Privacy Policy
Privacy Policy
Last updated: July 12, 2026 Version: 2026-07-12 Data controller: Devglaze LLC
This Privacy Policy explains what Devglaze LLC ("we", "us", "our") collects when you use ToolsPow, why we collect it, how long we keep it, and the rights you have over it. It is written to satisfy the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and equivalent laws in other regions.
1. Data we collect
1.1 When you visit anonymously (no signup)
- IP address — used only for rate-limiting, abuse logging, and ban enforcement. Never shared with third-party advertising networks.
- Browser user-agent string — used for compatibility and abuse pattern detection.
- Uploaded files — for the duration of the conversion, plus up to 1 hour, then auto-deleted.
- Cookies + browser localStorage — see the full inventory in section 4.
- Cookie-consent choice — stored as an audit event with a hashed IP and truncated user-agent so we can prove compliance under GDPR Article 5(2).
1.2 When you sign up
- Name, email, hashed password (we never see your plaintext password).
- If you sign up via Google: your Google account ID, email, name, and profile picture URL.
- Email verification OTP + token (15-minute expiry, then deleted).
1.3 When you use tools while signed in
- Per-tool usage counters (slug + day + count) for quota enforcement.
- Job records (slug, status, timing, error if failed) for the My Files page.
- Retained uploads (excluding videos) until you delete them from
/user/files.
1.4 When you pay
- Stripe customer ID and subscription state are stored locally.
- We never see or store full card details — Stripe processes the payment directly.
- Token ledger entries (purchase, grant, spend, refund).
1.5 When you use the API or MCP
- Hashed API token + per-token last-used timestamp.
- Same job + usage records as the web interface.
1.6 When something breaks
- Server-side error logs (visible only to the admin at
/admin/errors). - Optionally, Sentry — if a Sentry DSN is configured (see section 5).
2. Why we collect each item — legal bases
| Data | Purpose | Legal basis (GDPR Article 6) |
|---|---|---|
| Email + password | Account access | 6(1)(b) contract |
| IP + user-agent | Abuse prevention, rate limits | 6(1)(f) legitimate interest |
| Uploaded files | Run your conversion | 6(1)(b) contract |
| Usage counters | Enforce per-tier quotas | 6(1)(b) contract |
| Stripe customer ID | Bill subscriptions, ledger token purchases | 6(1)(b) contract |
| Essential cookies | Session, CSRF, consent choice | 6(1)(f) legitimate interest + ePrivacy strictly-necessary exemption |
| Preferences cookies | Save theme, favorite tools | 6(1)(a) consent |
| Analytics cookies (if enabled) | Improve the product | 6(1)(a) consent |
| Marketing cookies (if enabled) | Ads and cross-site targeting | 6(1)(a) consent |
| Error logs | Fix bugs, security incidents | 6(1)(f) legitimate interest |
| Consent audit trail | Demonstrate compliance | 6(1)(c) legal obligation (Article 5(2)) |
3. Data retention
| Data category | How long we keep it |
|---|---|
| Uploaded files (anonymous) | Deleted 1 hour after conversion, always. |
| Uploaded files (signed-in, retained) | Until you delete them from /user/files, or 30 days after account deletion. |
| Uploaded videos | Never retained. Deleted 1 hour after conversion regardless of account. |
| Account data (name, email, password hash) | For as long as your account is active; deleted 30 days after account deletion request (grace period for recovery). |
| Payment records (Stripe IDs, ledger entries) | 7 years (accounting law retention). |
| Tool job records (slug, timing, status) | 90 days rolling window; older records aggregated to per-day counters. |
| Cookie consent choice + audit event | 5 years (Article 5(2) accountability). |
| IP addresses in web-server logs | 90 days rolling. |
| Error logs | 180 days, then auto-purged. |
4. Cookies + localStorage inventory
4.1 Cookies
| Name | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
toolspow_session |
Essential | Session identifier for signed-in users | 2 hours rolling | First-party |
XSRF-TOKEN |
Essential | CSRF protection for form submissions | 2 hours rolling | First-party |
tp_uid |
Essential | Anonymous visitor ID for rate-limiting + abuse detection | 400 days | First-party |
| (No third-party analytics or marketing cookies are set today.) |
4.2 Browser localStorage
| Key | Category | Purpose | Duration |
|---|---|---|---|
cookie_consent_v2 |
Essential | Your granular consent choice + policy version — stops the banner reappearing | Until you clear browser storage or reset via footer link |
favorite-tools |
Preferences (opt-in) | Your starred tools list | Until you clear browser storage |
theme |
Preferences (opt-in) | Light/dark theme choice | Until you clear browser storage |
4.3 Withdrawal of consent
Click Cookie preferences in the footer of any page. The preferences modal reopens; toggle categories off and click Save — that is exactly as easy as giving consent, satisfying GDPR Article 7(3).
If we materially change our cookie use, we bump the policy version, and every user is re-prompted on their next visit.
5. Third-party data processors
We share only the minimum data necessary with these processors. All are bound by data-processing agreements or equivalent contractual protections.
