Legal

Privacy policy

What the website stores

Account records include your name, email address, password hash, role, timestamps, and sign-in timestamp. Developer submissions include store metadata, package integrity values, review history, and the package file stored in the configured GitHub repository. Waitlist and support forms store the information you submit.

What the device stores

Device settings, saved networks, apps, app-private data, maps, captures, tracks, and logs are local to device flash or microSD unless you deliberately upload or submit them. The public website does not automatically collect device telemetry.

Passwords and sessions

Passwords are hashed and are never stored in plaintext. Authentication sessions use signed tokens in HTTP-only cookies. No administrator can recover your original password.

Service providers

MongoDB stores application records, GitHub stores release files and submitted packages, and Vercel hosts the application. Their infrastructure processes data needed to provide those services.

Retention and requests

Submission review records may be retained for integrity and abuse prevention. Support records are retained while relevant. Before public launch, publish a jurisdiction-specific retention schedule and contact address for access or deletion requests.

Contact

Privacy questions: privacy@esp32doomsday.com.