SQL Sage · Privacy Policy
← Back to site

Privacy Policy

Last updated: 5 October 2026

This Privacy Policy is written in English, which is the authoritative version. Any translation (including the Polish section below) is provided for convenience only; the English version prevails in case of any discrepancy.

SQL Sage is a Windows extension for SQL Server Management Studio 22 — a developer productivity tool. We built it to send as little of your data through us as technically possible. This policy explains what we do and, just as importantly, what we never touch.

In one line: SQL Sage is bring-your-own-key (BYOK) developer tooling. We do not sell access to AI models or inference, we do not run your queries through our servers, and your AI credentials and license key are stored locally on your machine, encrypted — never transmitted to us.

Contents

  1. Who we are
  2. Scope of this policy
  3. What data is involved
  4. Data sent to the AI provider
  5. Local, encrypted secrets
  6. Licensing & update checks
  7. Payments & billing
  8. Legal bases (GDPR)
  9. Sub-processors
  10. Retention
  11. International transfers
  12. Your rights
  13. Security
  14. Children
  15. Website analytics & cookies
  16. Changes to this policy
  17. Contact

1Who we are

SQL Sage is an independent product of LUMA sp. z o.o. (trading as LumaSoft), a limited liability company registered in Poland: ul. Gawronia 15, 04-785 Warszawa, Poland; KRS 0001244636, NIP PL9522285489, REGON 544875680 ("we", "us", "the vendor"). We are the data controller for the limited personal data described in this policy.

SQL Sage is not affiliated with Microsoft, Anthropic, or OpenAI.

You can reach us on any privacy or data-protection matter, including a request about your own data, at [email protected]. For anything else — installation, licences, refunds — write to [email protected].

We have not appointed a data protection officer. None of the conditions in Art. 37(1) GDPR applies to us: we are not a public authority or body; our core activities do not consist of processing that requires regular and systematic monitoring of data subjects on a large scale (the extension contains no analytics or tracking code; its few requests to our servers, listed in section 6, carry no personal data other than the opaque licence identifier used for licence validation, and our server keeps aggregate counts plus, per licence, only the date it was last validated); and we do not process special categories of data, or data relating to criminal convictions and offences, on a large scale. The mailbox above is the contact point for all data-protection matters.

2Scope of this policy

This policy covers the SQL Sage extension installed on your Windows machine, our public website, and the limited backend services we operate for licensing and updates. It does not cover the AI provider you connect to (Anthropic or OpenAI), your SQL Server, or Paddle as our Merchant of Record — see the relevant sections below for how those relationships work.

3What data is involved

SQL Sage is architected to minimise the personal data that reaches us. The categories of data involved are:

DataWhere it livesDoes it reach us?
Your query text and database schema metadata (table / column / index names)Sent by the extension to your AI provider as contextNo — goes to your AI provider under your own account/key
Query result data (rows returned by your database)Stays on your machine unless you explicitly opt in per sessionNo
BYOK API key and license keyLocal, encrypted (Windows DPAPI)No — never transmitted to us
AI provider credentials (Claude / ChatGPT sign-in)Managed by the respective CLI on your machineNo — we never see, store, or transmit them
License identifier (paid licences only)Sent to our license-validation endpoint over HTTPSYes — an opaque identifier only, no personal data or query content. Our server also records the date it last saw that identifier (kept for 35 days) and a running count of validations, to count active installations
Update check and signed model listAnonymous HTTPS requests for two static files (see section 6)Standard connection metadata only (e.g. IP in server logs)
Download countOne anonymous request when you click Download on our website or in the extension's update banner (sections 6 and 15)Yes — as an increment of aggregate totals only; no identifier
Billing details (name, email, payment data, tax location)Handled by Paddle as Merchant of RecordNo — collected and held by Paddle, not us
The email address you use at checkout, and the Paddle transaction / subscription identifiersOur licence records (Cloudflare Worker + key-value store)Yes — so we can issue, deliver and re-send your licence key
Support correspondence & newsletter email (if you contact us or subscribe)Our Microsoft 365 mailboxes on the lumasoft.pl domainYes — only what you send us

Data stored on your machine

The extension keeps its own data in %LOCALAPPDATA%\SqlSage under your Windows user profile. None of it is uploaded to us.

