1. Who we are
Ajax UI is operated by the Ajax UI Contributors, the data controller for the personal data processed through the Service. For privacy matters you may contact our Data Protection Officer (DPO) at [email protected].
2. Data we collect
We collect only what is necessary to operate the Service. The categories below are exhaustive.
Account data
- Email address (required)
- Display name (optional)
- Avatar URL (optional, derived from your OAuth provider)
- Password - stored as a bcrypt hash, never in plain text
- GitHub or Google OAuth identifier, when you connect those providers
- Plan tier (free, pro, team, enterprise) and whether your email is verified
- Account creation and last-update timestamps
Billing data
- Stripe customer ID and subscription ID (we do not store card numbers; Stripe holds those directly)
- Billing email and country, as provided to Stripe at checkout
- Invoice history accessible through the Stripe billing portal
Usage & product data
- Presets, themes, templates, and component overrides you create
- API key metadata: name, prefix (first 8 chars), creation date, last-used timestamp, optional expiry - the secret itself is only stored as a bcrypt hash
- Component download counts per user (aggregated, used to track popularity)
- Per-component version installed in your project, when you opt in via the CLI
Technical data
- Authentication cookies (see Section 6)
- Refresh token records (hash, family, expiry) used for session continuity and reuse detection
- IP address and basic device information - collected by Cloudflare for bot protection (Turnstile) and CDN, and held in our application logs for at most 30 days
3. How we use data
- Provide the Service - sign you in, save your presets, run API calls, deliver components through the CLI.
- Billing - process subscriptions, surface invoices, handle refunds.
- Communications - send transactional emails (email verification, password resets, subscription receipts). We do not send marketing emails without your opt-in.
- Security - detect abuse, brute-force attempts, and credential stuffing via Cloudflare Turnstile and our own rate limits.
- Product analytics - track aggregate usage (e.g. which components are most installed). We do not use third-party behavioral analytics (no Google Analytics, no PostHog, no Mixpanel).
- Legal compliance - meet our obligations under tax, accounting, and consumer-protection laws.
4. Legal bases (LGPD Art. 7)
We rely on the following legal bases:
- Performance of a contract - to deliver the Service you signed up for (Art. 7, V).
- Legitimate interests - to operate, secure, and improve the Service, including fraud prevention and log retention (Art. 7, IX).
- Compliance with legal obligations - to keep tax-relevant billing records (Art. 7, II).
- Consent - for any future marketing communications or non-essential cookies (Art. 7, I).
7. International transfers
Several of our processors (Stripe, Resend, Cloudflare, GitHub, Google) operate from the United States or other countries. When personal data leaves Brazil, we rely on the safeguards required by LGPD Art. 33 - including adequacy decisions, standard contractual clauses, and contractual binding rules with each processor. You can request the specific transfer mechanism for any processor by emailing the DPO.
8. Data retention
- Active accounts - for as long as the account exists.
- Deleted accounts - account record removed within 30 days of your deletion request; backups purged within 90 days.
- Refresh tokens - 7 days from issuance, or until revoked.
- API keys - until you revoke them.
- Billing & tax records - kept for the period required by Brazilian tax law (typically 5 years), even after account deletion.
- Application logs - at most 30 days.
- Public presets - remain visible to other users while published; reverting a preset to private removes it from public discovery immediately.
9. Your rights (LGPD Art. 18)
As a data subject, you may at any time:
- Confirm whether we process your personal data and access a copy of it.
- Correct incomplete, inaccurate, or outdated data.
- Request anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
- Request portability - receive your data in a structured, machine-readable format.
- Be informed about the public and private entities with which we share your data.
- Be informed of the option to refuse consent and of the consequences of refusing.
- Revoke any consent you previously gave.
To exercise these rights, email [email protected]. We respond within 15 calendar days. You also have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD).
10. Security
We apply industry-standard safeguards: TLS for all traffic, bcrypt for password and API-key hashing, refresh-token family reuse detection, content security policies, and least-privilege access controls on our infrastructure. No system is perfectly secure - please report any vulnerability to [email protected].
11. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe we have, contact the DPO and we will delete the data promptly. Users aged 13–17 must have parental or guardian consent.
12. Changes to this policy
We update this policy when our practices change. The “Effective” date at the top reflects the latest revision. Material changes will be notified by email to registered users at least 14 days before they take effect.
13. Contact & DPO
Data Protection Officer: [email protected]
General contact: [email protected]
Security reports: [email protected]
See also our Terms of Use.