Privacy Policy

Effective 9 July 2026 · SublimeKeys is a service operated by Sublimearts.io

This is a plain-language draft covering how data actually moves through SublimeKeys today. It is not a substitute for legal advice tailored to your jurisdiction — if you're relying on this at meaningful commercial scale, have it reviewed by a lawyer.

01. TWO KINDS OF DATA, TWO ROLES

SublimeKeys handles data in two different capacities, and it matters which one applies:

As a controller — for data about you, the developer using SublimeKeys (your account email, plan, billing details). We decide how this is used, and this policy is our commitment to you about it.

As a processor — for data about your own end customers, submitted when you issue or deliver a license key through SublimeKeys (typically just their email address). That data belongs to your relationship with your customer, not ours — you decide why it's collected and what it's used for, and you're responsible for having a lawful basis to process it. We only process it to run the service you asked us to run: generating keys, delivering them, sending sale-notification emails.

02. WHAT WE COLLECT ABOUT YOU

  • Account: your email address (via magic-link sign-in) and an API key we generate for you.
  • Billing: if you upgrade to a paid plan, Stripe processes and stores your payment details directly — we never see or store your card number. We keep your Stripe customer/subscription IDs and plan tier so we can sync your account limits.
  • Usage: the products and license keys you create, and basic counts (how many of each) used to enforce plan limits.
  • Login/security events: we log sign-ins (email + IP) internally to catch abuse and unauthorized access.

03. WHAT WE PROCESS ON YOUR BEHALF

When you issue a license key, you may attach your end customer's email address so we can deliver the key or send a notification. This is stored alongside the license record for as long as the license exists, and used only to operate that specific feature — never for marketing, never shared with anyone besides you (the developer who created it) and the infrastructure providers listed below.

04. WHO ELSE TOUCHES THIS DATA

We use a small set of infrastructure providers to run SublimeKeys, each only for the specific job listed:

  • Stripe — payment processing for paid plans.
  • Supabase — authentication (magic-link sign-in).
  • Resend — transactional email delivery (license keys, account notifications).
  • Hetzner — hosts the license server and its database (Nuremberg, Germany).

We don't sell data to anyone, and we don't use it for advertising.

05. DATA RETENTION & BACKUPS

Account and license data is kept for as long as your account is active, plus a reasonable period after cancellation in case you come back — canceling never deletes your existing products or keys. The underlying database is backed up daily (encrypted, off-site) purely for disaster recovery; backups are not used for any other purpose and are pruned on a rolling schedule.

06. YOUR RIGHTS

You can access or export your account data, and your end customers' data you've stored with us, from the dashboard at any time. To request deletion of your account or data we control, email us — we'll act on it within a reasonable time, subject to what we're legally required to retain (e.g. billing records). If you're in the EU/EEA, you have rights under GDPR including access, correction, deletion, and portability.

07. SECURITY

API keys are stored hashed, never in plaintext. Backups are encrypted before leaving our infrastructure. Access to production systems is restricted and key-based, not password-based. No system is perfectly secure, but we treat your data and your customers' data with the same care we'd want for our own.

08. CHANGES TO THIS POLICY

We may update this policy as the service evolves. Material changes will be communicated by email to active account holders before taking effect.

09. CONTACT

Questions about this policy or a data request? Reach us at hello@sublimearts.io. See also our Terms of Service.