Privacy Policy
Overview
This policy governs the personal data collected when you interact with the service across all platforms. It explains our practices for collection, use, sharing, and retention. Continued use signifies acceptance. Please check for updates periodically.
Information Collected
We collect only essential data—email, username, IP address, device metadata, and usage logs. Collection is via user inputs and automated means (cookies, server logs). Sensitive data is never requested. Each collection point clearly states its purpose.
Data Use
Collected data is used to authenticate sessions, secure accounts, and provide support. Aggregate, anonymized metrics inform performance and feature improvements. No personal data is shared for marketing without consent. Any expansion of use will require opt‑in.
Cookies & Tracking
Essential cookies sustain login and security functions. Analytics cookies remain off until enabled. No third‑party advertising cookies are deployed without permission. You can manage cookies in your browser settings.
Security
All data in transit uses HTTPS/TLS encryption. Data at rest is encrypted with strong ciphers (e.g., AES‑256). Access is restricted by roles and multi‑factor authentication. Regular audits and penetration tests ensure robust security.
Storage & Retention
We retain personal data only as long as necessary—generally no more than 18 months. Afterward, data is deleted or anonymized. Backups are purged within 90 days post‑expiry. Retention practices are reviewed annually.
User Rights
You have the right to access, correct, or delete your personal data at any time. Requests are handled within 30 days, subject to legal limits. Data needed for compliance or disputes may be retained anonymized. Consent for optional processing can be withdrawn.
Breach Response
In case of a breach, affected users will be notified within 72 hours of confirmation. Notices detail breach nature, affected data, and mitigation steps. Authorities will be informed as required by law. A post‑incident review will improve future defenses.
Anonymization & Aggregation
Direct identifiers are removed or pseudonymized before any analysis. Aggregated datasets contain no individual details. Anonymized data may be kept indefinitely for research. This balances privacy with insights.
Third‑Party Sharing
Data is shared only with essential third‑party processors bound by strict agreements. Providers include hosting, payment, and email services. No data is shared with advertisers without explicit consent. All transfers are logged and auditable.
Policy Changes
This policy is updated at least once per year or upon significant changes. Material revisions are announced via email and in‑service notices 14 days before enforcement. Continued use signifies acceptance. Archived versions remain accessible.