Privacy Policy

Last updated: [Last Updated Date]

Introduction

Welcome to [Platform Name] (hereinafter referred to as "we," "[Platform Name]," "us," or "our"). [Platform Name] is operated by [Legal Entity Name], registered with the [Registration Authority] under number [Registration Number].

We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform and services. By accessing or using our platform at [Platform URL], you agree to the practices described in this Privacy Policy.

This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

What [Platform Name] Is

[Platform Name] is a platform for selling and delivering digital products. The central product type is Apps: interactive tools, dashboards, calculators, and configurators that you open and use directly inside the platform. Alongside Apps, the platform also delivers courses, digital downloads, private communities, services, recurring subscriptions (including software licensing), and bundles that combine several of these.

Because Apps take input from you and return results, they have their own data flows. Those are described in detail in the "Apps and Data Processing" section below.

Who This Policy Applies To

This policy covers everyone who interacts with our platform:

  • Visitors: people browsing our public pages without an account
  • Leads: people who contact us, request a demo, join a waitlist, or download a free resource
  • Account holders: people who register an account
  • Customers: account holders who purchase or subscribe to a product

Information We Collect

1. Information You Provide Directly

When you create an account and use the platform, we collect:

  • Account Information: First name, last name, email address, password (stored only as a secure hash, never in readable form), and profile avatar
  • Product Access Data: Which products you own or are enrolled in, enrollment status, purchase date, and access history
  • App Usage Data: The information you enter into an App (form fields, uploaded files, parameters, selections) and the results returned to you
  • Course Progress: Which lessons you have completed, used to display your progress
  • Discord Integration Data: If you connect your Discord account to access a community, we collect your Discord user ID, username, avatar URL, and server membership status
  • Billing and Invoicing Information: Name or company name, email, phone number, billing address, VAT number, and company registration number, used to issue invoices and payment requests
  • Communications: Your name, email, subject, and message when you use our contact form, request a demo, or contact support
  • Lead Information: Your name and email when you request a free download or join a waitlist
  • Preferences: Interface settings such as your language, sidebar state, theme, and onboarding tour progress

2. Payment Information

When you purchase a product or start a subscription:

  • Transaction Data: We store order summary records including the product purchased, amount paid, currency, date, and order status
  • Subscription Data: For recurring products we store your subscription status, billing interval (monthly or yearly), current period end date, and renewal or cancellation status
  • Linking Identifiers: Your Stripe customer ID, subscription ID, and payment intent ID, used to connect your account to the correct payment record
  • Payment Processing: All payment card details are processed and securely stored by Stripe, our payment processor. We never see or store your complete card information

3. Licensing and Device Data

Some subscription products grant a license to software that runs outside our platform, for example a desktop plugin or a client application. When you activate such a license, we collect:

  • License Instance Records: A record linking your subscription to each activated installation
  • Token Identifiers: The identifier of the most recently issued license token, along with the issue timestamp. This lets us detect and revoke tokens that have been rotated or shared
  • Activity Timestamps: The time of the most recent check-in ("heartbeat") from the licensed software, so we can see whether a license is still in use
  • Binding Metadata: A limited set of key-value pairs (maximum 20 entries) that the licensed software sends when it activates. This typically contains a machine identifier or hardware fingerprint so a license can be tied to a specific installation. What exactly is sent is determined by the software you installed, and is described in that software's own documentation

4. Automatically Collected Information

When you visit or use our platform, we automatically collect:

  • Device Information: IP address, browser type, operating system, and device identifiers
  • Usage Data: Pages viewed, features used, access times, and referring URLs
  • Progress Data: Lesson completion status for courses. We do not track granular video metrics such as pause points or rewind counts
  • Cookies: We use cookies for authentication, preferences, and (with your consent) analytics. See the "Cookie Policy" section below

How We Use Your Information

We use the collected information for the following purposes:

  • Providing Our Services:

