githubEdit

shield-halvedPrivacy Policy

How we collect, use, and protect personal data.

Summary

We collect the minimum data needed to run the service. We do not sell personal data. You can access, delete, and export your data.

Who this applies to

This policy covers:

  • The SchemaFX website and docs.

  • The hosted SchemaFX service (if you operate one).

  • Support, community, and other official channels.

If you self-host SchemaFX, you control the data in your instance. You are the data controller for your deployment.

What data we collect

Data you provide

  • Account data (name, email, organization).

  • Content you submit (schemas, records, files, messages).

  • Support requests and correspondence.

Data we collect automatically

  • Basic usage and diagnostic data.

  • Device and browser information.

  • IP address and approximate location.

  • Security events (login attempts, suspicious activity).

Cookies and similar tech

We use cookies for:

  • Session and authentication.

  • Security.

Why we process personal data (purposes)

We process personal data to:

  • Provide and operate the service.

  • Authenticate users and prevent abuse.

  • Provide support.

  • Improve performance and reliability.

  • Comply with legal obligations.

Data retention

We keep personal data only as long as needed. We also keep data longer if law requires it.

Typical retention (edit to match reality):

  • Account data: while the account is active.

  • Logs: 30 days.

Sharing and disclosure

We share personal data only when needed.

Service providers (processors)

We may use vendors for:

  • Hosting and storage.

  • Email delivery.

  • Error reporting.

  • Analytics.

  • Payments.

Maintain a list here:

  • Sliplane.io - Server Hosting

  • Cloudflare - Domain Hosting & Email provider

We may disclose data if required by law. We will challenge overbroad requests when we can.

Security

We use reasonable technical and organizational measures.

  • Encryption in transit.

  • Access controls and audit logs.

  • Backups.

  • Vulnerability management.

No method is perfect. We cannot guarantee absolute security.

Your rights

If GDPR or similar laws apply, you may have rights to:

  • Access your personal data.

  • Correct inaccurate data.

  • Delete data.

  • Restrict or object to processing.

  • Data portability.

  • Withdraw consent.

  • Lodge a complaint with a supervisory authority.

Contact us at [email protected]. We may ask you to verify your identity.

Changes to this policy

We may update this policy. We will post the new version here. We will update the effective date.

  • Effective date: 2026-01-25

Contact

Questions or requests:

Last updated