Legal

Privacy Policy

This policy explains what personal data the EmbedStudio website and account service collect, why, who else sees it, and what you can ask us to do about it. It covers embed-studio.com and the account, licensing and purchasing features on it.

It does not cover the EmbedStudio desktop application itself. As it stands today the desktop application works offline: it does not contact our servers, does not report usage, and verifies your licence file on your own computer without asking us anything.

If we ever add optional error reporting or usage statistics, it would be off unless you switch it on, and this policy would describe exactly what it sends before it is available.

Who is responsible

The data controller is Tehnično svetovanje, Oleg Gordiushenkov s.p., Češnjica 12, 1261 Ljubljana-Dobrunje, Slovenia — a registered sole trader (samostojni podjetnik), registration number 7407106000.

For anything in this policy, including any request about your own data, write to [email protected].

The short version

What we collect, and why

Visiting the site

Our web server records a standard access log entry for each request: the IP address, the time, the page requested, the response status, the referrer and the browser's user-agent string. This is ordinary server operation — diagnosing faults, and identifying abuse. These logs are rotated daily and kept for 14 days.

The site is served through Cloudflare, which terminates the connection and therefore also processes the same connection data as part of delivering and protecting the site.

Legal basis: our legitimate interest in operating a working, secure website (GDPR Art. 6(1)(f)).

Analytics

We use Umami, which we host ourselves on our own server — the statistics are not sent to an analytics company. Umami sets no cookies, assigns no persistent identifier, and does not follow visitors across other websites. It records page views, referrer, and coarse information such as browser, operating system, device type and country.

Because no cookie or similar identifier is stored on your device and the result is aggregate rather than individual, we rely on legitimate interest (Art. 6(1)(f)) rather than consent for this.

Creating an account

We store:

Legal basis: performance of our agreement with you (Art. 6(1)(b)) — an account is what a licence is attached to.

Signing in with Google

You can sign in with a Google account instead of a password. If you do, Google tells us three things about that account: a stable identifier for it, the email address on it, and whether Google has confirmed that address. We store the identifier and the address, together with the date you connected the account and the date you last used it to sign in.

We ask for nothing else. We request only the standard openid, email and profile scopes, which give no access to your mail, your files, your contacts or anything else in your Google account. We do not keep the access token Google issues, and we never ask for one that would let us act on your behalf later: we ask Google who you are once, when you sign in, and nothing after that.

If the address Google gives us already has an EmbedStudio account, we connect the two rather than creating a second one, so your licences and orders stay where they are. If it has none, we create an account — and because Google has confirmed the address, we treat it as confirmed. We never do either unless Google says the address is verified.

Google is a separate controller for what happens on their side, including the sign-in screen itself; their own privacy policy covers that. You can disconnect the account from your account page at any time, as long as you have a password set, and you never have to use this at all — email and password remain the ordinary way in.

Legal basis: performance of our agreement with you (Art. 6(1)(b)) — it is how you reach the account you asked us to create.

Staying signed in, and security

This site sets two cookies, both strictly necessary:

Neither cookie is used for analytics or advertising, and neither requires consent under the ePrivacy rules because the service you asked for cannot work without them. We store only a hash of the session token, so the value in your cookie does not exist in our database. Email-verification and password-reset links are held the same way: we store the hash, never the link. Verification links expire after 24 hours and password-reset links after 1 hour.

To limit brute-force and abuse, we count recent attempts against sign-in, registration, reset and checkout endpoints. These counters store a SHA-256 hash of the rule plus the identifier, and never the identifier itself — so this mechanism does not build a record of which addresses or IP addresses tried to sign in.

Legal basis: performance of the agreement (Art. 6(1)(b)) for the session, and legitimate interest in the security of the service (Art. 6(1)(f)) for the rest.

Licences

A licence is issued to your account. When you activate one, you supply a machine identifier — a value computed on your own computer and shown to you by the desktop application, which you paste in. We record it so that a licence file is bound to the machine it was issued for, and so support can help when you change computers.

The machine identifier is derived from your operating system's installation identifier. It is not a hardware serial number, it does not identify you personally, and it tells us nothing about what you do on that computer. We also keep an append-only record of each licence file issued — when, for which machine, and a checksum of the file — so a licence's history can be reconstructed if it is disputed.

If your licence was one you paid for, activating it also asks you to confirm that you want your licence file generated straight away and that you understand you then lose your right to withdraw from the purchase. We record that you gave that confirmation, when, and which wording you were shown — and we send it back to you by email. We keep it because the law that makes the confirmation meaningful is also the law that requires us to be able to evidence it. Free licences are not asked, because there is nothing to withdraw from.

