1. What we collect

Account email, name, and authentication credentials. Activity logs for sign-in, security events, and account changes. Hosting usage data (storage, bandwidth, hosting account metadata) where the service is in use.

2. How we use it

To provide the service, authenticate you, detect abuse, send operational notifications (sign-in alerts, account changes), and respond to support requests. We do not sell your data.

3. Cookies and sessions

We use a session cookie to keep you signed in and an optional "remember me" cookie so you stay signed in across browser restarts. Both are essential to the service; disabling them in your browser will sign you out.

4. Third parties

Email delivery (transactional mail via our SMTP provider), hosting infrastructure (the Enhance panel), and password breach checks (haveibeenpwned API for the breached-password check on registration and password change). Each operates under its own privacy terms.

5. Data retention

We retain account data while your account is active. Activity logs are retained for a rolling 12 months for security and abuse detection. You can request export or deletion of your account data at any time via support.

6. Your rights

You can view, export, or request deletion of your personal data via support. You can also disable "remember me" at any time by signing out, which clears the persistent cookie.

7. Changes

We will update this policy as the service evolves. Material changes will be communicated via the client area or by email where appropriate.

8. Contact

Questions about this policy? Open a ticket via support and we'll route it to the right person.