Legal
Privacy policy
noindex until it is.
1. Controller
[Operator legal entity, address, contact email — mirror the imprint.]
2. What we collect
[Account email and password hash; organization membership; API keys (hashed); usage metering per key; server access logs with IP address; the anonymous preview rate-limit counters at the edge.]
3. Why and on which legal basis
[Contract performance for accounts and billing; legitimate interest for abuse prevention and metering; consent where applicable.]
4. Cookies
[One HttpOnly session cookie for signed-in users; no advertising or analytics cookies. Describe any edge protection (Cloudflare, Turnstile) that sets its own cookies.]
5. Processors and transfers
[Hosting (DigitalOcean, region), edge/DNS (Cloudflare), payments (Stripe), and where data leaves the EEA/Switzerland.]
6. Retention
[Account data for the life of the account; logs and metering for a fixed period; deletion on request.]
7. Your rights
[Access, rectification, erasure, restriction, portability, objection, complaint to the supervisory authority; how to exercise them.]
8. Public web data in the index
[How publicly available source code is collected, what identifiers are stored, and how domain owners can request removal.]
9. Changes
[Effective date and how changes are announced.]