    • Managing your account and authentication
    • Granting and managing access to the products you have purchased
    • Running Apps, which includes passing your input to the workflow or handler that produces the result
    • Issuing, validating, renewing, and revoking software licenses
    • Delivering course content and video hosted on Vimeo or YouTube
    • Delivering digital downloads and resource files
    • Granting access to Discord communities associated with your products
    • Managing service projects and the files and updates exchanged within them
    • Processing one-time payments and recurring subscription billing through Stripe
    • Generating invoices, payment requests, and receipts
  • Communication:

    • Sending transactional emails related to your account, purchases, subscriptions, and invoices
    • Responding to your inquiries, demo requests, and support requests
    • Following up on waitlist entries and free download requests you have submitted
    • We do not run marketing email campaigns. If we introduce them in the future, we will only email you if you have opted in, and every message will include an unsubscribe link
  • Improving Our Platform:

    • Analyzing usage patterns through Google Analytics (only if you accept analytics cookies)
    • Understanding which products and features are most valuable
    • Identifying and fixing technical issues
  • Security and Fraud Prevention:

    • Detecting and preventing unauthorized access to accounts
    • Protecting against fraudulent transactions
    • Detecting license sharing and abuse through token and device binding records
    • Temporarily processing IP addresses in server memory for rate limiting and abuse prevention. This data is not persisted to disk and is cleared on server restart
  • Legal Compliance:

    • Fulfilling our legal obligations under [Country] law and GDPR
    • Retaining financial records for tax purposes as required by [Country] law

Apps and Data Processing

Apps are the core of the platform, so we describe their data handling separately. There are three kinds of App, and each one moves your data differently.

Workflow Apps

A workflow App sends the input you provide to an automation workflow that produces the result. When you run one:

  • We send the workflow endpoint your app identifier, the action you triggered, your account user ID, and the input you entered
  • If the App has user identity enabled, we also include a short-lived signed token (valid for one hour) containing your account user ID, your email address, and your display name. This lets the App recognise you and show you your own data
  • The workflow endpoint may be operated by us or by the provider of that specific App, and may be hosted outside the [Data Region]. Where the App is provided by a third party, that provider's own privacy policy also applies
  • The result is returned to your browser through our servers

Bundled Apps

A bundled App is a self-contained application that we host and serve to your browser:

  • The App runs in your browser. Some bundled Apps also have a server-side handler that runs on our own servers in an isolated sandbox with no network access, no file system access, and a strict execution time limit
  • If the App has user identity enabled, we pass the same short-lived signed token (user ID, email, display name) to the App inside your browser
  • Input sent to a server-side handler is processed and returned. It is not shared with any third party

Embedded Apps

An embedded App displays a third-party application inside our platform:

  • The embedded application is loaded directly from the third party's servers. Your browser connects to them, which means they may receive your IP address and other information their service collects
  • Anything you enter into an embedded application is handled by that third party under their own privacy policy, not ours
  • We pass identity information to an embedded App only when that App has user identity enabled, and only the short-lived signed token described above

Apps on Custom Domains and Single Sign-On

Some Apps are served on their own domain rather than on our main platform domain. To keep you signed in across domains, we issue a short-lived, single-use handoff token that establishes your session on the other domain. The token identifies you to our own platform only and expires quickly.

What We Do and Do Not Keep

  • We do not store the input you enter into an App or the results returned to you, unless that specific App is explicitly built to save your work. Where an App saves your work, this is stated inside the App itself
  • We do not use your App input or results to train AI models
  • We do not sell App usage data or make it available to other customers

Third-Party Services and Data Sharing

We do not sell or rent your personal information to third parties. We work with trusted service providers who process data on our behalf:

Essential Service Providers

  • Supabase (Authentication, Database & File Storage): We use self-hosted Supabase infrastructure to store your account data, product data, and uploaded files. All data is hosted on our servers in [Server Location/Country] ([Data Region]) with encryption at rest and in transit. While we self-host, the software is based on Supabase's open-source platform.

  • Stripe (Payment Processing & Subscription Billing): Processes all one-time payments and recurring subscriptions, and stores payment card information. We only store order and subscription summaries; Stripe handles all sensitive payment data according to their privacy policy.

