Privacy Policy
Last updated: 2026-09-13
This is the plain-English version of how we handle your data. We try to collect as little as possible, store it for as short as possible, and never sell it.
1. Who we are
GetAutomator ("we", "us") is a code-generation tool sold from this site. For privacy questions reach us at nishant@getautomator.com.
2. What we collect
- Account data: the email address you sign in with, your display name if Google OAuth provides one, and the profile picture Google returns (cached in your browser, never re-shared).
- Purchase data:your order history (which product, when, and how much you paid) and your license keys. Each key is stored as a SHA-256 hash plus an encrypted copy, so you and our support team can look it up again on your account's Licenses page. Payments run through Stripe; we never see your card details.
- Activation data:a SHA-256 hash of your machine's hardware fingerprint (hostname + MAC + machine GUID), plus your machine's hostname and operating system name in the clear. We use this to enforce the one-machine-at-a-time license rule and to show you which computer a license is on.
- Generation counts: when you generate a project, the desktop app tells us which product you used and adds one to a running count for your account. It is a number and a timestamp only - never your database, your tables, or the generated code (see section 3).
- Authentication codes: hashed 6-digit codes when you sign in via email OTP. Deleted after the code is used or after 10 minutes, whichever comes first.
- Audit log: a record of license activations, deactivations, template downloads, and admin actions. Used for security forensics and support troubleshooting.
- Analytics (only if you consent): if you click Accept on the cookie banner, Google Analytics 4 records aggregate page views and feature usage. See our Cookie Policy for the full list of cookies set.
3. What we explicitly do NOT collect
- Your database schema. The desktop app reads it locally; nothing about your tables, columns, or data ever leaves your machine.
- Generated code. It is produced on your machine and written to whatever folder you point at. We never see it.
- Database credentials. They live only in your operating system's native secure storage - Keychain on macOS, DPAPI on Windows, libsecret on Linux.
- Passwords. We don't use them. Sign-in is Google OAuth plus a short-lived email code, nothing to leak in a data breach.
4. Sub-processors
We rely on the third-party services below to operate. We've named them and the data they touch so you can make an informed decision.
- Stripe (USA) - processes payments. They see your card details; we never do. They store the order amount and your email under their own privacy policy.
- Crisp (EU) - powers the live-chat widget in the corner of the site. If you open the chat, they receive the messages you send and basic session data. The cookies it sets are listed in our Cookie Policy.
- Brevo (France) - sends sign-in OTP emails and transactional receipts. They see the email address and the rendered email body.
- Envato (Australia) - only if you bought through CodeCanyon. We send them your purchase code to verify it. They already hold your CodeCanyon purchase under their own policy.
- Google (USA) - only if you choose Google OAuth. They see that you signed into GetAutomator. We see the email address and name they share with us.
- Google Analytics (USA) - only if you click Accept on the cookie banner. Receives anonymised page-view data.
5. How long we keep things
- Account data: as long as your account exists.
- Order + license data: kept while your account exists, or up to 7 years after your last activity for tax record-keeping. Deleting your account removes them sooner (see section 6).
- OTP codes: 10 minutes or until used.
- Audit log entries: 1 year.
- Analytics data: GA4 default retention (14 months) unless we shorten it from the GA admin panel.
6. Your rights
Under GDPR (Europe), CCPA (California), and similar laws elsewhere, you can ask us to:
- Show you everything we have on you (access).
- Correct something that's wrong (rectification).
- Delete your account and associated data (erasure).
- Export your data in a portable format (portability) - JSON dump on request.
- Object to or restrict specific processing (objection / restriction).
Email nishant@getautomator.com with your request. We aim to respond within 30 days as GDPR requires.
7. International transfers
Our servers are in Europe (the VPS that runs this site). The sub-processors above are split between the EU (Brevo) and the US (Stripe, Google). When we send data to a US sub-processor, we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses as the legal basis.
8. Children
GetAutomator is a developer tool. It is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has signed up, email us and we'll delete the account.
9. Changes to this policy
We may update this page as the product evolves. The "Last updated" date at the top reflects the most recent change. For material changes (new sub-processors, new categories of data), we will email active customers.
10. Contact
Questions, requests, or anything else: email nishant@getautomator.com. We answer ourselves; there is no support ticket queue between you and the people who built the product.
