Your account. Username, e-mail address, a hash of your password (we never
store the password itself), the interface language you registered in, and whether
your address has been confirmed.
Google sign-in. If you sign in with Google, we receive your e-mail address,
your name as Google reports it and your Google account identifier. We do not
receive your Google password and have no access to anything else in your Google
account.
Purchases. Payment metadata from our payment provider: identifiers of the
checkout session, subscription and plan, the state of the purchase, the paid
period and the moment of payment. We never receive or store your card
details — they are handled by the payment provider on their own pages.
The payment provider's event log. Every notification the provider sends us is
stored whole, as it arrived, so that a purchase can be reconstructed if something
goes wrong. It contains the identifiers above and no card data.
Messages you send us. If you use the contact form, we store your name,
e-mail address, subject, the text of your message, the interface language, the
page you sent it from and the moment you accepted these documents. The message
text is free-form, so please do not put anything there that you would not want
stored — including other people's personal data. A copy is also e-mailed to us.
Technical logs. Our web server records the IP address, the requested address,
the time and the browser's user-agent string. This is what lets us notice an
attack or an outage. The contact form is a deliberate exception: the address it
was sent from is not stored with the message, it only lives in memory for up
to an hour to limit how often the form can be submitted.
Analytics. Google Analytics, and only if you agree to it — see the
Cookie Policy.