PRIVACY POLICY
Last updated August 13, 2026
This Privacy Policy describes how the operator of isaeva.xyz ("Isaeva", "we", or "us") processes personal data through the website, accounts, licensing, software, payments and support (the "Service"). It is a privacy notice, not a request to waive your rights.
1. Controller & Contact
The operator of Isaeva is the controller for personal data processed directly by the Service. Privacy requests can be sent through our official Discord.
2. Data We Collect
We collect only data reasonably needed to operate, secure and provide the Service.
- Account data. Email address, password hash, account identifier, username where used, role, account status, creation and login times, license details, accepted legal version and acceptance time, and optional account-security data.
- Technical and security data. Registration and recent login IP addresses, hashed hardware identifier, binding and reset times, software version, release channel, authentication attempts, update or download requests, rate-limit data and security events.
- Transaction data. Selected plan, price, order and provider identifiers, payment status and timestamps, license key, checkout status and the legal statement accepted at checkout. XPTP separately processes the selected asset, network, wallet and public blockchain transaction. We do not receive or store your private cryptographic keys.
- Support data. Messages, attachments, account details and proof of authorization or payment that you choose to send when requesting support, reporting misuse or exercising a legal right.
3. Sources of Data
We receive data directly from you, automatically from your browser or Isaeva software, from our security infrastructure, and from payment or support providers when needed to complete a transaction or request.
4. Purposes & Legal Bases
Where data-protection law requires a legal basis, we process data as follows:
- Contract. To create accounts, authenticate users, bind licenses, process orders, deliver updates and provide support.
- Legitimate interests. To secure the Service, prevent fraud, sharing and misuse, diagnose failures, enforce our Terms and protect legal claims.
- Legal obligations. To keep required transaction records and respond to valid legal requests.
- Consent. For optional processing where we specifically ask for consent. Consent can be withdrawn prospectively.
5. Required Data
Account credentials and essential technical, license and transaction data are required to provide the relevant Service. If you do not provide them, we may be unable to create an account, authenticate software, complete a payment or provide support.
6. Cookies, Sessions & reCAPTCHA
Isaeva uses an essential, secure first-party session cookie for up to seven days to keep you signed in. Cloudflare may use necessary network-security cookies. We do not use first-party advertising cookies or sell browsing profiles.
Registration, login and password-reset forms use Google reCAPTCHA to prevent automated abuse. Google may receive the CAPTCHA response, IP address, browser or device data and may set its own security cookies under the Google Privacy Policy. Disabling essential cookies or reCAPTCHA may prevent authentication features from working.
7. Service Providers & Disclosures
We do not sell personal data. We disclose it only as reasonably necessary:
- Cloudflare for network security, database and file-storage infrastructure.
- Google for reCAPTCHA verification.
- Resend to deliver requested password-reset emails.
- XPTP to create and verify cryptocurrency payments. XPTP separately processes payment and blockchain data under its own terms.
- Discord when you choose to contact our community or support through Discord.
- Advisers, authorities or other parties where required by law or reasonably necessary to protect rights, safety, the Service or legal claims.
- A successor in a merger, reorganization, financing or transfer of the Service, subject to applicable privacy law.
8. International Transfers
Providers may process data outside your country. Where transfer restrictions apply, we rely on an adequacy decision, contractual safeguards or another lawful transfer mechanism as appropriate. You may request information about applicable safeguards through the contact above.
9. Retention
Session cookies last up to seven days and password-reset links expire after five minutes. Temporary rate-limit data remains only for the applicable security window. Account, license and security records are kept while the account or license is active and afterward only as reasonably needed for security, disputes and legal obligations. Transaction and acceptance records are retained for applicable accounting, tax, consumer-protection and limitation periods. Data is deleted or anonymized when no longer needed, subject to backups and mandatory retention.
10. Security
Passwords and reset tokens are hashed, hardware identifiers are stored in hashed form, sessions are signed, and sensitive traffic is encrypted in transit. We use access controls and abuse prevention appropriate to the Service. No system is entirely secure, so absolute security cannot be guaranteed.
11. Your Rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, withdraw consent prospectively, and complain to a competent data-protection authority. These rights may be limited where retention is required or needed to protect others or legal claims. We may verify your identity before acting on a request.
12. Children
The Service is not intended for anyone under 18 or below the age of legal majority where they live. We do not knowingly permit such users. Contact us if you believe a minor provided personal data so we can review and delete it where appropriate.
13. Third-Party Services
Links and integrations may lead to independent third-party services. Their data practices are governed by their own notices, and we are not responsible for processing they control.
14. Changes
We may update this Policy when processing, providers or law changes. The current version and date will remain on this page. Material changes will receive additional notice where required. A policy update does not reduce rights provided by law.
15. Contact
Contact our official Discord for privacy questions or requests. isaeva.xyz is the only official domain for the Service.