Privacy Policy
Last updated: 14 September 2026
Privogrid is operated by WaveLinker OÜ, a company registered in the Estonian Commercial Register (Äriregister) under registry code 17450210, with its registered address at Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Estonia (VAT number EE102974542) — the "controller", "we", "us". This policy explains what we collect, why, where it goes and how you can control it. By using Privogrid you agree to this policy.
You must be at least 13 years old (Estonia's digital-consent age under the GDPR and the Estonian Personal Data Protection Act, Isikuandmete kaitse seadus) to use Privogrid. We do not knowingly collect data from children below that age.
1. What we collect
- Account data: your email address and a salted hash of your password (PBKDF2-SHA256 — we never store the password itself). If you sign in with Google we receive your Google account email and a verified-email flag; we do not receive your Google password.
- Subscription data: your plan, billing status and renewal date, and your Stripe customer and subscription IDs. Card numbers are entered on Stripe's pages and never reach our servers.
- Licensing data: on the Free plan, a hardware identifier (HWID) of the computer you first signed in on, used to lock the trial to one computer.
- Synced profiles (paid plans, optional): if you turn on cloud sync, your browser profiles — settings, fingerprint seeds and, with cookie sync, cookies — are encrypted on your device (AES-256-GCM) before upload. We store only the encrypted data, together with plain metadata such as profile IDs and "last updated" timestamps. The key material needed to unlock a profile is held per account on our server so that your other devices can open the same profiles — so this is encryption at rest and in transit, not zero-knowledge storage.
- Shared profiles (Pro and up): when you share a profile with a teammate it is wrapped with the recipient's public key on your device. Only the recipient's private key — kept on their computer, never on our server — can open it. We cannot read shared profiles.
- Team data (Pro and up): workspace name, member emails, roles, profile assignments and an audit log of team actions.
- Support messages: what you write to us in the support chat or by email, so we can answer you.
- Technical logs: IP address and request timestamps on our API, kept briefly for rate-limiting and abuse prevention.
We do not knowingly collect any special category data (such as health, religion or political opinions). Please do not send us such data.
2. What we do NOT collect
- We do not log your browsing activity, the websites you visit, or the accounts you manage inside your profiles.
- We do not collect the website passwords you save in a profile — they are encrypted on your device with a key held by your operating system and are excluded from sync.
- The Local API and MCP server run on your own computer; their calls and audit log never leave it.
3. Why we use it (legal basis)
- To provide the service you signed up for (contract, GDPR Art. 6(1)(b)): create and secure your account, enforce plan limits, sync and share profiles, take payment, answer support.
- For optional cloud sync and cookie sync (your consent, Art. 6(1)(a)): we only sync your profiles or cookies if you switch these features on. You can withdraw your consent at any time by turning sync off; this does not affect processing done before you withdrew.
- To keep the service safe (legitimate interest, Art. 6(1)(f)): rate-limiting, blocking abuse, preventing repeated free trials.
- To meet legal obligations (Art. 6(1)(c)): keeping invoices and payment records for accounting and tax law.
We do not sell your data and we do not use it for advertising. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Who processes it for us
- Stripe — payments, invoices and subscription billing (Stripe is an independent controller for card data; see Stripe's privacy policy).
- Cloudflare — hosting of the website, API, database and download files, plus DDoS protection and privacy-friendly, cookieless analytics.
- Resend — sends our transactional emails (verification codes, password resets, billing notices).
- Google — only if you choose "Continue with Google" to sign in.
Each processor only receives what it needs for its job.
5. International data transfers
Some of these processors operate outside the European Economic Area (EEA), for example in the United States. Where your data is transferred outside the EEA it is protected by an adequacy decision of the European Commission or by the EU Standard Contractual Clauses (SCCs), together with additional technical measures such as encryption. You can request a copy of the relevant safeguards by writing to [email protected].
6. How long we keep it
- Account, subscription, synced and team data: for as long as your account exists.
- Login sessions: expire automatically after 30 days.
- Support conversations: for as long as your account exists, so we can follow up.
- After you delete your account: everything above is deleted. We keep payment records (amount, date, plan) for 7 years from the end of the relevant financial year, as required by the Estonian Accounting Act (Raamatupidamise seadus § 12), and a hashed record of the deleted email address so that free trials cannot be repeated indefinitely.
7. Security
Passwords are salted and hashed (PBKDF2). Synced data is encrypted with AES-256-GCM before it leaves your device. All traffic uses HTTPS (HSTS). Accounts are protected with rate-limiting, automatic blocking of abusive traffic and session-token expiry. Access to personal data is limited to staff who need it.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Estonian supervisory authority within 72 hours, and affected users without undue delay, as required by the GDPR (Art. 33–34).
Found a vulnerability? See our security page or write to [email protected].
8. Your rights (GDPR)
You can ask us to access, correct, export (data portability) or erase your personal data, to restrict or object to processing, and — where we rely on your consent — to withdraw that consent. You also have the right to lodge a complaint with your supervisory authority — in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, [email protected].
- Delete your account yourself: Dashboard → Settings → Danger zone → Delete account. This cancels any active subscription and removes your data as described in section 6.
- Everything else: email [email protected] from the address on your account. We respond within one month (extendable by up to two further months for complex requests — we will tell you if so). Exercising your rights is free unless a request is manifestly unfounded or excessive.
9. Cookies
The website sets no advertising or tracking cookies. The dashboard keeps your login token in your browser's local storage so you stay signed in; Stripe sets its own cookies on its checkout pages. Cloudflare may set a strictly necessary security cookie to protect against bots. Because we use only strictly necessary storage and cookieless analytics, no cookie-consent banner is required — if we ever add non-essential cookies, we will ask for your consent first.
10. Changes
We may update this policy. Material changes will be posted on this page with a new "Last updated" date, and announced in the dashboard or by email if they affect how your data is used.
11. Contact
WaveLinker OÜ · registry code 17450210 · Tartu mnt 67/1-13b, 10115 Tallinn, Estonia · VAT EE102974542 · [email protected] (privacy requests) · [email protected] (security reports).
← Back to home