Privacy Policy
A short policy, because we collect little. Your email, a hash of your machine's hardware ids, and what you bought.
What we collect, and why
Your email address, so we can send your licence key and answer support. Your name and profile picture if you sign in with Google, so the account page shows who is signed in.
Your Machine ID, because the licence key is derived from it. This is a 16-character hash of hardware identifiers produced on your computer - we receive the hash, never the underlying serial numbers.
Your order history: tier, amount, date, and the terms version you accepted. We are required to keep transaction records for tax purposes.
What we do not collect
We do not collect telemetry from the desktop application. Kurm Optimizer performs its licence check offline, on your machine, without contacting us.
We never receive your card number. Card details are entered directly into the payment processor's own hosted input and go straight to them; our servers never see them.
We do not use advertising or analytics cookies. The only cookie set is the session cookie that keeps you signed in.
Who else sees your data
Our payment processor, to take the payment and to handle chargebacks. Our email provider, to deliver your key. Our hosting provider, which stores the database. Each of these processes data on our instructions only.
We do not sell personal data, and we do not share it for advertising.
How long we keep it
Order and licence records are kept for seven years, which is the retention period tax law requires. Account records are kept until you ask us to delete them.
Deleting your account removes your profile and sign-in details. Order records are retained in a reduced form - amount, date, and order reference, without your name or email - because we cannot lawfully delete them earlier.
Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Email us and we will respond within one business day and complete the request within 30 days.
If you are in the UK or EU you may complain to your data protection authority. If you are in California you have the rights described in the CCPA, including the right to know and the right to delete; we do not sell personal information, so there is nothing to opt out of.
Security
Passwords, where an account uses one, are stored only as bcrypt hashes and are never recoverable in plain text. Sessions expire and can be revoked by signing out.
Traffic is served over HTTPS only. Access to the order database is restricted to the application and to administrators.