Privacy Policy

Last updated September 6, 2026

This policy explains what personal data BulkyGen collects, why, and how long it is kept. The data controller is [[LEGAL ENTITY NAME]], registered in [[JURISDICTION]], at [[BUSINESS ADDRESS]]. For any privacy request, use the contact page.

What we collect and why

Account details

Your name and email address, and a hashed form of your password. We use these to create and secure your account and to send licence keys, payment updates, expiry reminders and password resets. We do not send marketing email. Kept for as long as your account is open, and for a period afterwards where we are required to retain related financial records (see below).

Payment proof screenshots

If you pay by bank transfer or wallet, you upload an image showing your payment. We use it only to confirm the transfer and issue your licence. These files are stored outside the public web root and are accessible only to you and to staff reviewing the order. They are retained as part of the order record for accounting and dispute-resolution purposes.

Device identifiers

To enforce the per-device licence limit, the desktop application computes a one-way hash from characteristics of your computer and sends that hash, together with a label you choose. We store the hash and label, not the underlying hardware identifiers, and we cannot reverse the hash. A device record is removed when you deactivate that device or when the licence ends.

Technical and security data

We record IP addresses and timestamps in two places: short-lived rate-limiting counters that guard login, password-reset, contact and licensing endpoints against abuse, and an audit log of security-relevant events (sign-ins, licence activation and validation, administrative actions). Rate-limiting counters expire automatically, typically within minutes to 24 hours. Audit-log entries are kept for as long as needed to investigate incidents and meet legal obligations.

Financial records

Orders, the currency and amount paid, and licence history are retained for as long as required by accounting and tax law in [[JURISDICTION]] — commonly several years — even after an account is closed. Where an account is deleted, these records are anonymised so they can no longer be linked to you by name or email.

Cookies

The website sets a single session cookie so you can stay signed in. There are no third-party advertising or analytics cookies.

Who we share it with

We share data only with service providers that make the service work: our email delivery provider (to send transactional email), our hosting provider (which stores the database and uploaded files), and, once online card payment is enabled, the payment processor that handles that transaction. We do not sell personal data.

Your rights

You can access and correct your account details from your dashboard, and request deletion of your account. Some records must be kept for legal and accounting reasons even after deletion; those are anonymised. Depending on where you live, you may also have the right to object to or restrict certain processing, and to complain to your local data protection authority in [[JURISDICTION]].

Security

Passwords are stored using a strong one-way hash, stored secrets are encrypted, and traffic to the website and licensing API is served over HTTPS.

Changes

We will post changes to this policy on this page with a new effective date.