Privacy Policy
Last updated: 2026-07-31
Provided in English — the English version is the legally governing text.
This policy explains how wyrmflow processes personal data in line with the EU General Data Protection Regulation (GDPR / RODO). The wyrmflow desktop app is local-first: it reads and works with your repositories entirely on your own machine.No repository content, commit messages, file contents, or file paths are transmitted to us, and we never sell, rent, or monetise your data. The processing described below relates only to the website, your account, billing, and — if you explicitly opt in — anonymous crash diagnostics.
Data controller
The controller responsible for your personal data is:
- Business name
- Andrii Romaniuk (sole proprietorship)
- Registered address
- ul. Długa 29, 00-238 Warszawa, Polska
- Privacy contact
- privacy@wyrmflow.com
We have not appointed a Data Protection Officer, as we are not legally required to do so. For our contact and identification details, see our legal information page.
What we process, and why
We process personal data only for the purposes below, each with its legal basis under Art. 6(1) GDPR:
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account & authentication — creating your account and keeping you signed in | Email address, authentication metadata | Performance of a contract — Art. 6(1)(b) | For the life of your account; deleted on account deletion |
| Billing & subscriptions — processing payments and issuing invoices | Email, billing details, subscription & payment records, tax ID where provided | Performance of a contract — Art. 6(1)(b); and compliance with a legal obligation (e.g. tax/accounting records) — Art. 6(1)(c) | Account-related billing data is deleted on account deletion; invoices and tax records are retained for the period required by applicable law |
| Website analytics — understanding aggregate website usage | Cookieless, aggregated metrics only; no individual tracking or fingerprinting | Legitimate interests — Art. 6(1)(f); no consent required as no personal data is stored on your device | Aggregated; not tied to an identifiable person |
| Crash & error diagnostics — diagnosing app crashes and errors to fix bugs (desktop app; strictly optional, off by default) | Error and stack-trace details, app version, and OS/runtime context — only if you turn diagnostics on. Never includes repository content. | Consent — Art. 6(1)(a); you can withdraw it at any time in the app's settings | Retained only as long as needed to investigate the issue, then deleted |
Providing your email is necessary to create an account and use the paid service; without it we cannot provide the contracted service. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Who processes your data (processors & sub-processors)
We share data only with the service providers below, who act as processors on our instructions. We do not sell, rent, or monetise your data.
- Supabase (EU region) — hosts our database and authentication; stores account, authentication, and billing-related data.
- Stripe — processes payments and manages subscriptions and invoicing.
- Cloudflare — provides website hosting, content delivery (CDN), and security, including the Turnstile CAPTCHA that protects our forms from automated abuse.
- Plausible — provides cookieless, privacy-friendly website analytics with no individual tracking (EU-hosted).
- Resend — delivers transactional email (e.g. sign-in and account-related messages).
- Sentry — receives anonymous crash and error diagnostics only if you opt in to diagnostics in the desktop app.
International transfers
We aim to keep personal data within the European Economic Area (EEA); for example, our Supabase database is hosted in an EU region and our website analytics (Plausible) are EU-hosted. Some processors are based in the United States and may process limited data outside the EEA. Where that happens, the transfer is protected by an appropriate safeguard under Chapter V GDPR:
- Stripe, Cloudflare, Resend, and Sentry are certified under the EU–US Data Privacy Framework, and additionally rely on the European Commission's Standard Contractual Clauses (SCCs).
- Supabase relies on the Standard Contractual Clauses (SCCs), with our database region set within the EU.
You can request a copy of the relevant safeguards by emailingprivacy@wyrmflow.com.
Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted ("right to be forgotten").
- Restriction — ask us to limit how we process your data.
- Data portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time (this does not affect processing already carried out).
You can delete your account and its associated data at any time from your account settings. To exercise any other right, email privacy@wyrmflow.com. We will respond within the time limits set by the GDPR.
Right to complain
If you believe we have mishandled your data, you have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), or with the supervisory authority in your EU country of residence.
Cookies
We use a single, strictly-necessary session cookie to keep you signed in to the account area. This cookie is required for the service to function, so no consent is needed for it. Our contact form is protected by Cloudflare Turnstile, which may store a short-lived, strictly-necessary token solely to verify that a submission is not automated. Our website analytics (Plausible) are cookieless and store no information on your device, so we do not show a cookie consent banner. We do not use advertising or third-party tracking cookies.