File or folderWhat it holds
settings.jsonYour settings: provider and models, pinned document, and switches such as Mask names, Audit SQL, Save chats (and how long to keep them), Check for updates, Include results and inline completions. Plain text.
sessions\Your saved chats, one .session file per chat: your prompts, the SQL and schema details exchanged, the server, database and login name of the connection, and — only if you shared them under the results consent — query results. Encrypted with Windows DPAPI for your Windows account (other Windows users on the machine cannot read them; programs running as you can). Written only while Save chats is on (on by default; turning it off deletes the saved chats). A chat you have not used for longer than the period you pick next to that switch (default 30 days; you can choose to keep chats) is deleted when SQL Sage starts. Chats saved as plain text by earlier versions (0.21.0 and before) are encrypted the first time a newer version reads them.
audit\audit-YYYYMMDD.jsonlThe audit log of the queries SQL Sage runs or blocks: server, database, login, classification, the full SQL text, row count and the model used, hash-chained. On by default; the Audit SQL switch turns it off.
usage\usage-YYYYMMDD.jsonlToken counts per AI request with the operation, channel, model and correlation identifiers — no SQL text and no server or database names. Always written.
byok.datYour own Anthropic API key, if you set one — encrypted with Windows DPAPI.
license.dat, trial.datYour licence key, and the trial's first-use and last-seen dates — encrypted with Windows DPAPI.
Registry value HKCU\Software\LumaSoft\SqlSage\TrialMarkerThe trial's first-use date only, kept as a second record outside this folder so that losing or deleting trial.dat does not restart the trial — encrypted with Windows DPAPI. No identifier; never sent anywhere.
policy.lkg.jsonThe last valid copy of the signed model list (section 6).
repo-map.jsonWhich source repository you connected to which server and database, and your consent to that connection.
diag.logDiagnostics: written only when the SQLSAGE_DIAG=1 environment variable is set, or when an error occurs (for example, the panel fails to start).
snapshots\Left from earlier versions; the current version only deletes stale content there when SSMS starts.

While a source repository is connected on the Claude channel, a small settings file that blocks Claude Code's own file tools is written to your Windows temporary folder (%TEMP%) and deleted when that Claude Code process ends. An evidence pack you export is saved only where you choose, and it includes your computer name and Windows user name. Uninstalling SQL Sage does not delete %LOCALAPPDATA%\SqlSage — see section 10.

4Data sent to the AI provider

When you use the chat, query help, or safe-execution features, the extension sends the following to your chosen AI provider (Anthropic or OpenAI) as context: your query text and database schema metadata — the names of tables, columns, and indexes.

Query result data (production data) is never sent unless you explicitly opt in for that session. A "Mask names" option replaces server and database identifiers with placeholders before anything leaves your machine.

The extension makes this explicit at the point of use: a persistent egress indicator in the chat context bar shows where content is going (the named provider when you sign in through Claude Code or the Codex CLI, or "your endpoint" for BYOK), and an (i) "What's sent" panel lists exactly the following — the same guarantees this section describes:

Sent to the AI provider:

Not sent (stays on your machine):

What the provider then does with the query text and schema it receives is governed by your relationship with that provider (their terms and privacy policy), including any model-training and data-retention settings on your account — matters we do not control and do not represent on their behalf.

Crucially, at launch the AI provider processes this data under your own account, subscription, or BYOK key. That means your direct relationship with Anthropic or OpenAI — their terms and privacy policy — governs how that data is handled. We are not an intermediary for AI inference and we do not resell access to AI models. We recommend you review your AI provider's privacy terms:

Roadmap note. A future hosted, keyless completions feature (a paid option on our roadmap) would route requests through our own infrastructure, adding Anthropic as our sub-processor. This policy will be updated before any such feature ships. It is not part of the product today.

5Local, encrypted secrets

Two kinds of secret are stored only on your machine, encrypted at rest via the Windows Data Protection API (DPAPI), scoped to your Windows user account:

These are never transmitted to us and never stored in plaintext, in the Windows registry, or in version control. Your AI provider sign-in tokens (for Claude Code or Codex) are managed entirely by those CLIs — SQL Sage only asks whether you are signed in; it never sees, stores, or transmits those credentials.

6Licensing, updates & other network requests

Trial. SQL Sage offers a 30-day free trial with no credit card required. The trial is tracked locally on your machine — its first-use date is kept in trial.dat and, as a second record, in the registry value HKCU\Software\LumaSoft\SqlSage\TrialMarker (both encrypted with Windows DPAPI); it makes no request to us. If either record is lost the trial continues from the earlier date; if the records cannot be read, SQL Sage switches to SQL Sage Free rather than starting a new trial.

