Privacy Policy
Last updated 25 August 2026
The short version: we collect as little as we can get away with, we do not store your IP address, we do not sell anything to anyone, and you can export or delete everything yourself from your dashboard. The rest of this page is the detail.
1. What we collect
If you have an account: your email address, display name, optional avatar, locale and timezone, and your subscription and invoice records.
When you use a tool: which tool, when, whether it succeeded, how long it took, and a one-way hash of your input. The input itself is not stored unless the tool explicitly says so and you agree.
Rather than your IP address: a rotating daily HMAC of your IP and browser user-agent. This lets us count unique visitors for one day and enforce fair-use limits. It cannot be reversed, and it is useless the next day. We do not write your IP address to our database.
If you upload a file: the file, in private storage, served only through short-lived signed links, deleted automatically after 30 days.
2. What we deliberately do not do
- We do not sell or rent personal data. Ever.
- We do not use your content to train machine-learning models.
- We do not request write access to any social account.
- We do not load third-party analytics or advertising scripts before you consent to them.
- We do not build advertising profiles.
3. Cookies and tracking
Necessary cookies keep you signed in and protect forms against cross-site request forgery. These cannot be turned off without breaking the site, and they set no third-party data.
Analytics and marketing tags — where enabled — load only after you accept them in the consent banner. Declining costs you nothing; every tool works identically either way.
4. Who else touches your data
We use a small number of processors, each for one specific job:
- Stripe — payments. Card details go directly to Stripe and never reach our servers.
- Mailgun — transactional email such as receipts and password resets.
- DigitalOcean — hosting and file storage.
- Sentry — error reporting, with passwords, tokens and card data scrubbed before anything is sent.
- Your newsletter provider — only if you subscribe, and only after you confirm.
5. How long we keep things
- Tool run records: 90 days, then aggregated into anonymous statistics.
- Uploaded files and generated artifacts: 30 days.
- Support tickets: 2 years after closure.
- Invoices: 7 years, because tax law requires it. If you delete your account, these are kept with the personal fields redacted.
- A deleted account: 30 days of recoverability, then permanently purged.
6. Your rights
You can access, correct, export or delete your data. Export and deletion are self-serve from Dashboard → Privacy — no email to us, no waiting, no retention-offer gauntlet.
If you are in the EEA or UK you also have the right to object to processing and to complain to your supervisory authority. If you are in California, you have the right to know, delete, and opt out of sale — we do not sell data, so the last one is already satisfied.
7. Security
Everything is encrypted in transit. Passwords are hashed with Argon2id. Access to production data is limited and audited. If a breach affects your personal data we will tell you and the relevant authority within 72 hours of becoming aware of it. To report a vulnerability, email [email protected].
8. Contact
Questions about this policy, or about data we hold on you, go to [email protected].
Questions about this document? Get in touch.