Privacy Policy
Last updated: PENDING — publish date to be set at launch
1. Information We Collect
We collect account information you provide directly, and the observations the IRONCHILD desktop application makes on an authenticated device once you have signed in and activated a license.
2. Account Information
Full name, email address, and password. Authentication and password storage are handled entirely by Supabase Auth — IRONCHILD never stores your password in plain text.
3. Technical Information
To operate the service, we store your Stripe customer and subscription identifiers, and your license status (plan, device limit, active/expired state). On the device where IRONCHILD is installed and activated, the Core observes: human presence, keyboard and mouse behavior, device identity, network connections, running processes, files, and connected email accounts (when you configure one) — the same categories already described publicly on our homepage.
PENDING — this section describes what the Core technically observes. It does not yet state whose device/accounts IRONCHILD is intended to monitor (your own, an organization's, or another relationship) — that decision affects the legal basis for this collection and must be confirmed before this policy is treated as final.
4. How Information Is Used
To operate your account and subscription, to process payment, and to present the observations and evidence described above back to you inside the application. We do not sell personal information.
5. Supabase
Supabase is our authentication and database provider. Your account credentials, license records, and application data are stored on Supabase's infrastructure. PENDING — confirm whether a formal Data Processing Agreement with Supabase exists or is required.
6. Stripe
Stripe processes all payments. IRONCHILD never receives or stores your full card number — Stripe's own hosted Checkout page collects it directly.
7. Cookies / Local Storage
This website does not set first-party tracking cookies. It uses sessionStorage for a single, short-lived value that remembers you clicked "Create Account" so checkout can continue automatically after sign-up, and localStorage (via the Supabase Auth client) to keep you signed in between visits. When you are redirected to Stripe's own Checkout page, Stripe may set its own cookies on its own domain — outside our control and governed by Stripe's own privacy policy.
8. Third-Party Providers
Supabase (authentication, database) and Stripe (payments) are the only third-party providers this website and the IRONCHILD account system rely on. If you connect an email account inside the desktop application, that connection is made directly between IRONCHILD and your own mail provider.
9. Data Retention
PENDING — no data retention or deletion schedule has been defined yet.
10. Security
Access to your data is restricted using database-level row security, so an account can only ever read its own records. Passwords are managed entirely by Supabase Auth and are never visible to IRONCHILD in plain text.
11. User Rights
You may request access to, correction of, or deletion of your account information. PENDING — a self-service deletion flow does not exist yet; requests must go through support until it does.
12. Contact
PENDING — privacy contact email/address
13. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of IRONCHILD after a change takes effect constitutes acceptance of the revised policy.