Privacy policy

Template. svelte-saas-kit ships this page as a starting point. It describes what the kit does with personal data. Before launch, the operator must add its legal name and address, check each section against the law that applies to it, and have a lawyer review the text. This page is not legal advice.

1. Overview

This Privacy Policy explains what information we collect when you use this service, why we collect it, and the choices you have. In this policy, "we" means the operator of this service, and "you" means a person who visits the site or has an account. By using the service, you agree to the collection and use of information as described here.

2. Information We Collect

Account information: your email address and name. If you set a password, we keep only a secure hash of it, never the password in plain text. If you sign in with Google, we receive your Google email address, name, and profile picture.

Sign-in sessions: for each session we keep the IP address and the browser user agent, so that we can protect your account.

Billing information: the plan or credit pack you buy, the amount, the currency, the status, and the reference numbers from the payment provider. The payment provider handles your card or QRIS payment. We don't receive or store your full card number, bank account number, or e-wallet credentials.

Credits and usage: your credit balance, every credit change, your daily usage counts, and the jobs you start, so we can bill accurately and show you your history.

Support requests: your messages, the screenshots you attach, and your browser user agent.

Referrals: the referral code from a link that you opened.

Technical data: request IDs, IP addresses, browser type, and error details, collected automatically for rate limits, security, abuse prevention, and to fix problems.

3. How We Use Your Information

  • To operate the service: create your account, sign you in, keep your session safe, and enforce your plan limits and credit balance.
  • To take payments, add credits, give refunds, and keep accurate transaction and accounting records.
  • To answer support requests and to communicate with you about your account, billing, or service changes.
  • To detect and prevent fraud, abuse, and violations of our Terms of Service, for example with rate limits.
  • To understand which pages and features people use, and to improve the reliability and performance of the service.
  • To comply with the law.

4. Who We Share Information With

We share the minimum necessary information with service providers that help us run the service, under obligations to protect your data:

Provider Purpose Data
Our server host and Cloudflare Hosting, network, and HTTPS All data that the service handles
Polar Card payments in USD (merchant of record) Email, order, and payment data
Pakasir QRIS payments in IDR Order and payment data
Resend and Brevo Sign-in codes and service emails Email address and email content
PostHog Product analytics A random browser ID, page views, and product events
Sentry Error tracking Error details and request IDs, with personal data removed before sending
Cloudflare R2 and Neon Encrypted backups and a copy of financial records Database backups; payment and credit records
Google Google sign-in, when you choose it The sign-in request

Some providers keep data outside your country, for example in the United States or the European Union.

We also share information with authorities if the law requires it, or to protect the rights and safety of the operator, our users, or others.

We don't sell your personal information to third parties.

5. Data Retention

We retain account data while your account exists. We retain billing, payment, and credit records for as long as legal, tax, and accounting obligations require, also after your account is closed. We never edit these records; corrections are new entries.

  • Support screenshots: 60 days, then we delete them automatically.
  • Database backups: daily backups for 35 days and monthly backups for 12 months.

6. Your Rights

You can see most of your account information directly in your account.

You may request a copy of your data, a correction, or the deletion of your account and associated personal data by sending a request through the support page in your account. When we delete an account, we keep the records that we're required to retain for legal and billing reasons.

7. Security

We use industry-standard measures to protect your information: HTTPS for all traffic, hashed passwords, encrypted secrets on our servers, backups encrypted before they leave the server, and access controls. Only administrators can see account data, and we keep an audit record of administrator actions.

No system is perfectly secure, so we can't guarantee absolute security. We work to keep your data protected and will notify affected users if we become aware of a breach involving personal data.

8. Cookies & Browser Storage

Name Purpose Duration
Sign-in session cookie Keeps you signed in 30 days, renewed when you use the service; deleted when you sign out
PARAGLIDE_LOCALE Remembers your language Up to 400 days
Pending email cookie Remembers your email between the sign-up form and the code form 15 minutes
Referral cookie Remembers the referral code from a link 90 days
PostHog cookie and local storage A random ID for analytics, only when analytics is on Until you clear it

Analytics does not record sessions or capture clicks automatically. If your browser sends "Do Not Track", analytics collects no data.

We don't use third-party advertising trackers.

9. Children's Privacy

This service isn't intended for use by anyone under 18.

We don't knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time.

11. Contact

Questions about this Privacy Policy?

Use the support page in your account, or the contact details that the operator adds to this page.