Privacy Policy
Last updated 7 August 2026
This Privacy Policy explains what personal data Sylnar (“Sylnar”, “we”, “us”) collects when you use our website and software (the “Service”), why we collect it, who we share it with, and the rights you have over it. We collect only what we need to operate the Service.
1. Who is responsible for your data
Sylnar is the controller of the personal data described here. You can reach us about privacy by opening a support ticket from your dashboard.
2. What we collect
Information you provide
- Account details: your name and email address when you register, and a securely hashed form of your password (we never store your password in readable form).
- Beta applications and support messages: anything you submit through the beta form or a support ticket.
Information collected automatically
- Device identifier (HWID): a hardware fingerprint used to bind a licence to a device and to prevent sharing and abuse.
- Network information: your IP address and related request metadata, used for security, fraud and abuse prevention, and rate limiting.
- Session data: a session identifier stored in a cookie so you stay signed in; only a hashed form of the token is stored on our side.
- Usage and delivery logs: records of downloads and key events, used to operate and secure the Service.
Information from linked services
- Discord: if you link Discord, we receive your Discord user identifier so we can grant community roles tied to your subscription. You can unlink at any time.
- Payments: when you pay, our payment processor handles the transaction and reports back the payment status, amount, and an order reference. We store a record of the payment for accounting and access control. We do not receive or store your wallet keys, card numbers, or similar payment credentials.
3. Why we use it, and our legal bases
- To provide the Service (accounts, licensing, downloads, subscriptions): performance of our contract with you.
- To keep the Service secure (fraud, abuse, and sharing prevention, rate limiting, device binding): our legitimate interests in protecting the Service and our users.
- To communicate with you (email verification, security notices, support replies, beta decisions): performance of our contract and our legitimate interests.
- To meet legal and accounting obligations: compliance with applicable law.
4. Who we share it with
We do not sell your personal data. We share it only with service providers that help us run the Service, under agreements that require them to protect it:
- Hosting and infrastructure: our cloud hosting provider, which stores and serves the application and database.
- Network, delivery, and security: our CDN and security provider, which routes and protects traffic to the Service.
- Payments: our cryptocurrency payment processor, which processes your payment and returns its status.
- Email: our email delivery provider, used to send verification, security, and account messages.
- Community: Discord, if you choose to link it.
We may also disclose data where required by law, or to protect the rights, safety, and property of Sylnar, our users, or others.
5. International transfers
Some of our providers may process data outside your country, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards, such as the providers’ standard contractual clauses, to protect your data.
6. How long we keep it
We keep personal data for as long as your account is active and for as long as needed to provide the Service, resolve disputes, prevent abuse, and meet legal and accounting obligations. Payment and audit records may be retained longer where the law requires. When data is no longer needed, we delete or anonymise it.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. If you are in the EU or EEA, you also have the right to lodge a complaint with your local data protection authority. To exercise any of these rights, contact us using the details above; we may need to verify your identity first.
8. Cookies
We use a small number of strictly necessary cookies, primarily a session cookie that keeps you signed in and a security token used to protect forms. We do not use advertising or third-party tracking cookies. Because these cookies are essential to the Service, they cannot be switched off without breaking sign-in.
9. Security
We take reasonable technical and organisational measures to protect your data, including password hashing, encrypted transport, hashed session and verification tokens, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to limit what we collect.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. Material changes will be made reasonably prominent. Your continued use of the Service after a change takes effect means you accept the updated policy.
Questions about this policy? Open a support ticket from your dashboard.