Privacy Policy
Last updated: August 2026.
This policy explains what Pitolet (the "Service"), operated by a sole proprietor ("we", "us"), collects, why, and your rights. We aim to collect as little as possible. We do not run ad tracking and we do not sell your personal data.
Who is responsible
The data controller is the sole proprietor operating Pitolet, based in South Africa. For any privacy question or request, contact [email protected].
What we store
| Category | What it is | Why |
|---|---|---|
| Account data | Your email and name | To create your account, authenticate you, and contact you about the Service |
| Your designs | The documents, tokens, and content you create | To provide the core Service: storing and rendering your work. Your designs are yours. |
| Product activity | A small set of milestones: opening the dashboard, workspace, or editor; copying an agent prompt; opening manual MCP setup; and completing a website import | To understand whether setup works and where users get stuck |
| Feedback | Your message and, only when you choose to include them, a screenshot, technical details, and a seven-day read-only support link | To answer feedback and investigate a problem you report |
| Problem reports | Error type, safe code location, source, release, page route, occurrence count, and the last affected account or workspace | To find and fix application failures |
| Billing data | Subscription status (payment card data is handled by Paddle, not stored by us) | To manage paid plans |
Legal bases (GDPR)
- Contract — to provide the Service you signed up for (account data, your designs, billing).
- Legitimate interests — security, abuse prevention, and keeping the Service working (usage logs), balanced against your rights.
- Legal obligation — where we must retain records (e.g. tax/accounting).
- Consent — for anything optional; you can withdraw it at any time.
Processors we use
We share data only with the service providers needed to run Pitolet:
- Virtarix — hosting and storage of the Service and your designs (EU data centres).
- Paddle — payment processing and merchant-of-record for subscriptions; handles card data and tax.
- Resend — transactional email (e.g. sign-in, account, and billing notices).
These processors act on our instructions under data-processing agreements. Where data is transferred outside your region, we rely on appropriate safeguards (such as standard contractual clauses).
What we do NOT do
- No advertising trackers, no ad networks, no selling of personal data.
- No profiling of you for marketing to third parties.
- No session replay or recording of arbitrary clicks.
- Product analytics and problem reports do not contain design content, prompts, tokens, request bodies, entered text, or raw IP addresses.
Retention
- Product activity milestones are kept for 90 days.
- Grouped problem reports are kept for 90 days after their last occurrence.
- Feedback screenshots are removed after 30 days.
- Resolved feedback and its successful outbound replies are kept for one year.
- Support links expire after seven days and can be revoked sooner from Sharing.
Account data and designs remain while your account is active. When you request account deletion, we delete or anonymize personal data unless limited records must be retained by law.
Your rights
Subject to applicable law, you can request to access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. We delete your data on request. To exercise any right, email [email protected]. You also have the right to complain to your local data-protection authority.
Self-hosting
If you self-host the open-source (AGPL-3.0) build, you operate the software and you are the controller of the data it processes. The self-hosted build does not send feedback, analytics, or diagnostics to Pitolet Cloud. This policy covers only the hosted Service we operate.
Cookies
We use only the cookies/local storage needed to keep you signed in and to run the Service. We do not use advertising or cross-site tracking cookies.
Changes
We may update this policy; material changes will be notified through the Service or by email.
Contact
Privacy questions and requests: [email protected].