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe | Payments | Card data (goes directly to Stripe, never through us), email |
| Sign-In + Drive picker (both opt-in per use) | Google account ID, email, name | |
| Dropbox | Dropbox Chooser (opt-in per use) | OAuth session, file ID |
| Microsoft | OneDrive picker (opt-in per use) | OAuth session, file ID |
| Cloudflare Turnstile | Bot protection on signup/login/contact forms | Anonymous fingerprint tokens |
| cPanel ClamAV | Malware scanning of uploaded files (local, our server) | File content (streamed to local scanner, not third party) |
| rdap.org | WHOIS Domain Lookup routing | Domain name you look up |
| ipwho.is | What Is My IP geolocation | IP address you look up (may be yours) |
| Sentry (if DSN configured) | Error monitoring | Stack traces, requesting URL, hashed user ID |
| Our SMTP mail provider | Sending account, verification, and reply emails | Email address, message body |
6. Your rights under GDPR
You have the following rights concerning your personal data. To exercise any of them, email info@toolspow.com with subject line "DPR: [right]" — for example "DPR: Access". We respond within 30 days.
- Right of access (Article 15) — request a copy of all data we hold about you.
- Right to rectification (Article 16) — ask us to correct inaccurate data.
- Right to erasure / "right to be forgotten" (Article 17) — delete your account and associated data. Some data (payment records retained 7 years under accounting law; audit-trail records, 5 years) may survive; we minimize what survives.
- Right to restrict processing (Article 18) — request we stop processing your data pending resolution of a complaint.
- Right to data portability (Article 20) — receive your data in a machine-readable format (JSON export).
- Right to object (Article 21) — object to processing based on legitimate interest.
- Right not to be subject to automated decision-making (Article 22) — we do not use profiling or fully automated decision-making that produces legal effects for you.
- Right to withdraw consent (Article 7(3)) — for any processing based on consent (analytics, marketing cookies), withdraw it anytime via the Cookie preferences link in the footer.
- Right to lodge a complaint with a supervisory authority (Article 77) — if you're in the EU/EEA, complain to your national data protection authority. In the UK, complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Phase 3 of our GDPR-compliance rollout adds self-service buttons in your account dashboard for Export my data and Delete my account — so you don't need to email us for the common cases.
7. Consent management
- How consent is captured: on your first visit, a banner offers Accept all / Reject non-essential / Customize. If you Customize, a modal lets you toggle Preferences / Analytics / Marketing individually. Essential cookies are always active — they're strictly necessary to run the site.
- Where consent is stored:
- Guests: browser
localStorageunder keycookie_consent_v2(JSON with categories + policy version). - Signed-in users: same localStorage key + also stored in your account (
users.cookie_consent,users.cookie_consent_at,users.cookie_consent_version) so it follows you across devices.
- Guests: browser
- Audit trail: every consent event (guest or authed) writes a
consent_eventsrow with hashed IP and truncated user-agent so we can demonstrate compliance under Article 5(2). Retained 5 years. - Re-prompt on policy change: the current policy version is embedded in every consent record. If we bump the version, you'll see the banner again on your next visit.
- No pre-ticked boxes: all non-essential categories default OFF. Consent is only recorded when you click a button explicitly (Recital 32).
8. International transfers
Our primary server is in the European Union. Data may be transferred to our processors (Stripe, Google, Microsoft, etc.) whose infrastructure spans multiple regions. Where transfers happen outside the EEA, our processors use Standard Contractual Clauses or equivalent safeguards approved by the European Commission.
9. Security
- All traffic is over HTTPS (TLS 1.2+, HSTS enforced).
- Passwords stored with bcrypt (cost 12).
- Two-factor authentication available for all users; required for admins.
- API keys stored as SHA-256 hashes (never plaintext).
- Stripe handles all card data; we never see the PAN.
- File uploads scanned by:
- Layer 0: Extension deny-list (blocks .exe, .php, .dll, etc.).
- Layer 1: Extension allowlist per tool.
- Layer 2: finfo magic-byte content sniff.
- Layer 3: PDF payload markers (JavaScript, Launch, EmbeddedFile).
- Layer 4: ClamAV signature scan (3.6M signatures, daily updates).
- Web Application Firewall (Imunify360 / mod_security) at the Apache layer.
- Continuous file-integrity monitoring via CloudLinux CageFS.
No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and applicable supervisory authorities within 72 hours as required by GDPR Article 33.
10. Children
The Service is not directed at children under 16 in the EU (or the equivalent age of consent in your jurisdiction; 13 in the US under COPPA). If you believe a child has provided us with personal data, please email info@toolspow.com and we will delete it.
11. Automated decision-making and profiling
We do not use fully automated decision-making or profiling that produces legal or similarly significant effects for you. Tool jobs are run as-requested and returned as-is; we do not score users or make decisions about them based on behavior patterns.
12. Changes to this policy
Material changes to this Policy will be announced here and (for paying customers) by email at least 14 days before they take effect. Non-material changes (fixed typos, clarified wording) will not trigger a version bump.
13. Contact
- General questions: contact form or info@toolspow.com
- Data protection requests (GDPR): info@toolspow.com with subject "DPR: [access/erasure/etc.]"
- Data breach reports: security@toolspow.com
- Company: Devglaze LLC
- Data controller for EU/EEA users: Devglaze LLC (contact as above)
This Privacy Policy is written to cover the data flows we actually run. Version 2026-07-12.