Privacy Policy
v2026-10-06
Privacy Policy (draft, effective [YYYY-MM-DD])
[legal entity] ("we") processes personal data as follows.
1. What we collect and why
- Account: email, display name, sign-in provider ids (GitHub, Google) — to sign you in, send receipts and notifications.
- Handle, profile image, chief look — your public profile, if you turn it on.
- Subscription state (Paddle customer and subscription ids, period, status) — to provide Pro. Card details stay with Paddle; we never receive them.
- App devices: a random install id, the device name you give, platform, app version — to count devices.
- Access records: a keyed hash of your IP address and your browser type — abuse prevention (90 days).
- Pro sharing (optional): the journal summary for the grass card (daily counts and coins; no repository names, sessions or messages) and the chief's look.
- Community: the posts, comments, images, packs and looks you upload.
The app's village data (sessions, inbox, Slack tokens, agent credentials) stays on your computer and is never sent to us.
2. Retention. Deleted within 30 days of leaving. Access records 90 days; payment records are kept by Paddle as the law requires. Whether an email has had a trial is kept as a hash.
3. Processors and third parties. Paddle (payments, receipts; email and payment data), GitHub and Google (sign-in), Resend (email), Cloudflare (hosting, security). They operate abroad, so data may be transferred internationally.
4. Your rights. View, correct, download and delete your data from My page. We do not accept sign-ups under 14.
5. Security. HTTPS everywhere, passwordless sign-in, least-privilege access.
6. Cookies. Only for the sign-in session and your language. No advertising or tracking cookies.
7. Contact. [name], [contact email].