  • Vimeo (Video Hosting): Hosts video content for courses and other products. When you play a video, your browser connects directly to Vimeo's servers. Vimeo may collect IP addresses and viewing data per their privacy policy. We do not send personal identifiers to Vimeo.

  • YouTube (Video Hosting): Some video content is embedded from YouTube. When you play such a video, your browser connects directly to YouTube's servers, which may set cookies and collect viewing data under Google's privacy policy.

  • Discord (Community Features): When you connect your Discord account, we share minimal information (your platform account link) to grant access to product-specific communities. Discord operates under their own privacy policy.

  • Automation and App Providers: Workflow Apps send your input to an automation endpoint, and embedded Apps load content from a third party. Depending on the App, that endpoint may be operated by us or by an external provider. See the "Apps and Data Processing" section.

  • Email Delivery (SMTP): Transactional emails (account, purchase, invoice, and support messages) are sent through a configured SMTP mail provider, which processes your email address and the content of the message in order to deliver it.

  • Google Analytics (GA4): Tracks anonymous usage patterns to help us improve the platform. Google Analytics uses cookies and may collect IP addresses. It only loads if you accept analytics cookies.

Legal Disclosure

We may disclose your information when:

  • Required by law, court order, or legal process
  • Necessary to protect our rights, property, or safety, or that of our users
  • In connection with a business transaction such as a merger or acquisition (users would be notified)

We do not:

  • Sell or rent personal data
  • Share data with educational institutions or employers
  • Participate in affiliate programs that involve data sharing
  • Use marketing pixels or remarketing services
  • Make your data available to other customers of the platform

Data Storage, Security, and Retention

Where We Store Your Data

All personal data is stored within the [Data Region] on our self-hosted servers in [Server Location/Country]. We use Supabase's open-source software for database, authentication, and file storage management, but the infrastructure and data storage are fully under our control in [Server Location/Country]. This ensures compliance with GDPR data residency requirements.

Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: All data is encrypted in transit using SSL/TLS and at rest through PostgreSQL encryption
  • Secret Encryption: Sensitive configuration values, such as App signing secrets, webhook secrets, and license API keys, are stored encrypted with AES-256 and are never held in readable form
  • Row Level Security: Database access rules are enforced at the database level, so users can only read the records that belong to them
  • Sandboxed Execution: Server-side App handlers run in an isolated sandbox with no network access, no file system access, and a strict execution time limit
  • Signed, Short-Lived Tokens: Identity, license, and single sign-on tokens are cryptographically signed, expire quickly, and can be revoked
  • Authentication: Secure password requirements enforced by Supabase Auth. Two-factor authentication is not currently available but may be implemented in the future
  • Payment Security: All payment processing is handled by Stripe, a PCI DSS compliant payment processor
  • Access Controls: Limited internal access to personal data on a need-to-know basis

While we implement robust security measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but continuously work to protect your information.

Data Retention Periods

We retain your information for as long as necessary to provide services and fulfill legal obligations:

  • Active Accounts: Personal data is retained while your account is active, so that you can access the products you have purchased at any time

  • After Account Deletion:

    • Most personal data (profile, product access, progress, preferences, App and license records) is deleted within 30 days
    • Order summaries and invoice records are retained for 7 years to comply with [Country] tax law
    • Detailed payment information remains with Stripe according to their retention policy
  • Specific Data Types:

    • Financial records, orders, and invoices: 7 years (legal requirement)
    • App input and results: not stored, unless the App is explicitly built to save your work
    • License instance and device binding records: retained while the subscription is active, then deleted with your account data
    • Lead and waitlist records: retained until you ask us to remove them
    • Contact and support messages: retained for as long as needed to handle and document the request
    • IP addresses for rate limiting: transient (held in server memory only, cleared on server restart)
    • Anonymized analytics: indefinitely (no personal identifiers)
    • Discord connection records: retained for administrative purposes unless deletion is requested
  • Inactive Accounts: We do not automatically delete inactive accounts, so you can return to your products at any time. You may request deletion whenever you wish.