These are all the requests the extension itself makes to our servers. None of them carries your name, email, a device or installation identifier, your queries, schema or results, and none sets a custom user agent. As with any HTTPS request, our hosting provider (Cloudflare) sees your IP address and may keep it transiently in server logs.

AI requests do not go through us. If you use your own Anthropic API key, the extension sends your prompts directly to Anthropic (api.anthropic.com). If you use Claude Code or the Codex CLI, SQL Sage runs that tool on your machine and the tool talks to Anthropic or OpenAI under your own account (section 4).

7Payments & billing

Purchases are processed by Paddle, acting as Merchant of Record (MoR). Paddle is the seller of record: it collects and processes your billing information (name, email, payment method, and tax/location data), handles VAT/GST/sales tax, issues invoices, and manages chargebacks and refunds. Paddle also serves the checkout overlay in your browser when you use a buy button, and your purchase is subject to Paddle's own checkout terms.

What reaches us. We do not receive or store your payment card details. From the payment notification we receive and store the email address you used at checkout (together with a SHA-256 hashed index of it, used for lookups) and the Paddle transaction and subscription identifiers, alongside the licence record itself — that is what lets us issue your key, tie a renewal or cancellation to it, and re-send it if you lose it.

Delivery. The key is issued as soon as the payment notification is verified and is retrievable from our licensing service using the transaction identifier Paddle gives you at checkout. If you lose it, a resend endpoint re-sends the keys held for an address you enter; the response is deliberately identical whether or not we hold anything for that address, and the endpoint is rate-limited per address and IP address, using counters keyed by a hash that expire automatically. Where email delivery is enabled, the key is sent from our own Microsoft 365 mailbox on the lumasoft.pl domain; we do not hand your address to a bulk-email or marketing platform, and we never use it to market to you.

For payment-data privacy requests, Paddle acts as controller of that billing data; we will help route your request to them. See our Sub-processors page.

9Sub-processors

We use a small number of sub-processors to operate the service: Cloudflare (static hosting, the licence-fulfilment Worker and its key-value store, and installer storage), Paddle (Merchant of Record for payments), Google Ireland Limited (Google Analytics 4 on the website only, and only if you allow statistics — see section 15) and Microsoft (Microsoft 365, which hosts the mailboxes the licence-key email is sent from and our correspondence is kept in). Paddle is our only payment channel; a second, unfinished Merchant of Record integration exists in our licensing service but is inactive and closed by default, so no data reaches that provider — the Sub-processors page explains this. At launch, Anthropic and OpenAI are your providers (via your own account or BYOK), not our sub-processors. If you allow ad measurement on our website, Google Ireland Limited (Google Ads) also receives data for that purpose — as an independent controller, not as our sub-processor; see section 15. The full, current list — with roles and locations — is maintained on our Sub-processors page.

10Retention

11International transfers

Our infrastructure providers operate globally. Where personal data is transferred outside the European Economic Area, such transfers are covered by appropriate safeguards (for example, the European Commission's Standard Contractual Clauses) implemented by the relevant provider. Any data you send to your AI provider is transferred under your own agreement with that provider.

12Your rights

Under the GDPR you have the right to: access your personal data; request rectification or erasure; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

To exercise any of these, write to [email protected]. For requests about payment and billing data, Paddle is the controller of that data as Merchant of Record; tell us and we will point you to the right place.

13Security

We follow a data-minimisation and least-custody approach: secrets stay on your machine encrypted via DPAPI, our license service transmits only opaque identifiers over HTTPS, and we never take custody of your AI provider tokens. No method of transmission or storage is perfectly secure, but we design the product so that there is very little sensitive data on our side to protect in the first place.

14Children

SQL Sage is a professional developer tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.

15Website analytics & cookies

On our public website we use two Google services, each only with your consent and each switched on separately (Google Consent Mode v2 in basic mode):

What we do not do: personalised advertising and remarketing — the ad_personalization consent signal always stays denied and is never offered — and Google signals is not enabled for our Analytics property. How Google itself uses data from sites that use its services: policies.google.com/technologies/partner-sites.

Before you choose, and if you reject: the Google tag is not loaded at all — nothing is stored on your device for Google and nothing is sent to Google. Only after you allow a purpose does the Google tag load, with the consent signals for that purpose set to granted; if you allow only statistics, every advertising signal stays denied, and the other way round.

