Privacy Policy
Last updated: 30 August 2026
1. Scope and contact
This Policy explains how AtomCyou processes personal data through atom.cyou, its dashboard, APIs, payment webhooks, license delivery, and transactional email services. For questions, privacy requests, or complaints, contact contact@atom.cyou.
For project-owner account and service-administration data, AtomCyou determines why and how the data is processed. For end-customer identifiers and email addresses submitted by a project owner, that owner generally determines the purpose and AtomCyou processes the data to provide the licensing service. End customers should normally direct requests to the application provider that supplied their data.
2. Data we process
- Google account data: Google subject identifier, email address, display name, and profile picture supplied during sign-in. AtomCyou does not request access to Gmail, Drive, contacts, calendars, or the user’s Google password.
- Project data: project name and slug, product ID, tier display names and program IDs, pricing, currencies, features, duration, license model, slippage, capacity, status, and public signing keys.
- Protected key material: an encrypted project private signing key. It is decrypted only when needed to issue a certificate and is never returned through the API or dashboard.
- Customer and license data: customer identifier, optional customer email, selected tier, certificate, issue, expiry and revocation timestamps, and associated project and order identifiers.
- Payment records: expected and confirmed amount and currency, transaction identifier, order status, timestamps, CorePort customer identifier when supplied, webhook payload hash, and project-billing records. AtomCyou does not receive payment-card or bank-login credentials.
- Operational data: session cookie, OAuth state cookie, request and security logs, IP address and request metadata that may be processed by Cloudflare, email delivery failures, and notification history used to avoid duplicate messages.
- Communications: information included when you contact support or send a legal or privacy request.
3. Why we process data
- authenticate project owners and maintain signed-in sessions;
- create and administer projects, tiers, payment orders, keys, and billing periods;
- verify CorePort webhooks, prevent replay or fraud, validate payment, and issue licenses;
- deliver and synchronize certificates and public trust keys;
- send license, payment, grace-period, and suspension notifications;
- secure, troubleshoot, monitor, and improve the Service;
- provide support, enforce the Terms, establish or defend legal claims, and comply with law.
4. Legal bases
Where the GDPR, UK GDPR, or similar law applies, processing is based on:
- contract: operating accounts, projects, payments, licensing, support, and requested communications;
- legitimate interests: securing the Service, preventing fraud and replay, maintaining reliability, understanding failures, and protecting legal rights, balanced against affected individuals’ rights;
- legal obligation: accounting, tax, sanctions, regulatory, and lawful-request requirements;
- consent: where consent is specifically requested, which may be withdrawn for future processing.
5. Google user data
AtomCyou uses the basic Google identity data received during OAuth only to authenticate you, create your account, display your profile, provide account features, prevent abuse, and support the Service. We do not sell Google user data, use it for advertising or credit decisions, or use it to train generalized artificial-intelligence models. We disclose it only to service providers needed to operate AtomCyou, when you direct us, for security, or when legally required.
6. Cookies and local storage
AtomCyou currently uses essential cookies for Google OAuth state and the signed login session. The session cookie is HTTP-only, secure, same-site, and expires after approximately 30 days. These cookies are necessary to authenticate users and protect the login flow. AtomCyou does not currently use advertising cookies or third-party behavioral analytics. If that changes, this Policy and any required consent controls will be updated before such use.
7. Recipients and service providers
- Cloudflare: website and API delivery, Workers/Pages execution, D1 database hosting, security, logs, and transactional email sending.
- Google: project-owner authentication through Google OAuth.
- CorePort: payment initiation, redirects, and signed payment notifications.
- Open Bank Project FX service: currency-pair conversion requests when the paid and expected currencies differ; the request contains the currency pair, not the customer identity.
We may also disclose information to professional advisers, competent authorities, or a successor in a merger, financing, reorganization, or sale, subject to applicable law and appropriate confidentiality. We do not sell personal data.
8. International transfers
Providers may process data in countries outside your residence, including outside the EEA, United Kingdom, or Switzerland. Where required, transfers are protected through an adequacy decision, approved contractual clauses, a recognized certification framework, or another lawful transfer mechanism. Cloudflare publishes information about its privacy practices and subprocessors on its website.
9. Retention
Account and project records are kept while the account or project remains active. Orders, licenses, transaction identifiers, webhook replay records, billing history, and notification records are retained for as long as needed to provide verifiable licensing, prevent duplicate processing, resolve disputes, and meet accounting or legal obligations. Session cookies expire after approximately 30 days. Logs and support communications are retained only as reasonably necessary for security, troubleshooting, support, and legal obligations.
After a verified deletion request, data is deleted or anonymized unless retention is required or permitted for payment records, security, fraud prevention, legal compliance, or legal claims. Residual copies may remain temporarily in provider backups until overwritten under normal cycles.
10. Security
Measures include encrypted transport, signed HTTP-only sessions, restricted Cloudflare bindings, encrypted private licensing keys, detached-JWS verification for CorePort webhooks, transaction replay protection, payload-size limits, and access controls. No system is perfectly secure. Project owners must protect their Google accounts, use opaque customer IDs, and avoid sending unnecessary personal data.
11. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent for future processing; and complain to your local data-protection authority. We may ask for information needed to verify identity and authority. Some rights are limited where data must be retained by law or is needed to protect others’ rights.
Project owners should email contact@atom.cyou. End customers should first contact the provider of the application they licensed because that provider controls the customer relationship and can identify the relevant project and customer identifier.
12. Children
AtomCyou is a developer and business service and is not directed to children. Project owners must not knowingly submit children’s personal data unless they have a valid legal basis and have satisfied all applicable notice and consent requirements.
13. Changes to this Policy
We may update this Policy when the Service, providers, or legal requirements change. The date above will be revised, and additional notice will be provided for material changes where required or reasonably practicable.
14. Contact
Send privacy questions or verified requests to contact@atom.cyou. See also the Terms of Service.