Data processed
- Paddle customer, subscription, transaction, and price IDs; purchase email, currency, amount, billing interval, subscription state, refunds, and disputes. This site does not directly collect full payment-card details.
- A random installation ID, locally calculated SHA-256 binding hash, plan code, activation times, and refresh times. The raw operating-system installation identifier never leaves the device.
- A SHA-256 digest of the authorization code. A plaintext delivery copy exists only briefly for web and email fulfillment, is AES-GCM encrypted, and is retained for no more than 24 hours.
- Truncated hashes needed for recovery and security rate limits, plus information voluntarily sent to support.
Purposes and providers
Data is used to run the separate 30-day trial, verify recurring subscriptions, enforce per-plan device allowances, issue short-lived Ed25519 certificates, deliver and recover authorization, prevent abuse, and provide support. Paddle acts as Merchant of Record for payments, tax, and the customer portal. Cloudflare Workers, D1, and R2 host the site, state, and public installers. Resend sends authorization email.
Browser storage
localStorage retains language choice. sessionStorage temporarily holds a one-time delivery-session secret and removes it after claim or session end. Paddle Checkout may use storage required for payment and fraud prevention. This site does not use advertising tracking.
Retention, security, and rights
Delivery ciphertext remains at most 24 hours; recovery rate-limit records 24 hours; inactive trials and installation bindings 24 months; security logs 30 days; and subscription, transaction, license, and necessary audit records seven years after entitlement ends. Certificates use Ed25519 signatures and production secrets are held as Cloudflare secrets. Applicable law may provide access, correction, deletion, restriction, objection, and portability rights; tax, dispute, and fraud records may need to remain.
For privacy requests, contact emdev4fun@gmail.com.