PWF Auth PWF Auth
功能 工作原理 定价
Getting started API 参考 SDKs & tools
常见问题 博客 更新日志 联系我们
English English العربية العربية Deutsch Deutsch Nederlands Nederlands Português Português Русский Русский Türkçe Türkçe 简体中文 简体中文
客户门户 登录 免费注册 ··
Legal · Privacy

Privacy Policy

How PWF Auth collects, uses, and protects your data — in plain English, with no dark patterns.

Updated April 22, 2026 ~4 min read GDPR & CCPA aligned
On this page
1. Information we collect 2. How we use it 3. Subprocessors 4. Data retention 5. Your rights 6. Cookies 7. Security 8. Children 9. Changes 10. Contact
The short version

We collect the minimum data needed to run the Service (your email, the licenses you create, basic usage metrics). We never sell it. You can export or delete everything anytime. Questions? [email protected].

This Privacy Policy explains how PWF Auth ("we", "us", "our") collects, uses, and shares information when you use our license-management platform (the "Service") at pwfauth.com.

1 Information we collect

1.1 Account information

  • Username, email address, and bcrypt-hashed password you provide at signup.
  • Optional 2FA secret if you enable two-factor authentication.
  • IP address and user-agent of each login (used for security and audit logs).

1.2 Application data

  • License keys, user accounts, sessions, app metadata, OTA updates, and audit logs you create through the dashboard or API.
  • Heartbeats, geo-IP, and HWID fingerprints submitted by your end users (this is the data your apps send us — you control what you collect).

1.3 Usage analytics

  • First-party visitor analytics: aggregate page views, referrers, and approximate country. Visitors are identified only by a salted, irreversible hash of the IP address — we do not store your raw IP for analytics.
  • Google Analytics is loaded only after you accept analytics cookies via our cookie banner; if you decline, it is never loaded.
  • These metrics tell us which features are used, error rates, and page-load performance. Account passwords and license keys are never sent to any analytics provider.

2 How we use your information

  • To operate the Service (authenticate you, run your apps, send updates).
  • To send you transactional emails (password resets, security alerts, important notices).
  • To improve the Service (debug errors, prioritise features, prevent abuse).
  • To comply with legal obligations (record-keeping, lawful subpoenas).

We do not use your data to train AI models, sell it to advertisers, or share it with anyone outside the subprocessors listed below.

3 Subprocessors

We rely on a small set of trusted vendors to deliver the Service:

CloudflareDNS, CDN, DDoS protection, TLS termination.
Email providerTransactional email delivery (password resets, alerts, notices).
TelegramOperational notifications to our team (e.g. a new signup). We send only your username, account ID, and — if known — your country; never your email or IP address.
Google AnalyticsAggregate usage analytics — loaded only with your consent.
Hosting providerServer & database infrastructure.

4 Data retention

  • Account data: kept until you delete your account.
  • Audit logs: retained 90 days, then automatically purged.
  • Backups: encrypted at rest, retained 30 days, then permanently destroyed.

5 Your rights (GDPR & CCPA)

If you are in the EU, UK, or California, you have the right to:

  • Access a copy of your data (one-click export from your dashboard).
  • Correct inaccurate data.
  • Delete your account and all associated data ("right to be forgotten").
  • Object to or restrict processing.
  • Lodge a complaint with your local data-protection authority.

To exercise these rights, email [email protected]. We respond within 30 days.

6 Cookies

We use first-party functional cookies (session token, theme preference, "remember me" flag) that are always active. Analytics cookies (Google Analytics) are set only if you accept them via our cookie banner — decline, and none are set. We never use advertising or cross-site tracking cookies.

7 Security

  • All traffic is encrypted in transit with TLS 1.3.
  • Passwords are hashed with bcrypt (cost 12).
  • Database backups are encrypted at rest.
  • We follow the OWASP Top 10 security practices and run regular vulnerability scans.
  • To report a security issue, email [email protected].

8 Children

The Service is not intended for users under 16. We do not knowingly collect data from children.

9 Changes to this policy

We will notify you by email at least 30 days before any material change to this policy.

10 Contact

Questions about how we handle your data? We're happy to walk you through any of it.

Questions about your privacy?

Email our privacy team and we'll get back to you within 30 days.

[email protected]
PWF Auth PWF Auth

开发者真正愿意使用的许可证服务器与用户认证后端。自助式、托管式、安全可靠。

产品

  • 功能
  • 定价
  • 工作原理
  • 常见问题
  • KeyAuth 替代方案
  • Cryptolens alternative
  • Keygen alternative
  • License keys for .NET

开发者

  • Getting started
  • API 参考
  • SDKs & tools
  • API 状态(JSON)
  • 更新日志
  • 控制台
  • 获取 API 密钥

公司

  • About us
  • 联系我们
  • 系统状态
  • 报告安全问题

法律

  • 隐私政策
  • 服务条款
  • GDPR
  • Cookie 政策
© 2026 PWF Auth. 版权所有。
所有系统运行正常