🧠 SaveEnv - Privacy Policy
This policy describes how SaveEnv collects, uses, and protects your personal information and project data.
🔐 Information Collection
Information we collect:
- Account data (name, email, password)
- Payment information (processed by Stripe)
- Project data and environment variables (encrypted)
- Encryption public keys
- System access and usage logs
🛡️ Security and Encryption
How we protect your data:
- RSA-OAEP encryption for all sensitive data
- Public keys stored with hash and salt
- Private keys are never stored on our servers
- HTTPS/TLS communication for all transmissions
- Secure authentication via NextAuth.js
⚠️ CRITICAL WARNING ABOUT ENCRYPTION KEYS
WARNING: If you lose your private encryption key, it will NOT be possible to recover your data!
Why does this happen?
- Your private key is generated locally and never sent to our servers
- Data is encrypted using asymmetric encryption (RSA-OAEP)
- Without the private key, it is mathematically impossible to decrypt the data
- Not even our technical team can recover data lost due to lost keys
💡 Recommendation: Keep your private keys in a safe place and make regular backups!
🗑️ Data Deletion
Right to complete deletion:
- You can request complete deletion of your account at any time
- All data will be permanently removed from our servers
- Projects, keys, and configurations will be completely erased
- This action is irreversible and cannot be undone
To request deletion, contact us: [email protected]
👥 Organizations and Responsibilities
Responsibilities in organizations:
- The organization creator is responsible for managing members and permissions
- Members with permissions can access and modify shared projects
- SaveEnv is not responsible for improper actions by organization members
- It is the organization's responsibility to monitor and control member access
- We recommend regularly reviewing organization permissions and members
📊 Data Usage
We use your information to:
- Provide and maintain the SaveEnv service
- Process payments and manage subscriptions
- Send important communications about the service
- Improve and optimize our platform
- Comply with legal and regulatory obligations
🔗 Data Sharing
We do not sell, rent, or share your personal data with third parties, except:
- Payment processors (Stripe) for transactions
- Email providers (Resend) for communications
- When required by law or court order
- With your explicit consent
🌍 Storage and Transfer
Your data is stored on secure servers located in regions that comply with data protection regulations. We use technical and organizational security measures to protect your information.
📱 Cookies and Tracking Technologies
We use essential cookies for system functionality and analytics cookies to improve user experience. You can control cookie usage through your browser settings.
👤 Your Rights
You have the right to:
- Access and review your personal data
- Correct incorrect information
- Request deletion of your account and data
- Export your data in a readable format
- Withdraw consent for data processing
- Object to data processing
🚨 Breach Notifications
In case of a security breach that may compromise your personal data, we will notify you and relevant authorities within 72 hours, as required by applicable legislation.
📞 Contact
For questions about this privacy policy or to exercise your rights:
Email: [email protected]
📝 Policy Changes
We reserve the right to update this privacy policy periodically. Significant changes will be communicated via email notification or website notice.