Privacy Policy
Scope
This policy applies to all personal information collected, processed, and stored when you use the service via web, mobile, or API interfaces. It governs the methods of collection, the purposes for which data is used, and the safeguards in place to protect your information. Your continued use of the service constitutes acceptance of these practices. Please review this policy periodically, as updates may occur.
Information We Collect
We collect only the minimum personal data necessary for service functionality, including email addresses, user IDs, and usage logs. Data is obtained through user inputs (e.g., registration, profile updates) and automatically via server logs, cookies, and device telemetry. We do not request sensitive categories such as health, financial, or biometric information. Each collection point clearly communicates the intended purpose of processing.
Use of Data
Collected data is used to authenticate your access, maintain session security, and diagnose technical issues. Aggregate, anonymized metrics help us improve performance and develop new features. We never sell or rent personal data to third-party advertisers without explicit, separate consent. Any new uses of your information will be communicated and require opt-in.
Cookies & Tracking Technologies
Essential cookies support core functionality such as login sessions and security tokens. Non-essential analytics cookies remain disabled unless you explicitly enable them in your settings. Third-party advertising trackers are not deployed without your explicit permission. You may manage or block cookies via your browser or account settings.
Data Security
All data in transit is encrypted using industry-standard protocols (e.g., TLS) to prevent interception. Data at rest is stored in encrypted repositories with access restricted to authorized personnel only. Role-based access controls and multi-factor authentication further limit internal data exposure. Regular security audits and vulnerability assessments help identify and remediate potential risks.
Data Retention
We retain personal data only as long as necessary to fulfill its original purpose, typically no more than 24 months from the date of last user activity. After this period, data is either securely deleted or irreversibly anonymized. Backups are purged within 90 days once the active retention period has expired. Retention schedules are reviewed at least annually.
User Rights
You have the right to access, correct, or delete your personal information at any time. Requests are processed within 30 calendar days in accordance with applicable laws. Information that must be retained for legal compliance or dispute resolution may be retained in anonymized form. You may also withdraw consent for optional processing without affecting essential services.
Breach Notification
In the event of a confirmed data breach that affects your personal information, we will notify affected individuals within 72 hours of breach confirmation. Notifications will outline the nature of the breach, categories of data involved, and recommended mitigation steps. Regulatory authorities will be informed as required by law. A thorough post-incident review will guide improvements.
Anonymization & Aggregation
Direct identifiers (e.g., email addresses) are removed or replaced with non-reversible pseudonyms before any analytical or reporting use. Aggregated data sets never contain individual-level details and cannot be traced back to specific users. Anonymized information may be retained indefinitely for statistical and research purposes. This approach balances user privacy with operational insights.
Third-Party Service Providers
Data is shared only with trusted third-party providers essential to service operation (e.g., hosting, payment processing, email delivery). Each processor is bound by data protection agreements and undergoes regular security audits. No personal data is shared with advertising networks or data brokers. All third-party transfers are logged and available for audit.
Policy Updates
This policy is reviewed and updated at least once per year or whenever legal or operational changes occur. Material revisions will be communicated via in-service notifications and email at least 14 days before taking effect. Continued use after the effective date implies acceptance of updated terms. Archived versions remain accessible for transparency.