Privacy policy
Last updated: 2026-09-23
Who is responsible
Sergio Belmonte Morales, tax ID 53911974C, registered address Calle Sevilla, 9, 14640, Villa del Río, Córdoba. For anything about your personal data, write to info@secureaikit.com.
What we store, and only if you ask us to
If you join the waiting list we store:
- Your email address, lowercased and trimmed.
- The language you were reading in, so the confirmation email is in that language.
- A campaign tag, when you arrived through a link that carried one (for example ?from=hn). It says which channel brought you, never who you are.
- The date you signed up and the date you confirmed.
- The exact consent text you were shown and its version number.
- A keyed hash of your shortened network (/24 for IPv4, /48 for IPv6). Not your IP address: the address is truncated first and then hashed with a secret that is not stored in the database, so this row cannot be turned back into a visitor. If that secret is not configured, nothing about your network is stored at all.
Why, and on what legal basis
To tell you when a new attack or a new version of the kit is published. That is the whole purpose: no newsletter, no drip sequence, no third-party advertising. The legal basis is your consent, article 6(1)(a) GDPR, which you give by ticking the box and confirm by clicking the link in the confirmation email. **Until 8 September 2026 this list had a different purpose** — telling you when the kit shipped — and it changed on the day the kit shipped; nobody who subscribed before that date receives email under the new purpose without consenting to it again.
Until you click that link nothing counts as a subscription, and the record deletes itself.
How long we keep it
Until you unsubscribe. A sign-up that is never confirmed is deleted after 30 days by a scheduled task, and again whenever somebody else signs up, so it goes even if the site is quiet.
While you are on the list we also keep, for each release notice we send you, a note that it went out to you — so that re-running a send does not write to you twice — and the unsubscribe link that came with it, so that it keeps working months later. Both carry your address, and both are deleted the moment you unsubscribe. If you unsubscribe we keep exactly one thing: your address on a do-not-contact list, so that a later release notice does not write to you again. It is stored for that reason and no other, it is never used to send you anything, and it is what makes an unsubscribe stick even though a buyer's address also lives in the purchase record, which we are required to keep. Ask us to remove it and we will.
The counters that rate-limit the form store two keyed hashes: one of your IP address, kept for at most an hour, and one of the email address you submitted, kept for at most a day. Both are hashes made with a secret that is not in the database, and neither can be read back. They are deleted by a scheduled task and again whenever somebody signs up. If that secret is not configured the counters still work — they are a defence that cannot be left switched off because a variable is missing — but the hash is then computed without it.
How many people visit
We count how many pages we serve each day and how many distinct people ask for them. What is stored is a number per day and per page: not your IP address, not your browser, not the pages you in particular looked at. No analytics company is involved and nothing is written to your browser, so there is nothing to clear there either.
To avoid counting you four times when you open four pages we have to recognise you as the same person, and for that a **fingerprint** is computed: a keyed hash of your address and your browser (without the version numbers), together with the date. The date is inside it on purpose, so tomorrow that fingerprint is a different one and you cannot be followed from one day to the next. It lives **48 hours** and a scheduled task deletes it. If that secret is not configured no fingerprint is computed at all: the pages served are counted and the people are not. What remains afterwards is the number, which is nobody's data.
The legal basis is legitimate interest, article 6(1)(f) GDPR: knowing whether anyone visits the site is necessary to keep running it, and of the ways to know that, the one that exposes you least was chosen deliberately. If you would rather we did not, write to us.
Who else sees it
For the waiting list, nobody other than what is said below. Buying is different, and has its own section further down. We do not sell, rent or share the list, and there is no analytics, no advertising pixel and no tracking on this site. If an email to you fails to send, a line goes to our own server error log so we can find out why. Your address is not in that line: only its first letter and its domain, which is enough to tell one failure from another and not enough to write to you.
The email is sent from our own server. Our hosting provider processes the data on our behalf as part of running the server.
If the anti-robot check (Cloudflare Turnstile) is switched on, your browser contacts Cloudflare when you submit the form, and our server then sends Cloudflare your IP address so it can confirm the answer. Cloudflare processes that technical data to decide whether you are a robot. That may involve a transfer outside the European Economic Area under Cloudflare's own safeguards. Whether it is switched on is a setting of this site, not something you can tell from this page; if the form you are looking at shows a Cloudflare check, it is on for that form.
If you buy
Buying is a different thing from the waiting list, and it stores different data. When you buy we store: your email address, the customer identifier Paddle gives us, the GitHub username you typed, which licence you bought, the amount and currency, the transaction identifier, and the state of your access. We do not see or store your card: that never touches this site.
The legal basis is the performance of the contract you entered into, article 6(1)(b) GDPR — not consent. We cannot deliver a licence without knowing who to give it to, and we cannot honour a refund without a record of the purchase.
We keep the purchase record for as long as the licence lasts, which is indefinitely, because the licence is perpetual and the record is what proves you hold one. Tax and accounting law also sets minimum retention periods for transaction records, and those apply on top.
Who else sees it when you buy
Two companies, and only these two. **Paddle** is the merchant of record: they take the payment, issue the invoice and handle the tax, so they are a data controller in their own right for that part and their privacy notice governs it. **GitHub** receives the username you gave us, because the delivery is an invitation to a private repository and there is no way to invite an account without naming it. GitHub is a company in the United States, so that is an international transfer.
Nothing else. There is still no analytics, no advertising and no tracking anywhere on this site, before or after you buy.
Your rights
You can withdraw your consent at any time, and every email on that list carries a link to do it: the link opens a page with a single button, and pressing it deletes your address and everything attached to it, immediately and permanently — all but the one entry on the do-not-contact list described under retention, which exists so that we do not write to you again, and which goes as soon as you sign up and confirm again. It takes two steps on purpose — a link that deleted you the moment it was opened would delete you the moment a mail scanner opened it for you. Two other kinds of email exist and they are not the same. A release notice — sent when a new version is published, both to that list and to people who bought the kit — always carries an unsubscribe link, buyers included; unsubscribing from it stops the notices and does not touch your access to the repository, which is perpetual and has nothing to renew. Emails about a purchase itself carry no such link: they are the delivery of something you paid for, and there is nothing to unsubscribe from.
You also have the rights of access, rectification, erasure, restriction, objection and portability. Write to info@secureaikit.com and we will answer.
If you think we have handled your data badly, you can complain to the Spanish data protection authority (Agencia Española de Protección de Datos, www.aepd.es).
How it is protected
The links in our emails carry single-use tokens that are stored hashed, never in plain text. The confirmation link expires after 72 hours. Your network is never stored in a form that can be read back.