// legal / privacy
Privacy Policy
last updated: august 8, 2026
1. Introduction
wYnFuscate ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our code obfuscation platform and services ("Service").
This policy applies to all users of the wYnFuscate platform, including visitors, registered users, and API clients. By using our Service, you consent to the data practices described in this policy.
We are compliant with GDPR (EU), CCPA (California), and other applicable data protection regulations.
2. Information We Collect
2.1 Information You Provide
Account Information:
- Email address (required for account creation)
- Full name (optional)
- Profile photo (if signing in with Google or Discord)
- Discord user ID (if you link your Discord account)
- Invite code (during beta period)
- Payment information: card brand, last four digits, expiration date, billing address, and transaction history (processed and stored by Stripe; we do not store full card numbers)
Note: We use Firebase Authentication for secure login. Your password is managed by Google Firebase and is never stored in our databases. For more information, see Firebase Privacy Policy.
User-Submitted Content:
- Source code files uploaded for obfuscation (.lua files)
- Configuration preferences (security level selections)
- Support tickets and correspondence
- Feedback and survey responses
2.2 Automatically Collected Information
Usage Data:
- IP addresses and geographic location (country/region)
- Browser type, version, and language settings
- Operating system and device information
- Pages visited, features used, and actions taken
- Timestamps of all activities
- Referral source (how you found our Service)
Technical Data:
- API usage logs and performance metrics
- Job processing times and success/failure rates
- File sizes and obfuscation parameters
- Error logs and debugging information
- IP addresses for each obfuscation request (for account sharing detection)
2.3 Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies. See our Cookie Policy for detailed information.
2.4 Runtime Protection Telemetry (End-Users of Protected Scripts)
Some scripts protected by Wynfuscate use our "online key" runtime protection feature. When such a script is run, it makes an automated request to a Wynfuscate server to retrieve a key needed to operate. If you are running a protected script, you may not be a Wynfuscate customer and may never have visited our website; this section describes the limited information we receive from you in that situation.
When a protected script contacts our servers, we receive: (a) the IP address from which the request is made, and (b) a device or executor identifier (sometimes called an "HWID") that the runtime environment exposes. We never store the raw device identifier. It is immediately converted into a keyed cryptographic hash (HMAC), and only the hashed value is retained.
We process this information for one purpose only: protecting the security and integrity of our service and our customers' scripts, including detecting, rate-limiting, and temporarily blocking attempts to crack, pirate, or abuse the protection. We do not use it for advertising, analytics, profiling, or any other secondary purpose, and we do not sell it or share it with third parties.
Where the GDPR or UK GDPR applies, our lawful basis for this processing is legitimate interests under Article 6(1)(f), specifically ensuring network and information security and preventing fraud and abuse, interests recognized in Recitals 47 and 49 of the GDPR. Where the California Consumer Privacy Act applies, this information is collected solely for the "security and integrity" business purpose of detecting and protecting against security incidents and fraudulent or illegal activity, and it is not sold or shared.
Retention is short. Transient detection state (such as recent request records) is kept only for a matter of hours. If abusive activity is confirmed, the hashed identifier may be placed on a blocklist, where it is retained only for the duration of the block and then deleted. We do not retain raw identifiers long term at any point.
Because we have no direct relationship with end-users of protected scripts, we make this notice publicly available here, and we contractually require our customers (the script owners) to inform their own users that protected scripts perform this online security check.
If you are an end-user and wish to exercise your privacy rights, object to this processing, or ask questions about it, contact us at [email protected]. Please note that because we hold only a hashed identifier and an IP address, we may need you to provide additional information for us to locate any data relating to you, and in some cases we may be unable to identify you at all, in which case we will tell you.
3. How We Use Your Information
We use collected information for the following purposes:
3.1 Service Provision
- Creating and managing your account
- Processing obfuscation requests
- Enforcing usage quotas and rate limits
- Providing customer support
- Delivering obfuscated files and downloads
3.2 Security and Fraud Prevention
- Detecting and preventing fraudulent activity
- Identifying unauthorized access attempts
- Monitoring for Terms of Service violations
- Investigating reverse engineering attempts
- Enforcing intellectual property rights via watermark tracking
We also use limited runtime telemetry (an IP address and a keyed hash of a device identifier) received when protected scripts contact our servers, solely to detect and temporarily block attempts to crack, pirate, or abuse the protection applied to our customers' scripts, as described in Section 2.4 (Runtime Protection Telemetry). This information is used for no other purpose.