Cookies and browser storage (Google's cookies are set on our domain lumasoft.pl; lifetimes as published by Google):

NameSet by / whenPurposeLifetime
_gaGoogle Analytics — only if you allow statisticsDistinguishes visitorsUp to 2 years
_ga_<ID>Google Analytics — only if you allow statisticsKeeps the session stateUp to 2 years
_gcl_auGoogle Ads — only if you allow ad measurementConversion measurement90 days
_gcl_awGoogle Ads — only if you allow ad measurement and arrive from one of our adsRemembers the ad click for conversion measurement90 days
sqlsage-consent-v3 (local storage)Us — when you make a choiceYour choice per purpose, the version of the banner text and the date, so we do not ask againUntil you change it or clear your browser data
sqlsage-ad-visit (session storage)Us — only if you allow ad measurement and arrive from one of our adsThe value 1, so a download later in the same tab counts as coming from an adUntil the tab is closed
sqlsage-channel (session storage)Us — only if you allow statistics and arrive on the home page through a link tagged with a channelThe channel label from the fixed list in the download-counter paragraph below (for example reddit), so a download later in the same tab counts for that channelUntil the tab is closed
sqlsage_lang (local storage)Us — only if you pick a language on the home pageThe language you pickedUntil you clear your browser data

The checkout script of Paddle, our Merchant of Record, is loaded only when you click a buy button (section 7).

Legal basis: your consent (Art. 6(1)(a) GDPR). Retention: Google Analytics data is kept according to our Google Analytics data-retention setting; for ad measurement Google keeps data under its own terms as an independent controller. Transfers: Google may process this data in the United States. Google LLC states that it is certified under the EU-U.S. Data Privacy Framework (policies.google.com/privacy/frameworks); where that certification applies, the transfer relies on the European Commission's adequacy decision of 10 July 2023, and otherwise on the Standard Contractual Clauses in Google's data protection terms.

Withdrawal: you can change or withdraw your choice at any time with the Cookie settings control at the bottom of every page that uses these services, or here:

When you reject or withdraw a purpose, its consent signals are set back to denied and its Google cookies (_ga* for statistics, _gcl* for ad measurement) are deleted from our domains, together with our session-storage value for that purpose (sqlsage-channel for statistics, sqlsage-ad-visit for ad measurement); withdrawal does not affect processing carried out before it. This applies to the website only; the SQL Sage extension contains no analytics or tracking code (its requests to us are listed in section 6).

Download counter (not Google). Clicking Download on the home page sends one count to our own server (the Cloudflare Worker at api.lumasoft.pl). The count contains no identifier and sets no cookie; our server only increments aggregate totals — a running total and a total per day (UTC). The same counter also counts downloads started from the extension's update banner (section 6). Only if you have allowed ad measurement and arrived from one of our Google ads does the count carry the label gads, so we can tell how many downloads came from ads (and the session-storage value above keeps that label while you browse the site). Without that consent the count from an ad visit carries no label at all and nothing is stored in your browser. The ad-click identifier in the address bar is never stored or sent by this counter. Channel label. When you reach the home page through a link we tagged with a channel (for example ?src=reddit or a utm_source parameter), the count carries one label from this fixed list: reddit, ssc (SQLServerCentral), linkedin, github, newsletter, hn (Hacker News), x, youtube, or other for any other tag; the value in the address itself is never sent or stored, and our server accepts only labels from this list. The label is read from the address of the page you are on and contains no identifier — it says which link was used, not who used it — so it needs no storage and no consent. Only if you have allowed statistics does your browser keep that label in session storage (table above) so that a download later in the same tab still counts for that channel; the first channel of the tab session is kept. Legal basis for the count and the channel label: our legitimate interest in knowing how often the product is downloaded and which of our links lead to downloads (Art. 6(1)(f) GDPR); for the gads label and for keeping a label in session storage: your consent.

16Changes to this policy

We may update this policy as the product evolves — notably before any hosted/keyless AI feature ships (see section 4). When we make material changes, we will update the "Last updated" date and, where appropriate, notify you.

17Contact

LUMA sp. z o.o.
ul. Gawronia 15, 04-785 Warszawa, Poland
KRS 0001244636 · NIP PL9522285489 · REGON 544875680
Data protection and privacy: [email protected]
Everything else: [email protected]

// The following is a Polish translation provided for convenience. The English version above is the legally binding text.

