Privacy Policy
Last updated: 2026-06-23
Provided in English — the English version is the legally governing text.
This policy explains how wyrmflow processes personal data in line with the EU General Data Protection Regulation (GDPR / RODO). The wyrmflow desktop app is local-first: it reads and works with your repositories on your own machine and does not send your code or repository contents to us. The processing described below relates to the website, your account, and billing.
Data controller
The controller responsible for your personal data is:
- Business name
- Andrii Romaniuk (sole proprietorship)
- Registered address
- ul. Długa 29, 00-238 Warszawa, Polska
- Privacy contact
- privacy@wyrmflow.com
We have not appointed a Data Protection Officer, as we are not legally required to do so. For our contact and identification details, see our legal information page.
What we process, and why
We process personal data only for the purposes below, each with its legal basis under Art. 6(1) GDPR:
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account & authentication — creating your account and keeping you signed in | Email address, authentication metadata | Performance of a contract — Art. 6(1)(b) | For the life of your account; deleted on account deletion |
| Billing & subscriptions — processing payments and issuing invoices | Email, billing details, subscription & payment records, tax ID where provided | Performance of a contract — Art. 6(1)(b); and compliance with a legal obligation (e.g. tax/accounting records) — Art. 6(1)(c) | Account-related billing data is deleted on account deletion; invoices and tax records are retained for the period required by applicable law |
| Website analytics — understanding aggregate website usage | Cookieless, aggregated metrics only; no individual tracking or fingerprinting | Legitimate interests — Art. 6(1)(f); no consent required as no personal data is stored on your device | Aggregated; not tied to an identifiable person |
Providing your email is necessary to create an account and use the paid service; without it we cannot provide the contracted service. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Who processes your data (processors & sub-processors)
We share data only with the service providers below, who act as processors on our instructions. We do not sell, rent, or monetise your data.
- Supabase (EU region) — hosts our database and authentication; stores account, authentication, and billing-related data.
- Stripe — processes payments and manages subscriptions and invoicing.
- Cloudflare — provides website hosting, content delivery (CDN), and security.
- Plausible — provides cookieless, privacy-friendly website analytics with no individual tracking.
- Resend — delivers transactional email (e.g. sign-in and account-related messages).
International transfers
We aim to keep personal data within the European Economic Area (EEA); for example, our Supabase database is hosted in an EU region. Some processors (such as Stripe, Cloudflare, Plausible, and Resend) may process limited data outside the EEA. Where that happens, the transfer is protected by an appropriate safeguard under Chapter V GDPR — typically the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision for the destination country.
Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted ("right to be forgotten").
- Restriction — ask us to limit how we process your data.
- Data portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time (this does not affect processing already carried out).
You can delete your account and its associated data at any time from your account settings. To exercise any other right, email privacy@wyrmflow.com. We will respond within the time limits set by the GDPR.
Right to complain
If you believe we have mishandled your data, you have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), or with the supervisory authority in your EU country of residence.
Cookies
We use a single, strictly-necessary session cookie to keep you signed in to the account area. This cookie is required for the service to function, so no consent is needed for it. Our website analytics (Plausible) are cookieless and store no information on your device, so we do not show a cookie consent banner. We do not use advertising or third-party tracking cookies.