Legal

Privacy Policy

Effective . Ajax UI complies with the Brazilian General Data Protection Law (LGPD - Law 13.709/2018) and applies equivalent safeguards globally.

1. Who we are

Ajax UI is operated by the Ajax UI Contributors, the data controller for the personal data processed through the Service. For privacy matters you may contact our Data Protection Officer (DPO) at [email protected].

2. Data we collect

We collect only what is necessary to operate the Service. The categories below are exhaustive.

Account data

  • Email address (required)
  • Display name (optional)
  • Avatar URL (optional, derived from your OAuth provider)
  • Password - stored as a bcrypt hash, never in plain text
  • GitHub or Google OAuth identifier, when you connect those providers
  • Plan tier (free, pro, team, enterprise) and whether your email is verified
  • Account creation and last-update timestamps

Billing data

  • Stripe customer ID and subscription ID (we do not store card numbers; Stripe holds those directly)
  • Billing email and country, as provided to Stripe at checkout
  • Invoice history accessible through the Stripe billing portal

Usage & product data

  • Presets, themes, templates, and component overrides you create
  • API key metadata: name, prefix (first 8 chars), creation date, last-used timestamp, optional expiry - the secret itself is only stored as a bcrypt hash
  • Component download counts per user (aggregated, used to track popularity)
  • Per-component version installed in your project, when you opt in via the CLI

Technical data

  • Authentication cookies (see Section 6)
  • Refresh token records (hash, family, expiry) used for session continuity and reuse detection
  • IP address and basic device information - collected by Cloudflare for bot protection (Turnstile) and CDN, and held in our application logs for at most 30 days

3. How we use data

  • Provide the Service - sign you in, save your presets, run API calls, deliver components through the CLI.
  • Billing - process subscriptions, surface invoices, handle refunds.
  • Communications - send transactional emails (email verification, password resets, subscription receipts). We do not send marketing emails without your opt-in.
  • Security - detect abuse, brute-force attempts, and credential stuffing via Cloudflare Turnstile and our own rate limits.
  • Product analytics - track aggregate usage (e.g. which components are most installed). We do not use third-party behavioral analytics (no Google Analytics, no PostHog, no Mixpanel).
  • Legal compliance - meet our obligations under tax, accounting, and consumer-protection laws.

5. Sharing & processors

We do not sell personal data. We share it with a short list of processors who act on our instructions:

ProcessorPurposeData shared
StripeSubscription billingEmail, billing address, payment method (handled directly by Stripe)
ResendTransactional emailEmail, display name, message body
CloudflareCDN, Turnstile bot protection, R2 file storage (avatars)IP address, basic browser fingerprint, uploaded avatars
GitHubOAuth sign-inWhen you opt in: GitHub user ID and primary verified email
GoogleOAuth sign-inWhen you opt in: Google user ID, email, name, avatar

We may also disclose data when required by a valid legal process, to enforce these Terms, or to protect the safety of users or the public.

6. Cookies & tokens

Ajax UI uses a minimal cookie set, all strictly necessary:

  • ajax_rt - refresh token, HttpOnly, Secure, SameSite=Lax, 7-day lifetime, restricted to /v1/auth.
  • theme (localStorage, not a cookie) - remembers your light/dark theme choice.
  • Cloudflare Turnstile may set short-lived cookies on auth pages to detect automated traffic.

We do not use third-party tracking pixels, advertising cookies, or behavioral analytics. No banner is required because no non-essential cookies are set.

7. International transfers

Several of our processors (Stripe, Resend, Cloudflare, GitHub, Google) operate from the United States or other countries. When personal data leaves Brazil, we rely on the safeguards required by LGPD Art. 33 - including adequacy decisions, standard contractual clauses, and contractual binding rules with each processor. You can request the specific transfer mechanism for any processor by emailing the DPO.

8. Data retention

  • Active accounts - for as long as the account exists.
  • Deleted accounts - account record removed within 30 days of your deletion request; backups purged within 90 days.
  • Refresh tokens - 7 days from issuance, or until revoked.
  • API keys - until you revoke them.
  • Billing & tax records - kept for the period required by Brazilian tax law (typically 5 years), even after account deletion.
  • Application logs - at most 30 days.
  • Public presets - remain visible to other users while published; reverting a preset to private removes it from public discovery immediately.

9. Your rights (LGPD Art. 18)

As a data subject, you may at any time:

  • Confirm whether we process your personal data and access a copy of it.
  • Correct incomplete, inaccurate, or outdated data.
  • Request anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
  • Request portability - receive your data in a structured, machine-readable format.
  • Be informed about the public and private entities with which we share your data.
  • Be informed of the option to refuse consent and of the consequences of refusing.
  • Revoke any consent you previously gave.

To exercise these rights, email [email protected]. We respond within 15 calendar days. You also have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

10. Security

We apply industry-standard safeguards: TLS for all traffic, bcrypt for password and API-key hashing, refresh-token family reuse detection, content security policies, and least-privilege access controls on our infrastructure. No system is perfectly secure - please report any vulnerability to [email protected].

11. Children

The Service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe we have, contact the DPO and we will delete the data promptly. Users aged 13–17 must have parental or guardian consent.

12. Changes to this policy

We update this policy when our practices change. The “Effective” date at the top reflects the latest revision. Material changes will be notified by email to registered users at least 14 days before they take effect.

13. Contact & DPO

Data Protection Officer: [email protected]
General contact: [email protected]
Security reports: [email protected]

See also our Terms of Use.