Privacy Policy
The short version. We collect your email address if you give it to us, and almost nothing else. The linter runs on your machine. The playground runs in your browser — configs you paste never leave your device. We use no tracking cookies, no ad networks, and we never sell your data.
01What we collect
| DATA | WHY | WHERE IT GOES |
|---|---|---|
| Email address (waitlist, purchases, support) | To send you the product, license, and product updates you asked for | Stored in our database (Supabase, US region); email sent via Resend |
| Signup source tag (e.g. "landing", "devto") | To know which content is useful | Same database row as your email |
| Bot-verification token (Cloudflare Turnstile) | To keep scripted abuse out of the signup form | Verified with Cloudflare; not stored by us |
| Aggregate, anonymous page-view statistics (Cloudflare Web Analytics) | To understand traffic | Collected by Cloudflare; cookieless; no personal identifiers |
02What we deliberately do not collect
- Your bench configurations. The command-line linter runs entirely on your machine or CI runner and never transmits configs. The browser playground executes as WebAssembly inside your browser tab — pasted configs are processed locally and never sent to any server.
- Tracking cookies, advertising identifiers, cross-site trackers. We don't use them.
- Analytics that identify you. Our web analytics are aggregate and cookieless.
03How we use data
We use your email address to deliver what you signed up for: the product, your license, critical service notices, and — if you joined the waitlist — launch updates. We do not sell, rent, or share personal data with third parties for their marketing. We do not use your data to train models.
04Processors
We use a small set of subprocessors, each under its own data-protection terms: Cloudflare (hosting, bot detection, cookieless analytics), Supabase (database, US region), and Resend (transactional email delivery). Payment processing, when enabled, will be handled by a PCI-compliant provider; we never see or store card numbers.
05Retention and security
Waitlist emails are kept until you ask us to delete them or the list is retired. The database enforces row-level security; the public signup key can only insert, never read, modify, or delete. All traffic is served over HTTPS. No system is perfectly secure, but we keep the amount of data that exists to be breached deliberately small.
06Your rights (GDPR, CCPA/CPRA, and friends)
Wherever you live, you can: access the data we hold about you, correct it, delete it, export it, or object to / restrict its processing. California residents: we do not sell or share personal information as defined by the CCPA/CPRA. EEA/UK residents: our legal basis for processing is your consent (waitlist) and contract performance (purchases); you may also lodge a complaint with your local supervisory authority. To exercise any right, email hello@standguard.dev — a human will handle it. We will not discriminate against you for exercising your rights.
07International transfers
We are US-based and our processors store data in the United States. If you use the Service from elsewhere, your data will cross borders; by using the Service you consent to that transfer.
08Children
The Service is a professional tool and is not directed at children under 16. We do not knowingly collect their data.
09Changes and contact
If this policy changes materially, we will post the new version here and update the effective date; waitlist members get an email. Questions, access, or deletion requests: hello@standguard.dev.