Privacy Policy
Last updated 27 July 2026
Zyeon UI is run by Zyeon. This page explains exactly what we store, who else sees it, and how to get it deleted. Short version: an email address, a hashed password or a GitHub sign-in, your license record, hashed API tokens, and a handful of first-party product events. No third-party analytics, no ad trackers.
What we store
- Account: your email address, display name, and — if you sign in with GitHub — the avatar URL GitHub returns. If you sign up with email and password, we store a hash of the password, never the password itself.
- Sessions: a session record and a session cookie so you stay signed in.
- Email verification codes: six-digit codes, short-lived, deleted after use or expiry.
- API tokens: only a SHA-256 hash of each token plus its first characters and the time it was last used. The token itself is shown to you once at creation and is not recoverable afterwards — not even by us.
- License: that you hold Pro All-Access, when it was granted, and the Stripe checkout session id used as the idempotency key.
- Product events: a small set of first-party counters stored in our own database — a Pro paywall was viewed, a checkout was started, a purchase completed, a token was created, a component was installed. Each row holds the event name, a timestamp, the component name where relevant, and your user id when you are signed in. That's it: no page-by-page browsing history, no device fingerprint, no third-party analytics service.
What we don't store
- Card numbers or any payment instrument. Checkout happens on Stripe's own pages; we only receive the result.
- Third-party analytics, behavioural profiles or ad identifiers. Nothing on this site reports to an analytics vendor — the product events above stay in our own database and are never shared.
- Anything about the code you write with the components. Installing a component is a plain HTTP request for a JSON file; we don't inspect or receive your project.
Cookies
Only two kinds, both strictly necessary: the session cookie that keeps you signed in, and a preference for light or dark theme stored in your browser. There is no advertising or analytics cookie, which is why you don't see a consent banner.
Who else processes your data
- Stripe — payments, tax calculation and refunds. Stripe receives your email and billing country, and holds the payment data.
- GitHub — only if you choose to sign in with GitHub, which shares your email, name and avatar with us.
- Cloudflare — sits in front of the site as CDN and TLS terminator, so it processes request metadata (IP address, requested URL).
- Amazon Web Services — hosts the application and database.
- Feishu (Lark) mail — delivers verification and password-reset emails, so it processes your email address.
We don't sell your data, and we don't share it with anyone else.
How long we keep it
Account, license and token records stay while your account exists. Verification codes expire within minutes. Product events are kept as long-run counters; deleting your account detaches them from you (the user id is cleared) and what remains is an anonymous tally. Database backups are kept for a short rolling window (about two weeks) and then deleted, so a deletion request may persist in a backup for a few days before ageing out. Stripe keeps payment records for as long as its own legal obligations require, independently of us.
Your choices
- Access or export: email us and we'll send you what we hold about you.
- Correction: your name and email can be changed from your account, or we'll do it for you.
- Deletion: email us and we'll delete your account and its data. If you hold a paid license, deleting the account ends access to Pro content — the source you already installed stays yours.
- Token revocation: revoke any token yourself from your account page at any time.
Requests go to [email protected] and we aim to answer within a few days.
Changes to this policy
If we start using something new that touches your data — analytics, for example — this page is updated before it goes live, and the date at the top changes with it.
Questions about this page? Email [email protected].