Privacy Policy
Effective date: 25 April 2026 · Last updated: 25 April 2026
1. Who We Are
StayAwake (“we”, “our”, “us”) is the developer and operator of the StayAwake desktop application and the website at . For any privacy-related enquiries, contact us at support@stayawakemouse.com.
2. Data We Collect
Desktop Application
- Machine fingerprint — a one-way SHA-256 hash derived from hardware identifiers. It cannot be used to identify you personally and is used solely to enforce per-machine licence limits.
- App & OS version — sent with API requests to diagnose compatibility issues.
- Local logs — stored only on your device at
%LOCALAPPDATA%\StayAwake\logs. Never transmitted to us.
Website & Account
- Email address — required to create an account, deliver your licence, and send transactional communications.
- Billing & payment data — handled directly by Paddle. We receive only a customer ID, subscription status, and the last four digits of your card. We never store full card numbers.
- Machine activation records — machine fingerprint, optional device name you provide, and activation timestamp.
- Session tokens — short-lived authentication cookies set after you sign in, stored in an HttpOnly cookie and cleared on sign-out.
3. How We Use Your Data
- To validate and deliver your Pro licence
- To enforce per-machine activation limits and prevent licence sharing
- To send transactional emails — magic-link sign-in, purchase receipts, renewal reminders, and licence delivery
- To send service notifications — planned maintenance windows, pricing changes, or policy updates
- To investigate and resolve support requests you initiate
We do not sell, rent, or broker your personal data to third parties. We do not use your data for advertising or behavioural profiling.
4. Legal Basis (GDPR)
Where GDPR applies, we rely on the following lawful bases:
- Contract performance — processing your email and machine data to deliver the service you purchased.
- Legitimate interests — fraud prevention, licence enforcement, and service security.
- Legal obligation — retaining billing records as required by applicable tax and financial regulations.
5. Third-Party Services
Paddle
Payment processing and subscription management. Paddle acts as the Merchant of Record for all transactions and is responsible for billing compliance. Paddle Privacy Policy →
Supabase
Secure PostgreSQL database and authentication. Data is hosted in the EU (AWS eu-central-1 by default). Supabase Privacy Policy →
6. Data Retention
- Account and activation data is retained while your account is active.
- Billing records are retained for 7 years as required by financial regulations.
- If you request account deletion, all personal data is removed within 30 days, except records we are legally required to retain.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your account and personal data
- Object to or restrict certain processing activities
- Export your data in a portable, machine-readable format
To exercise any of these rights, email support@stayawakemouse.com. We will respond within 30 days.
8. Cookies
The website uses only two categories of cookie:
- Authentication cookies — HttpOnly session tokens set when you sign in. These are strictly necessary and expire when your session ends or you sign out.
- Paddle checkout cookies — set by Paddle during payment processing only. Subject to Paddle's cookie policy.
No advertising, analytics, or tracking cookies are used.
9. Security
We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest via Supabase, Row-Level Security to ensure users can only access their own data, and short-lived signed JWTs for offline licence validation. No password is ever stored — authentication uses magic links only.
10. Changes to This Policy
We may update this policy from time to time. We will notify active Pro subscribers of material changes via email at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
11. Contact
For privacy questions or data requests, contact us at support@stayawakemouse.com.