Polityka prywatności (wersja polska — informacyjnie)

Wersja angielska ma moc rozstrzygającą. Poniższe tłumaczenie na język polski ma charakter wyłącznie informacyjny; w razie rozbieżności obowiązuje wersja angielska.

SQL Sage to rozszerzenie dla SQL Server Management Studio 22 działające w systemie Windows — narzędzie zwiększające produktywność deweloperów. Działa w modelu BYOK (własny klucz): nie sprzedajemy dostępu do modeli AI ani inferencji, nie przepuszczamy Twoich zapytań przez nasze serwery, a Twój klucz API (BYOK) oraz klucz licencyjny są przechowywane lokalnie na Twoim urządzeniu, zaszyfrowane mechanizmem Windows DPAPI — nigdy nie są przesyłane do nas.

Administrator danych: LUMA sp. z o.o., ul. Gawronia 15, 04-785 Warszawa (KRS 0001244636, NIP PL9522285489, REGON 544875680). Sprawy danych osobowych: [email protected]; pozostałe sprawy: [email protected]. SQL Sage nie jest powiązany z Microsoft, Anthropic ani OpenAI.

Nie powołaliśmy inspektora ochrony danych (IOD). Nie spełniamy przesłanek art. 37 ust. 1 RODO: nie jesteśmy organem ani podmiotem publicznym, nasza główna działalność nie polega na regularnym i systematycznym monitorowaniu osób na dużą skalę (rozszerzenie nie zawiera kodu analitycznego ani śledzącego; jego nieliczne zapytania do naszych serwerów, opisane niżej, nie zawierają danych osobowych poza nieprzejrzystym identyfikatorem licencji przy jej walidacji, a serwer przechowuje zagregowane liczniki oraz — dla każdej licencji — tylko datę ostatniej walidacji), nie przetwarzamy też na dużą skalę danych szczególnych kategorii ani danych o wyrokach skazujących. Kontakt w sprawach danych: adres powyżej.

Dane wysyłane do dostawcy AI: treść Twojego zapytania oraz metadane schematu bazy (nazwy tabel, kolumn, indeksów). Dane wynikowe zapytań (dane produkcyjne) nigdy nie są wysyłane bez Twojej wyraźnej zgody dla danej sesji. Opcja „Mask names" maskuje nazwy serwera i bazy. W momencie startu produktu dostawca AI (Anthropic/OpenAI) przetwarza te dane na podstawie Twojego własnego konta lub klucza BYOK — regulują to Twoje umowy z tym dostawcą.

Licencjonowanie, aktualizacje i inne zapytania rozszerzenia: 30-dniowy darmowy okres próbny bez karty, śledzony lokalnie (bez zapytań do nas). Rozszerzenie wysyła do nas wyłącznie: (1) sprawdzenie aktualizacji — plik version.json przy starcie panelu (wyłączane przełącznikiem Check for updates); (2) podpisaną listę modeli models.v2.json (przy starcie panelu, zmianie dostawcy i dla podpowiedzi, najwyżej co 30 minut); (3) walidację licencji — tylko dla płatnej licencji, wyłącznie identyfikator licencji; serwer zapisuje datę ostatniej walidacji (przechowywaną 35 dni) i łączną liczbę walidacji; (4) licznik pobrań — tylko po kliknięciu Download w banerze aktualizacji rozszerzenia; serwer zwiększa wyłącznie sumy (łączną i dzienną). Żadne z tych zapytań nie zawiera imienia, e-maila, identyfikatora urządzenia ani instalacji, zapytań, schematu ani wyników; jak przy każdym zapytaniu HTTPS, Cloudflare widzi adres IP.

