We collect the minimum data needed to run the Service (your email, the licenses you create, basic usage metrics). We never sell it. You can export or delete everything anytime. Questions? [email protected].
This Privacy Policy explains how PWF Auth ("we", "us", "our") collects, uses, and shares information when you use our license-management platform (the "Service") at pwfauth.com.
1 Information we collect
1.1 Account information
- Username, email address, and bcrypt-hashed password you provide at signup.
- Optional 2FA secret if you enable two-factor authentication.
- IP address and user-agent of each login (used for security and audit logs).
1.2 Application data
- License keys, user accounts, sessions, app metadata, OTA updates, and audit logs you create through the dashboard or API.
- Heartbeats, geo-IP, and HWID fingerprints submitted by your end users (this is the data your apps send us — you control what you collect).
1.3 Usage analytics
- First-party visitor analytics: aggregate page views, referrers, and approximate country. Visitors are identified only by a salted, irreversible hash of the IP address — we do not store your raw IP for analytics.
- Google Analytics is loaded only after you accept analytics cookies via our cookie banner; if you decline, it is never loaded.
- These metrics tell us which features are used, error rates, and page-load performance. Account passwords and license keys are never sent to any analytics provider.
2 How we use your information
- To operate the Service (authenticate you, run your apps, send updates).
- To send you transactional emails (password resets, security alerts, important notices).
- To improve the Service (debug errors, prioritise features, prevent abuse).
- To comply with legal obligations (record-keeping, lawful subpoenas).
We do not use your data to train AI models, sell it to advertisers, or share it with anyone outside the subprocessors listed below.
3 Subprocessors
We rely on a small set of trusted vendors to deliver the Service:
4 Data retention
- Account data: kept until you delete your account.
- Audit logs: retained 90 days, then automatically purged.
- Backups: encrypted at rest, retained 30 days, then permanently destroyed.
5 Your rights (GDPR & CCPA)
If you are in the EU, UK, or California, you have the right to:
- Access a copy of your data (one-click export from your dashboard).
- Correct inaccurate data.
- Delete your account and all associated data ("right to be forgotten").
- Object to or restrict processing.
- Lodge a complaint with your local data-protection authority.
To exercise these rights, email [email protected]. We respond within 30 days.
7 Security
- All traffic is encrypted in transit with TLS 1.3.
- Passwords are hashed with bcrypt (cost 12).
- Database backups are encrypted at rest.
- We follow the OWASP Top 10 security practices and run regular vulnerability scans.
- To report a security issue, email [email protected].
8 Children
The Service is not intended for users under 16. We do not knowingly collect data from children.
9 Changes to this policy
We will notify you by email at least 30 days before any material change to this policy.
10 Contact
Questions about how we handle your data? We're happy to walk you through any of it.
Questions about your privacy?
Email our privacy team and we'll get back to you within 30 days.
[email protected]