Privacy Policy
Last updated: 8 September 2026. This is the short, honest version of what we store and why. The full legal text follows.
TL;DR
- Depending on how you sign in, we store your email, username and password hash or your Telegram handle + user ID, plus orders, licenses, sessions, and data you explicitly sync.
- We do not receive your payment card number. Stripe hosts card entry; on-chain payments expose public transaction data.
- Service data lives on a Hetzner-hosted server in Helsinki (EU), with encrypted backups to object storage. Rotating access logs contain normal request metadata such as IP, path, and timestamp.
- You can request account deletion by messaging @OpCrime1312 or emailing
hello@crimecode.cc.
1. Who is the data controller?
The data controller is the CrimeCode operator (Italy, EU). For questions, privacy requests, or GDPR complaints, contact hello@crimecode.cc or @OpCrime1312 on Telegram.
2. What we collect and why
When you message our bot or sign in
- Telegram user ID (numeric) and username if set — used to identify your account and deliver messages back to you. Stored in the
customerstable. Legal basis: performance of contract (Art. 6(1)(b) GDPR). - Email address, account username, and password hash when you choose email/password registration. We use these to authenticate you and deliver account and license messages. We do not store the plaintext password.
- Device label (app name + hostname) at sign-in time — stored in
auth_sessionsso you can see which devices have an active session. You can revoke any session from the Account dialog.
When you place an order
- Order record: plan, status, amount, creation time, confirmation time. No KYC data.
- Wallet transaction hash once confirmed on-chain — this is public information by definition.
- Stripe checkout identifiers and customer email for card purchases, used to reconcile payment and deliver the license. Stripe retains the card details under its own privacy policy.
- License token signature (12 bytes) — NOT the full token. We never store the part that a customer pastes into the app.
When you use cloud sync
- Anything you explicitly push via
/license/sync/<key>— currently the app uses two keys,client.settings(preferences JSON) andclient.recent-projects(list of recent folder paths and names). You control what's pushed; we never scrape the rest of your filesystem. - Max 64 KB per key. Stored unencrypted at rest on the server disk, but transmitted only over HTTPS.
When you use the web app or a hosted backend
- Prompts, model responses, tool output, and session metadata are processed by the backend you select and may be stored there so you can resume the session.
- Files or code are transmitted only when you attach them, include them in a prompt, or authorize a tool to read them. Your selected AI model provider also receives the request content needed to generate a response.
- When you use the desktop app with a local sidecar, workspace and session storage stays on that machine except for requests you send to an external model provider or features you explicitly sync.
When you create or join a team
- Team name, member list (customer IDs), roles, pending invite identifiers (Telegram handles or emails).
- Live-session metadata (title + small JSON state) for the duration of the session; cleared when you end it or after 90 seconds of no heartbeat.
When an error happens
- A stack trace + the HTTP path/method that triggered the error is sent to Sentry. Sentry is configured with
sendDefaultPii: false, so we do not intentionally forward your IP, cookies, or user agent in error events.
When you visit our sites or APIs
- Our reverse proxy writes rotating access logs containing standard request metadata, including IP address, requested path, status, and timestamp. We use these logs for reliability, abuse prevention, and incident response.
- The marketing homepage loads fonts from Google Fonts, so Google receives normal connection metadata such as your IP address and user agent.
3. Cookies and local storage
The website at crimecode.cc does not use advertising cookies. The marketing checkout, web IDE, and desktop app use browser storage or secure session cookies for:
- The signed session token used for checkout and app authentication.
- Your active workspace preference (
client.active-workspace). - Your settings snapshot and recent project list (also synced to the cloud when you're signed in).
No third-party analytics, no advertising, no fingerprinting.
4. Payment data
Card entry and processing happen on Stripe's hosted checkout. We receive checkout/customer identifiers, payment status, amount, and the email used for delivery, but not the card number or security code. For crypto payments, we record the public blockchain transaction data needed to match the order: from wallet, to wallet, amount, tx hash, timestamp.
5. Who we share data with
- Hetzner (Germany — Helsinki region) — hosts our application server and database in the EU.
- Tigris Data (Delaware, USA, EU region) — S3-compatible backup storage, receives nightly encrypted copies of the database.
- Stripe — processes card checkout and sends us payment confirmation, customer email, and transaction identifiers. Stripe's privacy policy applies to its hosted checkout.
- Telegram Messenger LLP — delivers bot messages to you. Telegram sees the bot-chat content (the bot is how we get messages to you). Telegram has its own privacy policy at telegram.org/privacy.
- Cloudflare — provides DNS, CDN, and web delivery for public CrimeCode domains and sees normal request metadata such as IP, URL, and timestamps.
- Google Fonts — serves the marketing site's fonts and receives normal web request metadata.
- AI model providers you select — receive prompts, attachments, and tool context needed to answer your request under their own terms and privacy policies.
- CoinGecko — USD→crypto exchange rate. We send them no user data; we just fetch the public rate.
- mempool.space, litecoinspace.org, etherscan.io, Blockcypher — block explorers queried by our on-chain payment poller. We only send wallet addresses and they see that our server is polling them; no user data leaves.
- Sentry — receives error traces with default PII collection disabled.
We do not sell your data and never will. We do not share it with advertisers, governments, or other third parties outside of a valid legal request.
6. Retention
- Customer and license records: kept for as long as the license is active, plus 24 months after the last expiry, so we can honour reactivation requests.
- Auth sessions: 30 days from issue, automatically purged.
- Pending invites: kept until claimed or cancelled.
- Live-session metadata: kept for 30 days after the session ends, then purged.
- Hosted IDE sessions: kept until you delete them or close the associated account, subject to backup retention.
- Audit log: 12 months.
- Web access logs: size-capped rotating files retained only until they are replaced.
- Backups: rolling 30 days on Tigris, then overwritten.
7. Your GDPR rights
If you are in the EU/EEA, you have the following rights under GDPR:
- Access — request a copy of everything we hold about you.
- Rectification — correct anything that's wrong.
- Erasure ("right to be forgotten") — delete your account and all its data.
- Restriction — pause processing while you investigate a concern.
- Portability — receive your data in a machine-readable format (JSON).
- Objection — object to processing that relies on legitimate interests.
- Complaint — file a complaint with your local supervisory authority (in Italy: Garante per la Protezione dei Dati Personali, gpdp.it).
To exercise any right, message @OpCrime1312 from your linked Telegram account or email hello@crimecode.cc from your account address. We respond within 30 days.
8. Children
CrimeCode is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has created an account, please let us know and we'll delete it.
9. International transfers
Although our primary server is in the EU, some processors (including Tigris, Stripe, Sentry, Cloudflare, and Google) may process data outside the EEA under their applicable data-transfer terms, including Standard Contractual Clauses where required.
10. Security
We use HTTPS, signed session tokens, hashed account credentials, restricted admin access, encrypted backups, and regular automated backups. No security control is infallible; report concerns to hello@crimecode.cc.
11. Changes
We may update this policy occasionally. Material changes will be announced on this page with a new "last updated" date at least 14 days before they take effect. If the change expands the scope of data we process, we'll also message it to you via the Telegram bot.