Your Rights Under GDPR

As we primarily serve EU users and comply with GDPR, you have the following rights regarding your personal data:

Your Privacy Rights

  • Right to Access: Request a copy of the personal information we hold about you
  • Right to Rectification: Update or correct inaccurate personal information
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data (subject to legal retention requirements)
  • Right to Restriction: Request that we limit how we process your data
  • Right to Data Portability: Receive your personal data in a machine-readable format
  • Right to Object: Object to our processing of your data for certain purposes
  • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data

How to Exercise Your Rights

Currently Available Options:

  • You can view and update your account information through your profile settings
  • Your purchases, invoices, subscriptions, and progress are viewable within the platform
  • You can disconnect your Discord account at any time
  • You can decline analytics cookies through the cookie banner

Features Under Development:

  • Self-service data export
  • Self-service account deletion

To Request Data Access or Deletion:

  1. Email your request to: [Privacy Email]
  2. Include your registered email address for identity verification
  3. We will respond within 30 days as required by GDPR (typically within 7 to 14 business days)
  4. For data deletion, we will confirm via email when the process is complete

Important Notes:

  • Even after deletion, we may retain certain data to comply with legal obligations (financial records for 7 years)
  • Payment information stored by Stripe follows their retention policy
  • We require identity verification before processing data requests to protect your privacy

Cookie Policy

We use cookies and similar tracking technologies to provide and improve our services.

What Are Cookies?

Cookies are small text files stored on your device that help us recognize you and remember your preferences. They enable essential functionality and help us understand how users interact with our platform.

Types of Cookies We Use

1. Strictly Necessary Cookies (Required)

These cookies are essential for the platform to function and cannot be disabled:

  • Authentication Cookies
    • Purpose: User authentication and session management
    • Provider: Supabase
    • Data Collected: Session tokens, authentication status
    • Duration: Session-based and persistent
    • Can be disabled: No, required for login and platform access

2. Functional Cookies (Optional)

These cookies enhance your experience but are not strictly necessary:

  • Referral Tracking Cookie (referral_source)

    • Purpose: Track referral sources from marketing campaigns
    • Data Collected: Referral parameter values (utm_source, ref, via, aff, referral_code)
    • Duration: Session-based, removed once your account is created
    • Can be disabled: Yes, does not affect platform functionality
  • Language Alert Cookie (langAlertDismissed)

    • Purpose: Remember if you dismissed the language detection alert
    • Data Collected: Dismissal status (true/false)
    • Duration: 30 days
    • Can be disabled: Yes, the alert will reappear on your next visit
  • Sidebar State Cookie (sidebar:state)

    • Purpose: Remember your sidebar preference (open or closed)
    • Data Collected: Open or closed state
    • Duration: Persistent
    • Can be disabled: Yes, the sidebar will reset to its default state
  • Theme Preference Cookie (theme)

    • Purpose: Store your theme preference
    • Provider: next-themes library
    • Data Collected: Theme selection (light or dark)
    • Duration: Persistent
    • Can be disabled: Yes, the theme will reset to its default

3. Analytics Cookies (Optional)

These cookies help us understand how users interact with our platform:

  • Google Analytics Cookies (_ga, _gid, _gat)
    • Purpose: Understanding usage patterns to improve the platform
    • Provider: Google Analytics (GA4)
    • Data Collected: Anonymous usage statistics, page views, interactions, session data
    • Duration: Up to 2 years
    • Can be disabled: Yes, through the cookie consent banner or a browser add-on

4. Third-Party Cookies From Embedded Content

Video players (Vimeo, YouTube) and embedded Apps may set their own cookies when you interact with them. These are governed by the privacy policy of the provider in question.

Browser Storage: In addition to cookies, we store a small amount of information in your browser's local storage, including your cookie consent choice (cookie-consent) and the last management page you visited. This information stays in your browser and is not sent to our servers.

