Privacy policy
Last updated 2026-08-17. This describes what AppGuard collects when you request or hold a licence, why, who it passes through, and the rights you have over it.
1. Who controls this data
Andreas Paphitis, of 9 Riga Fereou, Akaki, 2720 Nicosia, Cyprus, trading as AppGuard, is the data controller for everything described here. See licence terms for who this is in the context of a purchase.
2. What we collect, and why
| When you submit the licence request form | Company or developer name, contact email, the application ID and environment suffixes you want covered, a short app description, and any notes you add. Used to decide the licence, sign it, and email it to you — the description exists so we can sanity-check the tier fits before issuing a paid licence. |
|---|---|
| When you pay for a licence | Billing name, address, and VAT number if supplied, plus payment details. Collected and processed directly by Stripe at checkout — we never see or store your card details. We do receive the billing address and VAT status back from Stripe, since EU reverse-charge tax treatment depends on it. |
| When you sign in as an admin | A username and password, checked against a stored scrypt hash. This applies only to AppGuard staff administering the licence queue, not to customers. |
3. Legal basis
Processing your request and issuing a licence is necessary to perform the contract you are asking us to enter into (GDPR Art. 6(1)(b)). Reviewing free-tier requests for abuse, and keeping records of what was issued to whom, is our legitimate interest in not having the free tier used to mint unlimited keys, and in being able to answer a licensing dispute (Art. 6(1)(f)). Where Stripe collects tax-relevant billing details, that is necessary to comply with our own tax obligations (Art. 6(1)(c)).
5. Retention
Licence request records — including an issued Licence Key and the details above — are kept as the record of what was issued to whom, since that is what we would need in a licensing dispute or a tax audit, and since a Licence Key remains valid until its own expiry with no revocation (see licence terms, Section 5). [This project does not yet commit to a fixed deletion schedule after a licence's business relevance ends — decide one, most likely tied to your jurisdiction's statutory record-keeping period for tax and commercial records, before this policy is final.]
7. Your rights
Under GDPR you can ask us to confirm what we hold about you, correct it, delete it (subject to Section 5's retention need), or object to our processing it. Contact us using the details below. If you are not satisfied with our response, you may complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or the supervisory authority in your own EU member state.
8. Security
Admin passwords are stored as salted scrypt hashes, never in plain text. The Ed25519 key
that signs licences, and the API keys for Stripe and Resend, live only in Google Secret
Manager, read only by the Cloud Functions that need them — never in this site's client-side
code or in Firestore. See web/README.md in the project repository if you want
the full technical detail.
9. Changes to this policy
We may update this policy as the site changes; the version in force is the one published here at the time you submit a request.
10. Contact
Questions about this policy, or a request concerning your data: andreaspaph@gmail.com.