Legal

Privacy Policy

Effective 6 September 2026Version 2026-09-06Contact [email protected]
The short version. We collect the minimum needed to sell you a licence and make it work: your Discord identity, your licence key and the device it is bound to, payment records held by Stripe, and operational logs. We do not sell your data, we do not run advertising, and we do not use tracking cookies. Accounts you generate with the software live on your own computer, not with us.

1. Who we are

Intervest Technologies LLC, doing business as Cipher Tools, operates ciphertools.app and the Cipher Tools application. We are the data controller for the personal data described here. You can reach us at [email protected].

2. What we collect

DataWhere it comes fromExamples
Discord identityDiscord OAuth when you sign in (scope: identify only)Discord user id, username, display name, avatar URL. We never see your Discord email, password, messages or server list.
Portal activityOur websiteSign-in count, first and last sign-in, the version of the Terms you accepted and when, the IP address you accepted from.
Licence dataCreated when you buy or redeem a keyLicence key (encrypted at rest), plan, status, expiry, the Discord id it belongs to, a hashed hardware identifier of the device it is bound to, activation and release history.
Payment dataStripe, our payment processorStripe customer id, subscription id, invoice status, the email you gave at checkout. We never receive your card number.
Application telemetryThe desktop app while it is openApp version, a hashed device identifier, which modules are running and their success/failure counts, last heartbeat time. No account credentials, no contents of your tasks.
Server logsOur hosting providersIP address, user agent, request path and time, error traces. Used for security and debugging.
Hosted mailboxesOnly if you use our mail serviceMailbox addresses provisioned for your licence and the messages delivered to them (typically verification codes), which the app reads to complete your tasks.
Support messagesYouAnything you send to support, including screenshots.

What we do not collect: the accounts, passwords, proxies, profiles, phone numbers or other data you create or configure in the application. Those are stored on your own device as plain files and are never uploaded to us, except where a request-based task is processed on our servers for the duration of that task (see Section 6).

3. Why we use it, and on what legal basis

4. Cookies

We use only strictly-necessary, first-party cookies. There are no analytics or advertising cookies, and we do not use third-party trackers.

CookiePurposeLifetime
ct_sessionKeeps you signed in to your dashboard. Signed so it cannot be forged.7 days
ct_oauth_stateProtects the Discord sign-in against forged redirects.10 minutes
ct_nextRemembers the page you were heading to before signing in.10 minutes
ct_admin, ct_admin_failOperator-only: the admin panel's second factor and its lockout counter.2 hours / 15 minutes

Stripe sets its own cookies on its checkout and billing pages under Stripe's privacy policy.

5. Who we share it with

We do not sell personal data and we do not share it with advertisers. We share it only with the providers needed to run the Service, each bound by their own terms and data-protection commitments:

We may also disclose data if required by law, to enforce our Terms, to protect the rights and safety of Cipher Tools, our customers or the public, or in connection with a sale or merger of the business (in which case this policy continues to apply).

6. How long we keep it

7. Security

Licence keys are stored hashed and encrypted; device identifiers are stored hashed; secrets live in server environment configuration and never in the website or the application. All traffic is over HTTPS. Administrative access is restricted to a single operator account behind Discord sign-in and a second factor, and every administrative action is logged. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

8. Your rights

Depending on where you live (including under the GDPR, UK GDPR and the CCPA/CPRA), you may have the right to:

To exercise a right, email [email protected] from the Discord-linked identity or with proof you control the account. We respond within 30 days (45 days for California requests) and may need to verify your identity first. Much of your data is visible directly on your dashboard.

9. International transfers

Our providers operate primarily in the United States. If you are outside the US your data will be transferred there. Where required we rely on standard contractual clauses or equivalent safeguards offered by those providers.

10. Children

The Service is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes will be announced on the website, in the application, or by email, with the new version date at the top. Continued use after the effective date means you accept the update.

12. Contact

Privacy questions and requests: [email protected].