Privacy Policy
Applicability
This policy applies to all personal data collected when you use the service on any device or platform. It outlines collection methods, usage, sharing, and protection. Continued use implies acceptance. Please review periodically.
Data Collected
We collect only the data needed to operate the service—email, user ID, IP address, device type, and usage logs. Collection occurs via user inputs and automated logs (cookies, server logs). Sensitive categories are never requested. Each collection point clearly states its purpose.
Use of Data
Collected data is used to authenticate, secure, and support your use. Aggregate, anonymized metrics guide improvements and new features. No personal data is sold or shared for marketing without separate consent. Any expansion of use will require opt‑in.
Cookies
Essential cookies maintain session and security tokens. Analytics cookies remain off unless enabled by you. No third‑party advertising cookies are used without permission. You can manage cookies through browser settings.
Security
Data in transit is encrypted via TLS or equivalent. Data at rest is encrypted with advanced techniques (e.g., AES‑256). Access is controlled by role‑based permissions and multi‑factor authentication. Regular audits and tests verify security.
Retention
Personal data is retained only as long as necessary—typically no more than 24 months from last activity. Afterwards, data is deleted or anonymized. Backups are purged within 90 days after retention expiry. Retention policies are documented and reviewed annually.
User Rights
You may request access to, correction of, or deletion of your personal data at any time. Requests are processed within 30 days, subject to laws. Data needed for compliance or dispute resolution may be retained anonymized. You may withdraw consent for optional features.
Breach Notification
In the event of a confirmed breach, affected users will be notified within 72 hours of verification. Notifications include breach details, data categories impacted, and recommended actions. Authorities will be notified as required by law. A post‑incident review will strengthen safeguards.
Anonymization
For analysis, direct identifiers are removed or replaced with pseudonyms. Aggregated datasets contain no individual details. Anonymized data may be retained indefinitely for research. This protects privacy while enabling insights.
Third‑Party Sharing
We share data only with essential third‑party service providers under strict agreements. These processors include hosting, payment, and email services. No data is shared with advertisers without explicit consent. All disclosures are logged and reversible.
Updates
This policy is reviewed and updated at least once per year or upon significant changes. Material revisions are communicated via email and in‑service notices at least 14 days before taking effect. Continued use after the effective date signifies acceptance. Archived versions remain accessible.