Privacy Policy
Last updated 8 August 2026
The short version
We collect your email address and nothing else about you. We never see your card. Page views are counted in aggregate by Cloudflare Web Analytics — a cookieless counter that identifies nobody. We do not use advertising or tracking cookies, and we do not sell or share your data.
Who is responsible
Yevhen Maksymenko, Canada, is the data controller. Contact for any privacy question or request: [email protected].
What we hold, and why
- Email address — to identify your account, send the link that sets your password, and tell you about billing or material changes. Lawful basis: performance of our contract with you.
- Password — stored only as a scrypt hash. We cannot read it.
- Subscription status (plan, whether active, renewal date, and Stripe's customer identifier) — to decide whether to unlock the live session. Lawful basis: contract.
- Session cookie — a random identifier that keeps you signed in, plus a short-lived token that protects forms against cross-site request forgery. These are strictly necessary for the service to function, so no consent banner is required. There are no other cookies.
- Rate-limit counters — a short-lived tally that someone attempted to sign in or reset a password, keyed on a salted hash of the email entered, to blunt password-guessing. The address itself is not stored in the counter. Lawful basis: legitimate interest in keeping accounts secure. Expires within a few hours.
Browsing the free historical archive requires no account and creates no personal record. Page views across the site are tallied by Cloudflare Web Analytics, which uses no cookies, no local storage and no fingerprinting — we see aggregate counts (which pages, which countries, which referrers), never a profile of you.
Payments
Card details are collected and processed by Stripe, and never reach our servers. We receive only what is needed to run the subscription: an identifier, the plan, the status and the renewal date. Stripe acts as an independent controller for payment data — see stripe.com/privacy.
Who else touches it
- Stripe — payments and billing.
- Upstash — the database holding accounts and sessions.
- DigitalOcean — hosting.
- Resend — delivery of the set-password and billing emails.
- Cloudflare — DNS, routing of inbound mail to our support address, and cookieless aggregate page-view counting (Web Analytics).
- Google — the mailbox where support and privacy mail is read.
Apart from Stripe, which is an independent controller for payment data, they process data on our instructions to run the service. We do not sell your data, and we do not use it for advertising. Some of these providers operate outside your country, so your data may be transferred internationally under the safeguards those providers offer.
How long we keep it
Account data for as long as the account exists. If you delete the account it goes at once, and we keep no copy — a billing dispute after that is answered from Stripe's records rather than ours. Sessions expire after 30 days, or immediately when you sign out or delete the account. Rate-limit counters expire within a few hours. Stripe keeps payment records for as long as its own legal obligations require.
Your rights
You can delete your account yourself, from the account page — no email, no waiting, no request to approve. It takes effect immediately: your subscription is cancelled at once rather than at the end of the period, and your email address, password hash, subscription record, Stripe customer reference and every session you are signed in with are erased. There is no refund for a period already started, and the deletion cannot be undone. It does not delete Stripe's payment records, which we are required to keep. A password-reset link you requested in the last hour stops working the moment the account is gone, and expires on its own within the hour.
For everything else — a copy of the data we hold, correcting it, a portable export, or objecting to processing based on legitimate interest — write to [email protected] and we will respond within 30 days.
If you are in the EU, UK or Switzerland you may also complain to your national data protection authority.
Security and breaches
Traffic is served over HTTPS. Passwords are hashed with scrypt. The session cookie is signed and HttpOnly; the CSRF cookie holds only a random value and must be readable by the page — that is what it is for. If a breach affects your data and puts you at risk, we will tell you and the relevant authority without undue delay.
Children
gex.live is not intended for anyone under 18, and we do not knowingly hold their data.