We do NOT use:

  • Advertising or remarketing cookies
  • Social media tracking pixels
  • Third-party marketing cookies
  • Cross-site tracking cookies

Managing Cookie Preferences

Cookie Consent Banner:

When you first visit our public pages, you will see a cookie consent banner with two options:

  • Accept: Allows all optional cookies including Google Analytics tracking

    • Google Analytics will load and track your usage patterns to help us improve the platform
    • Your choice is stored locally in your browser
    • You can change your preference at any time by clearing your browser data and revisiting the site
  • Decline: Only essential cookies will be used

    • Google Analytics will NOT load, so we will not track your browsing behaviour
    • Only authentication and preference cookies (required for the platform to work) will be active
    • Your choice is stored locally in your browser
    • The platform will function normally without any limitations

Browser Controls: You can control cookies through your browser settings:

  • Most browsers allow you to view, delete, and block cookies
  • Blocking essential cookies will prevent you from logging in and using the platform
  • Blocking analytics cookies will not affect platform functionality

Third-Party Opt-Out:

Specific Features and Data Practices

Apps

See the dedicated "Apps and Data Processing" section above for the full description of how App input, results, and identity tokens are handled.

Subscriptions and Software Licensing

  • Recurring Billing: Subscription products renew automatically through Stripe until cancelled. We store the subscription status, billing interval, and period end date so we know whether your access is still valid
  • License Tokens: For subscriptions that license software running outside the platform, we issue signed tokens with a limited lifetime that the software renews while your subscription is active
  • Device Binding: Licensed software may send a machine identifier when it activates, so a license can be tied to a specific installation. We store this to enforce your license terms and detect sharing
  • Check-Ins: Licensed software may periodically confirm that a license is still valid. We record the time of the most recent check-in
  • Cancellation: When a subscription ends, the associated license tokens stop renewing and access is withdrawn

Payments, Invoices, and Billing Data

  • Stripe Processing: All payment transactions are processed by Stripe. We never see or store your full card details
  • What We Store: Order and subscription summaries (product, amount, currency, date, status, Stripe identifiers)
  • Invoices: If an invoice or payment request is issued to you, we store the billing details required by law, including name or company name, address, VAT number, and company registration number, together with a snapshot of the invoice so it can be re-issued identically
  • What Stripe Stores: Complete payment information, billing history, and card details
  • Refunds: Refund records are kept for 7 years with other financial records

Video Content and Progress Tracking

  • What We Track: Lesson completion status, used to display your progress
  • What We Do Not Track: Granular viewing metrics (pause points, rewind counts, watch time within videos)
  • Vimeo and YouTube: Video players connect directly to Vimeo's or YouTube's servers, which may collect viewing data under their own privacy policies
  • Admin Visibility: Platform administrators can view completion rates and individual user progress for support purposes. This data is not shared with third parties

Discord Integration

When you connect your Discord account to access a community:

  • Data Collected: Discord user ID, username, avatar URL, server membership status
  • Purpose: Granting and managing access to product-specific Discord servers
  • Synchronization: We periodically sync usernames, but use the Discord ID (permanent) as the primary identifier
  • Disconnection: When you disconnect Discord, we remove your community access but retain connection records for administrative purposes
  • Deletion: You can request full deletion of Discord data by emailing [Privacy Email]

Digital Downloads, Resource Files, and Services

  • Downloads: We record which files you have access to and when access was granted, so download links can be issued to you
  • Lead Capture: Free downloads may ask for your name and email before the file is sent. That information is stored as a lead record and you can ask us to remove it at any time
  • Service Projects: For service products delivered as a project, we store the project details, status updates, messages, and files exchanged between you and us as part of delivering that service

Contact Forms, Demo Requests, and Waitlists

  • Data Collected: Name, email, subject, and message content
  • Purpose: Responding to your request and, where relevant, following up about the product you enquired about
  • Storage: Contact submissions are emailed to us and lead records are stored in our database

AI Features

AI features are not currently active in production. If we enable them in the future:

