Privacy policy
Last updated
1. Scope and responsibility
This policy covers the UI website, Google sign-in, authenticated sessions, and messages sent to UI. UI is operated under the EDBN name. EDBN decides why and how personal information is handled for those activities.
The product roadmap includes a reference catalog, saved collections, executable examples, public submissions, organization workspaces, APIs, MCP tools, and machine-assisted features. Those features are not described as current data practices here. Before a new feature begins processing additional personal information, UI will update this policy or provide a clear feature-specific notice at or before collection.
Questions and requests can be sent to privacy@edbn.me.
2. Information handled today
Account notice at collection
When you select Continue with Google, UI starts a Google OAuth flow through Supabase Auth. After you approve the information shown by Google, Supabase may create or access an authentication record. It can include your Google account identifier, email address, a Supabase user identifier, authentication method and status, sign-in timestamps, and related security or audit events.
UI uses this information to create or access the account, maintain authentication security, and troubleshoot sign-in. This version of the application contains no advertising or data-broker integration and does not use account information for cross-context behavioral advertising. Account, cookie, log, and correspondence retention is described in Sections 5 and 8.
Google sign-in
If you choose Google, Google and Supabase participate in the OAuth exchange. UI's callback receives a temporary authorization code in the callback URL and sends it to Supabase to establish the session. Infrastructure handling that request may receive the callback URL. UI may then receive the Google account identifier, email address, name, profile image, and basic profile fields Google shows and you authorize for the sign-in. UI does not receive your Google password.
Sessions, devices, and requests
UI's hosting or network providers receive data normally sent with a request to the website, such as IP address, requested URL, referrer when supplied, date and time, user agent, and response status. Supabase receives the account and request information sent to its authentication service, including authentication and security events.
Supabase authentication cookies can encode access and refresh tokens, the Supabase user identifier and email address, provider or user metadata returned during sign-in, and related session data. UI processes those values to keep you signed in, refresh a session, validate claims, sign you out on the current device, and investigate suspected misuse. Do not send a session token, password, private key, or database credential by email.
Messages and requests
If you contact a UI legal, privacy, copyright, security, abuse, or terms address, UI and its mail provider process your contact details, message, attachments, affected URLs, supporting evidence, and records of the review and response. Provide only what is needed for the issue.
Pro checkout and billing
When you choose Pro checkout, UI sends Dodo Payments your email, display name, the selected product, a stable internal account and checkout reference, and the information you enter at checkout. Dodo Payments acts as Merchant of Record and handles payment details, applicable taxes, receipts, refunds, disputes, and subscription management. UI does not receive your full card number.
UI keeps a restricted billing record containing provider customer, checkout, payment, subscription, refund, and dispute identifiers; product, currency, amount, status, and paid-period information; and signed-event audit and reconciliation records. These records connect billing status to the Supabase user identifier and are used to grant, suspend, restore, or end Pro access accurately.
3. Sources
UI receives information:
- directly from you when you send a message;
- from Google when you deliberately select Google sign-in;
- from Supabase when it authenticates or maintains your session;
- from Dodo Payments when checkout or billing events occur;
- automatically from your browser, device, and network requests; and
- from hosting, security, email, and network providers when they operate the Service or report a reliability or abuse event.
4. Purposes and legal bases
Account access
UI uses account, OAuth, and session information to provide the sign-in service you request, take steps before providing it, maintain the session, and respond to account issues. Where a legal basis is required, this processing is necessary to perform the agreement with you or take the steps you request before entering it.
Security and reliability
UI uses request, device, session, and audit information to prevent abuse, detect account compromise, enforce configured authentication rate limits, troubleshoot failures, and protect the Service. The basis is UI's legitimate interest in operating a secure and reliable service, after weighing that interest against the effect on users.
Purchases and subscription access
UI and Dodo Payments use checkout and billing information to take the steps you request before purchase, perform the subscription agreement, calculate and document charges and taxes, provide receipts and account management, prevent duplicate charges, reconcile failures, and handle cancellations, refunds, disputes, and support.
Communications and legal duties
UI uses messages and evidence to answer requests, resolve disputes, protect rights, keep necessary records, and comply with law. Depending on the matter, the basis is performance of the agreement, a legal obligation, UI's legitimate interests in support and legal claims, or consent where the law requires a choice.
UI does not currently use personal information for behavioral advertising, data brokerage, or solely automated decisions that have a legal or similarly significant effect on a person.
6. Disclosures
- Supabase. Supabase provides authentication, user records, session infrastructure, and related security logging.
- Google. Google receives and returns information only when you choose Google sign-in.
- Dodo Payments. Dodo Payments is the Merchant of Record for Pro purchases and handles checkout, payment methods, taxes, invoices, subscription management, refunds, and disputes.
- Hosting, network, and email providers.These providers handle requests, diagnostics, and messages on UI's behalf.
- Professional advisers and authorities. Information may be disclosed when reasonably necessary for advice, a lawful request, an investigation, safety, rights protection, or a dispute.
- Rights-process participants. UI may share the report substance and necessary contact details with an affected contributor, claimant, subscriber, or opposing party to review a rights dispute. If a statutory DMCA process applies, valid notices and counter-notices are forwarded as that process requires.
