Template. svelte-saas-kit ships this page as a starting point. It describes what the kit does with personal data. Before launch, the operator must add its legal name and address, check each section against the law that applies to it, and have a lawyer review the text. This page is not legal advice.
1. Overview
This Privacy Policy explains what information we collect when you use this service, why we collect it, and the choices you have. In this policy, "we" means the operator of this service, and "you" means a person who visits the site or has an account. By using the service, you agree to the collection and use of information as described here.
2. Information We Collect
Account information: your email address and name. If you set a password, we keep only a secure hash of it, never the password in plain text. If you sign in with Google, we receive your Google email address, name, and profile picture.
Sign-in sessions: for each session we keep the IP address and the browser user agent, so that we can protect your account.
Billing information: the plan or credit pack you buy, the amount, the currency, the status, and the reference numbers from the payment provider. The payment provider handles your card or QRIS payment. We don't receive or store your full card number, bank account number, or e-wallet credentials.
Credits and usage: your credit balance, every credit change, your daily usage counts, and the jobs you start, so we can bill accurately and show you your history.
Support requests: your messages, the screenshots you attach, and your browser user agent.
Referrals: the referral code from a link that you opened.
Technical data: request IDs, IP addresses, browser type, and error details, collected automatically for rate limits, security, abuse prevention, and to fix problems.
3. How We Use Your Information
- To operate the service: create your account, sign you in, keep your session safe, and enforce your plan limits and credit balance.
- To take payments, add credits, give refunds, and keep accurate transaction and accounting records.
- To answer support requests and to communicate with you about your account, billing, or service changes.
- To detect and prevent fraud, abuse, and violations of our Terms of Service, for example with rate limits.
- To understand which pages and features people use, and to improve the reliability and performance of the service.
- To comply with the law.
4. Who We Share Information With
We share the minimum necessary information with service providers that help us run the service, under obligations to protect your data:
| Provider | Purpose | Data |
|---|---|---|
| Our server host and Cloudflare | Hosting, network, and HTTPS | All data that the service handles |
| Polar | Card payments in USD (merchant of record) | Email, order, and payment data |
| Pakasir | QRIS payments in IDR | Order and payment data |
| Resend and Brevo | Sign-in codes and service emails | Email address and email content |
| PostHog | Product analytics | A random browser ID, page views, and product events |
| Sentry | Error tracking | Error details and request IDs, with personal data removed before sending |
| Cloudflare R2 and Neon | Encrypted backups and a copy of financial records | Database backups; payment and credit records |
| Google sign-in, when you choose it | The sign-in request |
Some providers keep data outside your country, for example in the United States or the European Union.
We also share information with authorities if the law requires it, or to protect the rights and safety of the operator, our users, or others.
We don't sell your personal information to third parties.
5. Data Retention
We retain account data while your account exists. We retain billing, payment, and credit records for as long as legal, tax, and accounting obligations require, also after your account is closed. We never edit these records; corrections are new entries.
- Support screenshots: 60 days, then we delete them automatically.
- Database backups: daily backups for 35 days and monthly backups for 12 months.
6. Your Rights
You can see most of your account information directly in your account.
You may request a copy of your data, a correction, or the deletion of your account and associated personal data by sending a request through the support page in your account. When we delete an account, we keep the records that we're required to retain for legal and billing reasons.
7. Security
We use industry-standard measures to protect your information: HTTPS for all traffic, hashed passwords, encrypted secrets on our servers, backups encrypted before they leave the server, and access controls. Only administrators can see account data, and we keep an audit record of administrator actions.
No system is perfectly secure, so we can't guarantee absolute security. We work to keep your data protected and will notify affected users if we become aware of a breach involving personal data.
8. Cookies & Browser Storage
| Name | Purpose | Duration |
|---|---|---|
| Sign-in session cookie | Keeps you signed in | 30 days, renewed when you use the service; deleted when you sign out |
PARAGLIDE_LOCALE |
Remembers your language | Up to 400 days |
| Pending email cookie | Remembers your email between the sign-up form and the code form | 15 minutes |
| Referral cookie | Remembers the referral code from a link | 90 days |
| PostHog cookie and local storage | A random ID for analytics, only when analytics is on | Until you clear it |
Analytics does not record sessions or capture clicks automatically. If your browser sends "Do Not Track", analytics collects no data.
We don't use third-party advertising trackers.
9. Children's Privacy
This service isn't intended for use by anyone under 18.
We don't knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time.
11. Contact
Questions about this Privacy Policy?
Use the support page in your account, or the contact details that the operator adds to this page.