3.3 Improvement and Analytics
- Analyzing usage patterns to improve the Service
- Optimizing obfuscation algorithms and performance
- Conducting A/B testing of new features
- Generating anonymized statistical reports
3.4 Communication
- Sending transactional emails (account notifications, job completions)
- Service announcements and security alerts
- Marketing communications (with your consent, opt-out available)
- Responding to inquiries and support requests
3.5 Legal Compliance
- Complying with legal obligations and court orders
- Enforcing our Terms of Service
- Protecting our rights and property
- Cooperating with law enforcement investigations
4. Data Storage and Retention
4.1 Storage Locations
Your data is stored on secure servers located in the United States. We use industry-standard encryption for data at rest and in transit (TLS 1.3, AES-256).
4.2 Retention Periods
- Uploaded source files: Deleted immediately after obfuscation
- Obfuscated output files: 14 days from job completion, then permanently deleted
- Account data: Retained while account is active, deleted 90 days after account closure
- Firebase authentication data: Managed by Google Firebase; deleted when account is closed
- IP activity logs: 12 months for security and fraud prevention
- Usage logs: 12 months for operational purposes
- Watermark metadata: Retained indefinitely for anti-piracy enforcement
- Payment records: 7 years for tax and accounting compliance
4.3 Backup and Disaster Recovery
We maintain encrypted backups for disaster recovery. Backup data is retained for up to 30 days and follows the same security standards as production data.
5. How We Share Your Information
We do NOT sell your personal data to third parties. We may share your information in the following circumstances:
5.1 Service Providers
We share data with trusted third-party service providers who assist us:
- Google Firebase - Authentication services (email/password, Google OAuth)
- Stripe - Payment processing for subscriptions and credit purchases
- Supabase - Database hosting (PostgreSQL) for user data and application state
- Cloudflare - CDN, DDoS protection, and R2 object storage for file uploads
- Vercel - Web application hosting
- Discord - Community support and OAuth integration
All service providers are contractually bound to protect your data and use it only for specified purposes.
Third-Party Privacy Policies:
- • Stripe: stripe.com/privacy
- • Firebase: firebase.google.com/support/privacy
- • Supabase: supabase.com/privacy
- • Cloudflare: cloudflare.com/privacypolicy
- • Discord: discord.com/privacy
5.2 Legal Requirements
We may disclose your information if required by law:
- In response to court orders, subpoenas, or legal processes
- To comply with DMCA takedown notices
- To cooperate with law enforcement investigations
- To protect our rights, property, or safety
- To prevent fraud or security threats
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. You will be notified via email of any such change in ownership.
5.4 Aggregated Data
We may share anonymized, aggregated statistics that do not identify individuals (e.g., "50,000 files obfuscated this month") for marketing or research purposes.
6. Your Privacy Rights
6.1 GDPR Rights (EU Residents)
If you are located in the European Union, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for marketing communications
6.2 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and share
- Request deletion of your personal information
- Opt-out of the sale of personal information (we do not sell data)
- Non-discrimination for exercising your privacy rights
6.3 How to Exercise Your Rights
To exercise any of these rights, contact us at:
Email: [email protected]
Subject Line: "Privacy Rights Request"
We will respond within 30 days. We may require identity verification to process your request.
7. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Authentication: Firebase Authentication with industry-leading security practices
- Password Security: Passwords are managed by Google Firebase using bcrypt hashing and are never stored in our databases
- Access Control: Role-based permissions, principle of least privilege
- Network Security: Firewalls, DDoS protection (Cloudflare), intrusion detection
- Account Sharing Detection: IP tracking and automated flagging of suspicious activity
- Monitoring: 24/7 security monitoring and incident response
- Audits: Regular security audits and penetration testing
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Children's Privacy
Our Service is NOT intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If we discover that a child under 18 has provided us with personal information, we will delete it immediately. If you believe we have collected information from a child, contact us at [email protected].
Protected scripts may be run by end-users who are minors, including within platforms such as Roblox. Where our servers receive runtime telemetry from such users as described in Section 2.4 (Runtime Protection Telemetry), that information is limited to an IP address and a pseudonymized (keyed-hash) device identifier, is used exclusively for security and abuse prevention, is retained only briefly, and is never used to profile, advertise to, or build any record about any user, minor or otherwise. We do not knowingly collect any other personal information from children, and we do not sell or share this information.
9. International Data Transfers
Our servers are located in the United States. If you access our Service from outside the US, your data will be transferred to, stored, and processed in the United States.
By using our Service, you consent to this transfer. We ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) for GDPR compliance.
10. Third-Party Links and Services
Our Service may contain links to third-party websites (e.g., Discord, GitHub). We are not responsible for the privacy practices of these external sites.
We encourage you to review the privacy policies of any third-party services you interact with.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to registered users (for significant changes)
- Displaying a notice on our platform
Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
12. Contact Information
For privacy-related questions, concerns, or requests:
Privacy Contact: [email protected]
General Support: [email protected]
Legal Inquiries: [email protected]
Discord: https://discord.gg/Z5xQ47Mbnd