- A successor. Information may transfer in a merger, financing, reorganization, insolvency, or sale, subject to applicable confidentiality and notice duties.
This version of the application contains no advertising or data-broker integration and does not send personal information to an advertising integration for cross-context behavioral advertising. The identity, region, retention settings, and contractual role of a hosting, network, or email provider depend on the production deployment and must be confirmed against that deployment.
7. International processing
A provider may process information outside the country where you live, depending on the provider, project region, and production deployment. The application code does not determine those locations or establish a transfer mechanism. Before a restricted international transfer is made, the deployment must be reviewed and an applicable transfer mechanism put in place. Contact the privacy address for the location and mechanism that apply to the deployed Service.
8. Retention and deletion
Authentication records are kept while an account is active and until they are deleted or must be retained for a security, dispute, or legal reason. You may request deletion at the privacy address.
Billing records are kept for subscription administration, accounting, tax, refund, chargeback, fraud-prevention, support, and legal-claim requirements. Signed webhook bodies are restricted to server-side processing, removed from the operational inbox after successful normalization, and retained longer only while an event is unresolved. Provider and financial-record retention can differ where Dodo Payments or applicable law requires it. A deletion request may therefore sever the account link while legally required transaction evidence remains.
Sessions remain until expiry, revocation, sign-out, account deletion, or another configured session limit. Signing out through the current UI ends the session on that device; it does not promise to revoke every session on every device. Revoking the underlying session prevents later refreshes, but an access token already issued for that session may remain accepted until the token expires. Infrastructure, authentication, and email logs are kept for the provider's configured operational period. Legal, privacy, security, and rights correspondence is kept as long as needed to resolve the matter, meet a legal duty, or establish or defend a claim.
Deletion from active systems may not immediately remove a record from a rotating backup. A restricted copy may be kept during the backup cycle or under a legal hold. UI will not keep information longer merely because it may be useful someday.
9. Security and incidents
The application is configured to mark authentication cookies Secure in production, request HTTPS-only transport with HSTS, send no-cache headers on server responses that write authentication cookies, validate signed session claims, and keep server secrets outside browser code. Production TLS, CDN, identity, logging, mailbox, and provider controls must be verified against the deployed Service. Session cookies remain readable by the browser client, so preventing script injection is particularly important. No storage or transmission method is completely secure.
Report suspected compromise to security@edbn.me. UI will notify affected people and authorities when applicable law requires it.
10. Choices and rights
Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or receive a copy of personal information; withdraw consent; appeal a refusal; use an authorized agent; or complain to a privacy regulator. UI will not discriminate against you for making a privacy request.
Send a request to privacy@edbn.me. Identify the email associated with the account and the request. UI may ask for the minimum additional information needed to verify identity, authority, and scope. Do not email passwords, session tokens, or unnecessary identity documents. UI will respond within the period required by applicable law and explain any lawful refusal.
11. California and other U.S. state disclosures
The current account and Google sign-in paths handle identifiers such as email address, Supabase user identifier, IP address, a Google identifier, and authorized basic profile fields. They also handle internet or electronic activity such as user agent, requested website URL, request timestamps, authentication events, and session or security events. Account credentials and session tokens may qualify as sensitive personal information. UI uses them for authentication and account security, not to infer characteristics about a person. Pro billing also handles commercial information such as subscription, payment, refund, dispute, invoice, amount, currency, and paid-period records.
The sources and purposes are described in Sections 3 and 4. Supabase receives account, authentication, session, and related request data. Google receives the OAuth request when Google sign-in is selected and returns the profile fields authorized for sign-in. Hosting and network providers receive ordinary website request data. A mail provider receives information included in messages sent to UI. Dodo Payments receives checkout and billing information when Pro is used. This application contains no sale or cross-context advertising integration, so there is no such integration to opt out of today. UI will honor an applicable opt-out preference signal, including Global Privacy Control, if future practices create such a right.
California residents may request access to categories and specific pieces, correction, or deletion, and may use an authorized agent. Other state laws may also provide portability, opt-out, appeal, or related rights. Use the privacy address in Section 10. These provisions apply when the relevant law covers EDBN and the processing.
12. EEA, United Kingdom, and Switzerland
Sections 2 through 8 describe the categories, sources, purposes, legal bases, recipient categories, transfer status, and retention criteria for current processing. You may complain to the data protection authority where you live or work. Contact the privacy address for the relevant representative or data protection contact, if one is required.
13. India
India's Digital Personal Data Protection framework is being brought into force in stages. UI will apply the provisions that are in force and applicable at the time of processing, and will update its notice, grievance, consent, security, breach, retention, and children's-data procedures before later provisions become applicable. Current requests and grievances can be sent to the privacy address above.
14. Minors
UI is not offered to anyone under 18. If UI learns that a minor created an account or provided personal information, it will restrict the account and delete the information unless preservation is legally required. A parent or guardian can contact the privacy address.
15. Changes and contact
UI will update this policy when its real data practices, providers, or legal duties materially change. The revised version will show a new effective date. Additional notice or consent will be provided when law requires it before a materially new use begins.
Privacy questions, requests, and complaints: privacy@edbn.me. Formal legal notices: legal@edbn.me.