Privacy
Effective July 2026 · what we store, why, and what we don't.
What we collect
Account data (email, optional name, hashed password), security data (session and device tokens — stored hashed — sign-in audit events, coarse IP), commerce data (orders, wallet ledger, licenses, reviews), and the briefs you submit for services. Passwords are hashed with scrypt; one-time codes and API keys are stored only as hashes.
What we don't
No card numbers (Stripe holds those when card payments are configured), no tracking pixels, no third-party analytics, no selling or sharing of personal data. Emails are sent through the configured provider solely to deliver codes, receipts, and deliverable notifications.
AI processing
Service briefs are processed by automated AI systems to produce your deliverable, under human review. Briefs are not used to train models.
Retention and deletion
Commerce records are kept as long as your account exists (and as required for accounting). Expired sessions, codes, and rate-limit counters are pruned routinely. Email [email protected] to export or delete your account data; deletion completes within 30 days, minus records we must keep by law.
Your rights
Access, correction, export, deletion, and objection — write to [email protected] and we'll act within 30 days.