Legal
Privacy Policy
Free tools collect nothing. Pro's backend collects the minimum needed to license, deliver, and meter - and the website collects almost nothing at all.
1. Summary
- Free packer + SDK: fully offline. No accounts, no telemetry, no network calls. Nothing leaves your machine.
- This website: static pages, no analytics, no cookies, no accounts. It talks only to our own update backend (for the Download button and the status page) and to Google Fonts, and it saves just your chosen interface language in your browser.
- Pro (coming soon): the toolchain and protected apps contact our backend for license checks, gated downloads, rotation seeds, and updates. We log the minimum to enforce entitlements and metered billing (key, activation/seat, coarse usage), cached client-side with a short TTL.
- Payments go through a merchant of record - we never see or store card numbers.
- Dev project storage (Feature B) is not offered yet. We do not host your project files today.
2. Website
This site is static HTML on Cloudflare Pages. There is no analytics script, no tracking pixel, no cookies, no advertising, and no comment/chat widget. Standard Cloudflare edge logs (IP, user agent, requested path, timestamp) exist for security and debugging and rotate automatically.
The page makes two kinds of outbound request:
- Our own update backend (a Cloudflare Worker, visible in the page source). The Download button reads the current signed release manifest and the status page reads a health endpoint. These are plain GET requests: your IP and user agent reach our Worker and appear in its edge logs, but no account, cookie, or identifier is sent. Until the backend URL is configured the site runs fully offline and Download falls back to GitHub Releases.
- Google Fonts for the Inter typeface (stylesheet from
fonts.googleapis.com, files fromfonts.gstatic.com). Google may log that request under its own privacy policy.
No other third parties load (no ad networks, no social widgets). Our Content-Security-Policy blocks the page from connecting anywhere except our own origin, our update Worker, and those font hosts.
You can switch the interface language. Your choice is saved only in your browser's local storage as a functional preference: it is not a cookie and is never sent to us, and clearing site data resets it. The prose on the legal and documentation pages is English.
3. Free tools
The free packer (protector.exe), the desktop packing tool, the SDK headers, and the runtime modules run entirely on your machine. They make zero network requests, create no identifiers, and write only the files you ask them to (protected output, configs, local logs you control). Dropping an .exe into the tool uploads it nowhere - analysis happens locally.
4. Pro toolchain and backend (coming soon)
When Pro launches, the following contacts our backend (Cloudflare Worker + R2 + KV). The client is treated as hostile: the server decides entitlements, and every payload that matters is signed and verified - but verification does not require us to know who your end users are.
| Event | What is sent | Why |
|---|---|---|
| License install / activation | license key, app/toolchain version, coarse platform string, activation ID | authenticate the key, enforce seats/activations, deliver only paid bytes |
| Gated download / update check | license key or activation token, channel, current version | serve the signed manifest envelope + artifacts for that channel/version |
| Rotation seed pull | license key or activation token, time window | issue the current-window per-license seed; stale seeds stop working |
| Metered online features | aggregated counts (seats/activations, GB, rotation frequency) | metered billing against the developer's account with estimator + caps |
- Transport. TLS everywhere; requests and responses HMAC-signed with nonces/timestamps (anti-replay); responses verified client-side (anti fake-server).
- Caching. Validations are cached client-side with a short TTL so normal runs do not phone home every launch.
- Grace. If the backend is unreachable, clients fall back to last-known-good and keep running. We do not brick your app over our outage.
- What we never collect from protected end users: file contents of their machines, unrelated browsing, or identities. Metering is counted against the developer's account, not profiled per end user.
- Watermarking. Pro builds carry a per-license marker so a leaked build can be traced to the leaking key. That marker identifies the license, not the end user.
5. Payments
Checkout is handled by a merchant of record (Lemon Squeezy or Gumroad). They process your payment, handle tax/VAT, and issue receipts under their own privacy policy and terms. We receive purchase records (email, purchased features, license key issued, refund/chargeback state) to provision and revoke entitlements - we never receive full card numbers.
6. Retention and rights
- Retention. Edge/security logs rotate on a short schedule. License and entitlement records live as long as the key exists plus a reasonable accounting tail (refunds, chargebacks, watermark traces). Revoked keys stay on a denylist so abuse cannot simply re-register.
- Your rights. Request access, correction, or deletion of your account/license data via [support email]. Deletion of an active license ends backend services for that key (expected - there is nothing left to authorize). EU/UK users: the legal bases are contract (provisioning what you paid for), legitimate interests (security, abuse prevention, AV-reputation defense), and legal obligation (tax/accounting via the merchant of record).
- Children. No part of the service targets children. Paid purchases require contractual capacity (or a parent/guardian purchaser).
- Changes. Material changes are posted here with a new effective date. The only thing the site stores in your browser is your chosen interface language, a functional preference that does not require consent, so there is no consent banner.