1. Who we are
Intervest Technologies LLC, doing business as Cipher Tools, operates ciphertools.app and the Cipher Tools application. We are the data controller for the personal data described here. You can reach us at [email protected].
2. What we collect
| Data | Where it comes from | Examples |
|---|---|---|
| Discord identity | Discord OAuth when you sign in (scope: identify only) | Discord user id, username, display name, avatar URL. We never see your Discord email, password, messages or server list. |
| Portal activity | Our website | Sign-in count, first and last sign-in, the version of the Terms you accepted and when, the IP address you accepted from. |
| Licence data | Created when you buy or redeem a key | Licence key (encrypted at rest), plan, status, expiry, the Discord id it belongs to, a hashed hardware identifier of the device it is bound to, activation and release history. |
| Payment data | Stripe, our payment processor | Stripe customer id, subscription id, invoice status, the email you gave at checkout. We never receive your card number. |
| Application telemetry | The desktop app while it is open | App version, a hashed device identifier, which modules are running and their success/failure counts, last heartbeat time. No account credentials, no contents of your tasks. |
| Server logs | Our hosting providers | IP address, user agent, request path and time, error traces. Used for security and debugging. |
| Hosted mailboxes | Only if you use our mail service | Mailbox addresses provisioned for your licence and the messages delivered to them (typically verification codes), which the app reads to complete your tasks. |
| Support messages | You | Anything you send to support, including screenshots. |
What we do not collect: the accounts, passwords, proxies, profiles, phone numbers or other data you create or configure in the application. Those are stored on your own device as plain files and are never uploaded to us, except where a request-based task is processed on our servers for the duration of that task (see Section 6).
3. Why we use it, and on what legal basis
- To provide the Service (contract): authenticate you, issue and validate your licence, enforce the one-device limit, deliver purchased plans, route verification codes to your tasks.
- To take payment and keep accounts (contract, legal obligation): process subscriptions and refunds through Stripe, keep records required by tax and accounting law.
- To keep the Service secure and prevent abuse (legitimate interest): detect key sharing, fraud, chargebacks and attacks; maintain an audit trail of administrative actions.
- To support you and improve the product (legitimate interest): answer support requests, understand which modules are used and where they fail.
- To communicate (contract, legitimate interest): service notices such as renewals, outages, and changes to terms. We do not send marketing email.
4. Cookies
We use only strictly-necessary, first-party cookies. There are no analytics or advertising cookies, and we do not use third-party trackers.
| Cookie | Purpose | Lifetime |
|---|---|---|
ct_session | Keeps you signed in to your dashboard. Signed so it cannot be forged. | 7 days |
ct_oauth_state | Protects the Discord sign-in against forged redirects. | 10 minutes |
ct_next | Remembers the page you were heading to before signing in. | 10 minutes |
ct_admin, ct_admin_fail | Operator-only: the admin panel's second factor and its lockout counter. | 2 hours / 15 minutes |
Stripe sets its own cookies on its checkout and billing pages under Stripe's privacy policy.
5. Who we share it with
We do not sell personal data and we do not share it with advertisers. We share it only with the providers needed to run the Service, each bound by their own terms and data-protection commitments:
- Stripe (payments, subscriptions, invoices, tax).
- Discord (sign-in; and, if you interact with our Discord server, under Discord's own policy).
- Cloudflare (website hosting, edge functions, DDoS protection).
- Our server hosting provider (application servers and database hosting).
- Our mail-server provider, if you use hosted mailboxes.
- Anti-bot and captcha-solving providers, which receive the request data needed to complete a request-based task on your behalf but no data about you as a person.
We may also disclose data if required by law, to enforce our Terms, to protect the rights and safety of Cipher Tools, our customers or the public, or in connection with a sale or merger of the business (in which case this policy continues to apply).
6. How long we keep it
- Account and licence records: for the life of your account and for as long afterwards as tax, accounting and dispute-handling obligations require; keys themselves are marked revoked or expired rather than deleted so that a reused key can be recognised.
- Payment records: retained by Stripe and by us as long as required by tax law.
- Server logs: typically 30 days.
- Application telemetry: live instance data is discarded shortly after the app stops reporting; aggregate counts are kept on the licence record.
- Request-based task data processed on our servers: held in memory for the duration of the task and streamed back to your app; not stored afterwards except in error logs, which are purged with the logs above.
- Hosted mailbox contents: kept while the mailbox exists; you can delete mailboxes from the app, and they are removed when your licence ends.
7. Security
Licence keys are stored hashed and encrypted; device identifiers are stored hashed; secrets live in server environment configuration and never in the website or the application. All traffic is over HTTPS. Administrative access is restricted to a single operator account behind Discord sign-in and a second factor, and every administrative action is logged. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
8. Your rights
Depending on where you live (including under the GDPR, UK GDPR and the CCPA/CPRA), you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data, subject to records we must keep by law;
- restrict or object to certain processing, including processing based on legitimate interests;
- port your data in a machine-readable format;
- withdraw consent where processing is based on consent;
- not be discriminated against for exercising these rights, and (California) to know that we do not "sell" or "share" personal information as those terms are defined in the CPRA;
- complain to your local data-protection authority.
To exercise a right, email [email protected] from the Discord-linked identity or with proof you control the account. We respond within 30 days (45 days for California requests) and may need to verify your identity first. Much of your data is visible directly on your dashboard.
9. International transfers
Our providers operate primarily in the United States. If you are outside the US your data will be transferred there. Where required we rely on standard contractual clauses or equivalent safeguards offered by those providers.
10. Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy. Material changes will be announced on the website, in the application, or by email, with the new version date at the top. Continued use after the effective date means you accept the update.
12. Contact
Privacy questions and requests: [email protected].
Cipher