Published policy
Privacy Policy
How Unoctu handles account, purchase, entitlement, delivery, support, and privacy-choice data.
Controller and contact
The controller is NaNZeta LLC, 2325 Granite Hill Dr, Texas, United States. The privacy contact is jorgeruizwilliams@gmail.com. The same contact handles data-protection requests where a separate data protection officer is not required.
Information, sources, and purposes
We receive information from you when you create an account, accept checkout terms, submit a support inquiry, choose privacy preferences, or use the launcher. We also receive payment and entitlement references from Stripe and limited delivery/security events from our services. We use this information to authenticate accounts, deliver packages, process payments, provide support, prevent fraud and abuse, secure the service, meet legal/accounting obligations, and remember explicit local preferences.
- Account and authentication: email address, verification time, session and login records.
- Commerce and entitlement: Stripe customer and transaction references, selected plan, checkout acceptance, entitlement status, and delivery-start event.
- Support: the message and contact details you choose to submit.
- Privacy choices and local preferences: consent choice, policy version, and browser/app settings stored locally.
Lawful bases
Where the GDPR or a similar law applies, our bases are performance of a contract for account, checkout, delivery, and support; legal obligation for tax, accounting, fraud, and required records; legitimate interests for security, abuse prevention, service integrity, and limited operational measurement; and consent for optional repository metadata or other optional processing. We do not use consent where a strictly necessary account or security operation is required.
Recipients, processors, and international transfers
Cloudflare provides hosting, application delivery, D1/R2 storage, and configured email services. Stripe provides checkout and billing. Resend or Cloudflare Email Service may deliver sign-in email. GitHub may receive a repository metadata request only after you choose optional processing. Providers may process data in the United States and other countries under their own policies and contractual arrangements. Where a transfer law applies, we use an available lawful transfer mechanism and can provide more information on request.
AI and model-provider data
Unoctu does not use account, support, customization, catalog browsing, or legal-preference data to train an AI model. The platform does not receive prompts, files, or model outputs from local AI apps through the normal launcher account flow. An AI-enabled catalog product may process prompts, files, images, audio, code, and outputs locally or through a remote provider selected by you. That provider receives the data sent through the connection, not Unoctu; review the product EULA, privacy notice, and provider terms.
Retention period and deletion
- Magic-link tokens expire after 15 minutes and are deleted when used or expired.
- Browser access cookies expire after the configured 15-minute production TTL. A separate opaque, HttpOnly browser refresh cookie keeps an active browser signed in for up to 365 days after normal use and ends on logout, account deletion, or server-side revocation. Launcher access tokens are renewed with a separate refresh credential held in the operating-system credential vault; that credential remains revocable server-side and ends on launcher logout, account deletion, or credential removal. Revoked-session records remain only until expiry.
- Account profile data is retained while the account is active. Account deletion removes or anonymizes identity links, deactivates entitlements, and preserves only records required for accounting, fraud prevention, disputes, refunds, or security.
- Checkout idempotency records expire after 24 hours. Support records are retained only as long as needed to resolve the request and meet legal or security obligations.
- Financial and tax records are retained for the period required by applicable law and accounting obligations; our operational target may be up to seven years where required.
Privacy rights and how to exercise them
Depending on your location and applicable exemptions, you may exercise the following rights:
- Right of access / right to know: ask whether we process your personal data and request a copy in a commonly used electronic format.
- Right to rectification: ask us to correct inaccurate or incomplete account information.
- Right to erasure: ask us to delete personal data where no overriding legal, security, accounting, or dispute-preservation duty requires retention. You can also delete an active account from the account menu.
- Right to restriction and objection: ask us to limit processing or object where the applicable law provides that right, including to legitimate-interest processing.
- Right to data portability: where applicable, receive data you provided in a structured, commonly used, machine-readable format or ask us to transmit it to another controller.
- Right to withdraw consent: withdraw optional cookie or metadata consent at any time through Privacy settings. Withdrawal does not affect processing already carried out lawfully.
- Right to lodge a complaint with a supervisory authority: if the GDPR applies, you may contact the data-protection supervisory authority in your habitual residence, place of work, or the place of the alleged infringement.
Submit a request through the account deletion controls or by emailing jorgeruizwilliams@gmail.com. We may verify your identity using information already associated with the request. We do not discriminate against you for exercising a privacy right. We will respond within the period required by applicable law; if we deny a request, we will explain why and, where required, provide an appeal route. If the Texas Data Privacy and Security Act applies to you, use that same email address to appeal a denial; unresolved concerns may be directed to the Texas Attorney General privacy complaint process. California residents can review the California Privacy Protection Agency resources.
Automated decisions, sale, and children
We do not make decisions producing legal or similarly significant effects using solely automated processing or profiling. We do not sell or share personal information for cross-context behavioral advertising. The service is not directed to children under 13, and we do not knowingly collect their personal information.
Updates
We publish the policy version and effective date above and will update this notice when our processing or legal obligations change.