be notified as required. A post‑incident review will strengthen safeguards.
Anonymization
Personal identifiers are replaced with irreversible pseudonyms before analysis. Aggregated data sets contain no individual details. Anonymized data may be retained indefinitely for research. This approach protects privacy while enabling insights.
Third‑Parties
Data is shared only with essential third‑party service providers under strict agreements. Processors include hosting, payment, and email services. No data is shared with advertising networks without separate consent. All disclosures are logged.
Updates
This policy is reviewed yearly or on major changes. Material updates are communicated via email and in‑service notices 14 days before taking effect. Continued use implies acceptance. Previous versions remain accessible.