Legal basis: performance of the agreement (Art. 6(1)(b)) for the licence and the machine identifier, and our legal obligation (Art. 6(1)(c)) for the record of that confirmation.

Buying a licence

Payment is taken by our payment processor on their own hosted checkout page. Card details are entered on the processor's page and never reach our server — we never see, receive or store a card number.

The processor reports the completed payment back to us, and we record what we need to raise your invoice: your name, billing address, country, email address, an optional VAT or tax identification number if you gave one, what was bought, the amount and currency, and the processor's reference for the payment.

Our payment processor is named on the checkout page before you pay, and again on your invoice and in the confirmation email for the order. It acts as an independent controller for the payment itself and handles your data under its own privacy policy. If you would like to know who processes payments before you start a purchase, ask us and we will tell you.

Legal basis: performance of the agreement (Art. 6(1)(b)) for the purchase, and our legal obligation to issue and retain accounting documents (Art. 6(1)(c)) for the invoice.

Email we send you

Transactional messages — address verification, password reset, order confirmation, licence activation and your invoice — are delivered through Brevo (Sendinblue SAS, France) acting as our processor.

Please note that Brevo rewrites links in the HTML part of outgoing messages to pass through its own tracking domain, and injects open-tracking pixels and an unsubscribe header that we do not compose. We do not use the resulting engagement data, and the plain-text part of each message carries the real, unrewritten link.

⚠️ Because those unsubscribe headers are added by the delivery provider rather than by us, using them may suppress delivery of transactional mail to your address — including future password-reset links. If you can no longer receive our messages, write to us and we will look into it.

We operate no mailing list and run no campaigns. We would never add you to one without asking: any such mailing would be something you opt into deliberately, refuse without consequence, and leave at any time.

Who else processes your data

RecipientPurposeWhat they see
Our hosting provider Runs the virtual server Everything stored on the server, as the infrastructure operator
Cloudflare Content delivery, TLS, protection against attack Connection data for each request
Our payment processor Taking payment, issuing refunds Payment and billing details you enter at checkout
Brevo Delivering transactional email Your email address and the message content
Google Drive Off-site storage of encrypted backups Encrypted archives only — see below
Google Signing in with a Google account, if you choose to That you signed in to EmbedStudio, and when

Backups are encrypted before they leave our server, with AES-256-GCM and a key held separately from the storage account. The storage provider holds ciphertext and cannot read it.

Some of these providers may process data outside the European Economic Area. Where they do, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, as set out in that provider's own terms.

We do not sell personal data, and we do not disclose it to anyone else except where the law requires it.

How long we keep it

Deleting your account

You can delete your account yourself, from your account page. We ask for your password first, because the action cannot be undone from the page.

Deleting removes your password, your name, your last sign-in time, every sign-in session and any connected Google account, and detaches your email address from the account: the address is replaced with a placeholder that cannot receive mail, and only a one-way hash of it is kept, for the reason in the next paragraph. Once that is done we can no longer find the account from your address, you cannot sign in, and no password reset is possible.

What we keep, and why. The account record itself is not removed, because things attached to it must survive: the invoices raised against it and their order data, which accounting law requires us to keep and which we cannot delete on request; the record that you asked for a licence to be supplied immediately and acknowledged losing your withdrawal right, which evidences a statement you made to us; and the history of which licences were issued to which machine. What remains identifies nobody by name or address — it is the record, not you.

Licence files you have already downloaded are unaffected. EmbedStudio checks a licence on your own computer and never contacts us, so a file keeps working on the machine it was issued for until the date printed in it. What you lose is the ability to download it again.

Coming back. The hash of your address is kept so that registering again with the same address restores your account rather than creating an empty one — your licences and orders come back with it. It is restored only after you confirm the address from the email we send, so typing an address is never enough to reach an account. If you would rather we did not keep that hash, write to us and say so.

Encrypted backups age out on a rolling schedule, so data you have deleted may persist in a backup for a short period before it is overwritten.

Your rights

Under the GDPR you may ask us to:

Write to [email protected]. We will reply within one month. We may need to confirm you control the account's email address before acting on a request.

If you are not satisfied with how we have handled it, you may complain to the Slovenian Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si), or to the supervisory authority where you live.

Security

The site is served over HTTPS only. Passwords are hashed with Argon2id. Session, verification and reset tokens are stored only as hashes. Backups are encrypted before leaving the server. Access to the production server is restricted to named administrator accounts using SSH keys, and secrets are held in root-owned files outside the application's own directory.

No system is perfectly secure. If you believe you have found a vulnerability, please write to [email protected] rather than disclosing it publicly, and we will work with you on it.

Children

EmbedStudio is a professional development tool. It is not directed at children, and we do not knowingly create accounts for anyone under 16.

Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects you, we will tell you by email at the address on your account.