  • We will update this privacy policy before activation
  • We will not use your personal data to train AI models without explicit consent
  • We will clearly disclose how AI-generated content is handled

Features We Do Not Offer

To provide transparency, we explicitly state that we do NOT:

  • Send marketing emails or newsletters
  • Allow users to create public profiles
  • Enable public comments, reviews, or public user-generated content
  • Share data with educational institutions or employers
  • Operate referral or affiliate programs involving user data
  • Sell your personal data or App usage data to anyone

Age Requirements and Children's Privacy

No Minimum Age Restriction: We do not impose a minimum age requirement for using our platform. However, users under 18 should obtain parental consent before creating an account or making purchases.

Parental Responsibility: Parents and guardians are responsible for monitoring their children's internet usage. If you believe your child has provided personal information to us and you wish to have it deleted, please contact us at [Privacy Email].

Educational Use: We do not currently partner with educational institutions or offer services specifically designed for minors.

International Data Transfers

Primary Data Location: All personal data is stored within the [Data Region] ([Server Location/Country]) on our self-hosted infrastructure.

Third-Party Services: Some of our service providers (Stripe, Google, Vimeo, YouTube, Discord) and some App workflow endpoints may process data outside the [Data Region]. These providers have appropriate safeguards in place:

  • Stripe: Complies with GDPR and uses Standard Contractual Clauses (SCCs)
  • Google: EU-US Data Privacy Framework participant
  • Vimeo: GDPR-compliant with EU data processing agreements
  • Discord: Processes data with appropriate GDPR safeguards
  • App Providers: Where an App is operated by a third party, the transfer safeguards of that provider apply and are disclosed within the App

We ensure that any international data transfers comply with GDPR requirements through appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other approved transfer mechanisms.

Updates to This Privacy Policy

Review Schedule: We review and update this privacy policy annually or when significant changes to our data processing practices occur.

Notification of Changes: When we make material changes to this policy:

  • We will update the "Last Updated" date at the top of this page
  • Significant changes will be communicated through email or a prominent notice on the platform
  • Continued use of the platform after changes constitutes acceptance of the updated policy

Version History: Previous versions of this privacy policy may be requested by emailing [Privacy Email].

Last Review Date: [Last Updated Date] Next Scheduled Review: [Next Review Date]

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy and Data Protection:

  • Email: [Privacy Email]

General Support:

  • Email: [Support Email]

Business Information:

  • Company: [Legal Entity Name]
  • Registration: [Registration Authority] #[Registration Number]
  • Website: [Platform URL]

Response Time: We aim to respond to all privacy inquiries within 7 to 14 business days, and no later than 30 days as required by GDPR.

Supervisory Authority: If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority. For users in [Country], this is the [Local Data Protection Authority].


Summary of Key Points

For your convenience, here is a quick summary of our privacy practices:

What We Collect: Account info, product access and progress, App input and results, billing and invoice details, licensing and device records, Discord connections, payment data (via Stripe), usage analytics

How We Use It: Running Apps and delivering products, managing subscriptions and licenses, processing payments and invoices, supporting you, improving the platform

Who We Share With: Supabase (self-hosted infrastructure), Stripe (payments), Vimeo and YouTube (video), Discord (communities), App and automation providers, our SMTP email provider, Google Analytics

Apps: Your input goes to the workflow or handler that produces the result. We do not store it, and we never use it to train AI models

Your Rights: Access, rectification, deletion, data portability, and more under GDPR

Data Location: Stored in the [Data Region] ([Server Location/Country]); complies with GDPR

Retention: Kept while your account is active; deleted within 30 days of account deletion (7 years for financial records)

Cookies: Essential (authentication and preferences) plus analytics, which load only if you accept

Security: Encryption in transit and at rest, encrypted secrets, sandboxed App execution, short-lived signed tokens

Contact: [Privacy Email] for all privacy requests

No Minimum Age: Platform accessible to all ages (parental consent advised for minors)


This privacy policy is effective as of [Last Updated Date], and governs all data processing activities of [Platform Name] operated by [Legal Entity Name].