Privacy Policy

Last updated: 8 September 2026. This is the short, honest version of what we store and why. The full legal text follows.

TL;DR

1. Who is the data controller?

The data controller is the CrimeCode operator (Italy, EU). For questions, privacy requests, or GDPR complaints, contact hello@crimecode.cc or @OpCrime1312 on Telegram.

2. What we collect and why

When you message our bot or sign in

When you place an order

When you use cloud sync

When you use the web app or a hosted backend

When you create or join a team

When an error happens

When you visit our sites or APIs

3. Cookies and local storage

The website at crimecode.cc does not use advertising cookies. The marketing checkout, web IDE, and desktop app use browser storage or secure session cookies for:

No third-party analytics, no advertising, no fingerprinting.

4. Payment data

Card entry and processing happen on Stripe's hosted checkout. We receive checkout/customer identifiers, payment status, amount, and the email used for delivery, but not the card number or security code. For crypto payments, we record the public blockchain transaction data needed to match the order: from wallet, to wallet, amount, tx hash, timestamp.

5. Who we share data with

We do not sell your data and never will. We do not share it with advertisers, governments, or other third parties outside of a valid legal request.

6. Retention

7. Your GDPR rights

If you are in the EU/EEA, you have the following rights under GDPR:

To exercise any right, message @OpCrime1312 from your linked Telegram account or email hello@crimecode.cc from your account address. We respond within 30 days.

8. Children

CrimeCode is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has created an account, please let us know and we'll delete it.

9. International transfers

Although our primary server is in the EU, some processors (including Tigris, Stripe, Sentry, Cloudflare, and Google) may process data outside the EEA under their applicable data-transfer terms, including Standard Contractual Clauses where required.

10. Security

We use HTTPS, signed session tokens, hashed account credentials, restricted admin access, encrypted backups, and regular automated backups. No security control is infallible; report concerns to hello@crimecode.cc.

11. Changes

We may update this policy occasionally. Material changes will be announced on this page with a new "last updated" date at least 14 days before they take effect. If the change expands the scope of data we process, we'll also message it to you via the Telegram bot.