This policy explains what personal data Smart Dev Agency S.A.S. ("we", "us"), a company organized under the laws of the Republic of Colombia, collects when you use Smart Grow Vault ("Smart Vault" or the "Service") and its website, why we collect it, who we share it with and what choices you have.
We are responsible for your account data. For the content you store in the Service (variables and secure files), we act on behalf of you or your organization. We process personal data under Colombian data protection law (Law 1581 of 2012) and, where it applies to you, the EU General Data Protection Regulation (GDPR).
1. Data we collect
1.1 Data you give us
- Account: your name, email address and, if you add one, a profile picture. If you sign up with a password, our authentication system stores it only as a one-way hash.
- Sign-in methods: if you sign in with Google, Microsoft, GitHub or GitLab, we receive your account identifier and basic profile from that provider, and store the tokens needed to keep your account linked. If you turn on two-factor authentication, we store its secret and backup codes in encrypted form. If you add a passkey, we store its public key.
- Organizations: organization names, members and their roles, and the email addresses of the people you invite.
- Billing: your plan, your subscription status, the identifiers our payment provider, Polar, assigns to you, and the payment events Polar sends us, including the customer information they contain. If you set a billing email, we store it. We never receive or store card numbers.
- Contact form: the name, email address, topic and message you send us.
- Your content: the environment variables and secure files you store. We keep them encrypted and process them only to provide the Service (see section 3).
1.2 Data collected automatically
- Sessions: the IP address and browser user agent of each signed-in session.
- Activity log: when someone creates, changes, deletes or rolls back an individual variable; creates, changes or deletes a secure file, app or environment; or changes or removes a member, we record who did it, when, and from which IP address and user agent. The organization owner can see this log.
- Terms acceptance: the version of the Terms you accepted, with the IP address and user agent at that moment.
- CLI devices: the name, a fingerprint and a public key of each device you sign in to with the CLI.
- API keys: each key's name, a short prefix, a one-way hash, its permissions, its expiry date and a monthly count of its requests. We never store the full key.
- Diagnostics: our API sends error reports and payment-event diagnostics to our own logging service. They include identifiers such as your user ID and, for payment events, excerpts of the data Polar sends.
- Browser error reports (optional): only if you allow them, the web app sends error and performance reports to Sentry. These reports are not linked to your name or email address.
2. How we use it
- To provide the Service: accounts, organizations, permissions, storing and serving your content, the CLI and API keys.
- To keep it secure: sessions, the activity log, rate limiting by IP address, and preventing fraud and abuse.
- To send transactional email: email verification, password reset, organization invitations, billing-email verification and account-deletion codes. We do not send marketing email.
- To bill paid plans through Polar.
- To diagnose errors: server error logs and, only with your consent, browser error reports.
- To answer your messages and requests.
- To comply with legal obligations.
We do not sell personal data, and we do not use it for advertising.
Legal bases (for users covered by the GDPR): performing our contract with you (providing the Service); our legitimate interests (security, abuse prevention and diagnosing server errors); your consent (browser error reports, which you can withdraw at any time); and legal obligations (such as billing records).
3. How we protect it
- In transit: all traffic uses HTTPS. Requests that carry your variables, secure files or API keys, CLI operations and some account operations also travel inside an additional post-quantum encrypted channel.
- At rest: your content is encrypted before it is stored, with a key unique to your organization and a separate key derived for each record. Organization keys are themselves encrypted with a master key kept in our infrastructure provider's secrets store.
- What this means: the Service can decrypt your content to answer the requests you authorize. Smart Vault is not end-to-end or zero-knowledge encrypted.
Access control, two-factor authentication, passkeys and the activity log are described in our Security Policy.
4. Who we share it with
We share personal data only with the providers that help us run the Service, and only what each one needs:
| Provider | Purpose | Data it receives |
|---|---|---|
| Cloudflare | Hosting, database, key storage, rate limiting and network protection. Turnstile checks for bots on the contact form. | The data the Service processes. |
| Polar | Payments and subscriptions, as merchant of record. | Your user ID, your subscription, and what you enter at checkout. |
| Resend | Sending transactional email. | Recipient email address and email content. |
| Sentry | Browser error reports, only with your consent. | Error and performance data. |
| Google, Microsoft, GitHub, GitLab | Sign-in, only if you choose one of them. | What you authorize on their consent screen. |
| Product Hunt | Displays our badge; your browser loads the image from its servers. | Your IP address and browser details, as with any web request. |
Messages from the contact form go to our own contact service. We may also disclose data when the law requires it.
International transfers. Our providers process data in several countries, which may be outside your own. Where their terms provide transfer safeguards, such as the European Commission's Standard Contractual Clauses, those safeguards apply.
5. How long we keep it
- Account data and your content: until you delete them or delete your account.
- Account deletion: immediate. It permanently deletes your profile, sign-in methods, sessions, API keys, CLI sessions, billing email, the organizations you own and all their content. Content and activity log entries you created in organizations owned by others remain in those organizations.
- Sessions: web sessions expire after 7 days without activity, and CLI sign-ins 7 days after they are created. Expired sessions are deleted every day.
- Activity log: kept while the organization exists.
- Payment records: payment events we receive from Polar are kept for accounting and legal purposes, also after an account is deleted.
- Backups: our database provider keeps point-in-time recovery data for up to 30 days, so deleted data can remain there for up to 30 days.
6. Your rights
You can:
- Access and export: see your profile in the app, download the variables you have access to as JSON or
.envfiles, or ask us for a copy of your personal data. - Correct: update your profile in account settings.
- Delete: delete your account from account settings (with your password, or with a code we email you if you only use social sign-in), or ask us to do it.
- Object or restrict: ask us to stop or limit certain processing.
- Withdraw consent: turn browser error reports off at any time in your profile, under Data & Privacy.
Under Colombian law you also have the right to know, update and rectify your data, to request proof of your authorization, to be informed of how your data is used, and to revoke your authorization. You can file a complaint with Colombia's Superintendencia de Industria y Comercio or with the data protection authority where you live.
To exercise any right, email support@smart-grow.app. We will answer within the deadlines set by the applicable law, and we may need to verify your identity first.
7. Cookies and local storage
Essential (always on)
- Authentication cookies: keep you signed in, remember a trusted device for two-factor authentication, and protect social sign-in. They are secure and HTTP-only.
- Local storage on your device: your theme, sidebar state and cookie choice; an encrypted cache of your profile and selected workspace; and temporary state while you sign in to the CLI.
Optional
- Browser error reports (Sentry): loaded only after you accept them. Your choice is saved on your device and, when you are signed in, in your account.
Third parties
- The Product Hunt badge is loaded from Product Hunt's servers.
- Cloudflare Turnstile, on the contact form, may set the cookies it needs for its bot check.
We do not use advertising or analytics trackers.
8. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data.
9. Changes to this policy
We will publish any update on this page and change the date above. If a change is material, we will also notify account owners by email.
10. Contact
Smart Dev Agency S.A.S., Republic of Colombia — support@smart-grow.app.