Privacy Policy

Last updated: 20 June 2026
This Privacy Policy explains what personal data FrontScale (https://frontscale.dev) collects, why, and your rights over it. The data controller is FrontScale, operated by an individual based in Georgia (the "Controller", "we", "us"). Contact: privacy@frontscale.dev. Our full legal identity and address are available on request at privacy@frontscale.dev and appear on your invoice, which is issued by Freemius as the seller of record (Merchant of Record).

1. What we collect

When you sign in with Google and use your account, we collect:
  • Identity from Google sign-in: your email address, name, and profile image.
  • Purchase & license records: that you bought, when, and your license/access status.
  • Technical data: IP address and basic request logs (kept for security and fraud prevention).
We do not collect special-category data, and we do not run advertising or analytics trackers.

2. Why we use it and our legal basis

  • To create your account, grant lifetime access, deliver the product, and send transactional/license emails — basis: performance of a contract (GDPR Art. 6(1)(b)).
  • To keep the service secure and prevent fraud, including IP logging — basis: our legitimate interests (Art. 6(1)(f)).
  • Only if we ever add marketing or analytics — basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
Providing this data is necessary to create an account and receive the product; without it we cannot deliver the service.

3. Who we share it with

We use a small number of trusted providers (processors/recipients), each under their own data-processing terms:
  • Google — Sign-in (OAuth); independent controller of your Google account
  • Freemius — Payments & Merchant of Record (billing, tax, invoices)
  • Vercel — Website hosting & logs
  • Neon — Database (your account & purchase records)
Freemius acts as our Merchant of Record and is an independent controller for the payment, billing, and tax data collected at checkout. See Freemius's privacy policy: https://freemius.com/privacy/. We do not sell or share your personal data.

4. International transfers

Our hosting and database providers (Vercel, Neon) are US-based, and we operate from Georgia, which has no EU adequacy decision. Where your data is transferred outside the EEA/UK, it is protected by the safeguards in our providers' data-processing agreements (EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework).

5. How long we keep it

We keep your account and purchase data for the life of your account. If you ask us to delete your account, we erase or anonymise your profile data within 30 days, except records we are required to keep by law. Billing and tax records are held by Freemius as Merchant of Record.

6. Your rights

Subject to applicable law (GDPR/UK GDPR and the Law of Georgia on Personal Data Protection), you can:
  • Access the data we hold about you, and get a copy (portability).
  • Correct inaccurate data, or ask us to delete it (“right to be forgotten”).
  • Restrict or object to certain processing, and withdraw consent where we rely on it.
  • Complain to a supervisory authority (in Georgia, the Personal Data Protection Service, pdps.ge; or your local EU/UK authority).
To exercise any right, email privacy@frontscale.dev. We respond within one month and there is no charge.

7. Cookies & local storage

We use only what is strictly necessary to run the site — no analytics, marketing, or advertising trackers — so no cookie consent banner is required. Specifically:
  • Session cookie “better-auth.session_token” — essential: keeps you signed in. Without it, accounts don't work.
  • Theme and language preference — stored in your browser's localStorage because you set them; not sent to us, not used for tracking.
If we ever add analytics or marketing, we will show a consent banner first and load those scripts only after you opt in.

8. Security

We serve the site over HTTPS, keep credentials out of our codebase, and restrict database access. If a data breach is likely to affect your rights, we will notify the relevant authority within 72 hours and affected users without undue delay.

9. Changes & contact

We may update this policy; the “Last updated” date above reflects the latest version. Questions or requests: privacy@frontscale.dev.
This document is provided in English. It is a general template, not legal advice.