Dane na Twoim komputerze: rozszerzenie przechowuje w %LOCALAPPDATA%\SqlSage ustawienia (settings.json), historię czatów (sessions\, z nazwą serwera, bazy i loginu; zaszyfrowaną DPAPI dla Twojego konta Windows; zapisywaną tylko przy włączonym Save chats — wyłączenie usuwa zapisane czaty; czat nieużywany dłużej niż wybrany okres, domyślnie 30 dni, jest usuwany przy starcie), dziennik audytu (audit\, z pełną treścią SQL; domyślnie włączony, wyłączany przełącznikiem Audit SQL), zapis zużycia tokenów (usage\, bez SQL i nazw), zaszyfrowane DPAPI klucz API (byok.dat), licencję i daty trialu (license.dat, trial.dat; dodatkowo data pierwszego użycia, zaszyfrowana DPAPI, w rejestrze HKCU\Software\LumaSoft\SqlSage — utrata jednego zapisu nie restartuje trialu), kopię listy modeli (policy.lkg.json), mapę podłączonych repozytoriów (repo-map.json), dziennik diagnostyczny (diag.log — tylko przy SQLSAGE_DIAG=1 lub błędzie) oraz pozostałość starszych wersji (snapshots\). Nic z tego nie jest do nas wysyłane. Odinstalowanie SQL Sage nie usuwa tego folderu — usuń go samodzielnie (usuniesz też zapisany klucz licencyjny); zob. Docs › Update & uninstall.

Płatności: obsługuje je Paddle jako Merchant of Record (sprzedawca formalny) — to Paddle pobiera dane rozliczeniowe, dolicza i odprowadza VAT, wystawia faktury i obsługuje zwroty. Do nas trafia wyłącznie adres e-mail użyty przy zakupie (wraz z jego skrótem SHA-256 służącym do wyszukiwania) oraz identyfikatory transakcji i subskrypcji Paddle — potrzebne do wydania, dostarczenia i ponownego wysłania klucza licencyjnego. Klucz wysyłamy z naszej własnej skrzynki Microsoft 365 w domenie lumasoft.pl; nie przekazujemy Twojego adresu do platform mailingowych ani marketingowych.

Podprocesorzy: Cloudflare (hosting, Worker licencyjny i magazyn klucz-wartość), Paddle (Merchant of Record), Google Ireland Limited (Google Analytics 4 — wyłącznie strona i tylko po zgodzie na statystyki) oraz Microsoft (Microsoft 365 — skrzynki pocztowe). Pełna lista: Podprocesorzy.

Statystyki strony i pomiar reklam: każdy cel wyłącznie po Twojej zgodzie i osobno (art. 6 ust. 1 lit. a RODO; Google Consent Mode v2 w trybie podstawowym). Statystyki (Google Analytics 4) — Google Ireland Limited działa jako nasz podmiot przetwarzający (Google Ads Data Processing Terms). Pomiar reklam (Google Ads) — czy kliknięcie naszej reklamy doprowadziło do pobrania, rozpoczęcia zakupu lub zakupu; tu Google Ireland Limited działa jako niezależny administrator (Google Ads Controller-Controller Data Protection Terms), a za zbieranie danych na naszej stronie i ich przekazanie możemy odpowiadać wspólnie z Google. Nie stosujemy reklam spersonalizowanych ani remarketingu (sygnał ad_personalization jest zawsze odrzucony), a Google signals nie jest włączone. Zanim wybierzesz i gdy odrzucisz, tag Google w ogóle się nie ładuje — nic nie jest zapisywane na Twoim urządzeniu dla Google i nic nie jest wysyłane do Google. Pliki cookie po zgodzie: _ga i _ga_<ID> (statystyki, do 2 lat), _gcl_au i _gcl_aw (pomiar reklam, 90 dni); nasz wybór zgody zapisujemy w sqlsage-consent-v3 (local storage). Dane Google Analytics przechowujemy zgodnie z ustawieniem retencji danych w Google Analytics. Google może przetwarzać dane w USA; Google LLC deklaruje certyfikację w ramach EU-U.S. Data Privacy Framework — tam, gdzie ona obowiązuje, przekazanie opiera się na decyzji Komisji o adekwatności z 10 lipca 2023 r., w pozostałym zakresie na standardowych klauzulach umownych w warunkach Google. Zgodę możesz zmienić lub wycofać w każdej chwili przyciskiem Ustawienia cookies na dole każdej strony (lub w sekcji 15 powyżej); przy odrzuceniu lub wycofaniu usuwamy pliki cookie _ga* / _gcl* z naszych domen; wycofanie nie wpływa na zgodność z prawem przetwarzania sprzed wycofania.

Licznik pobrań (nie Google): kliknięcie Download na stronie głównej (lub w banerze aktualizacji rozszerzenia) wysyła jedno zliczenie do naszego serwera (Cloudflare Worker na api.lumasoft.pl). Zliczenie nie zawiera żadnego identyfikatora ani cookie; serwer zwiększa wyłącznie sumy — łączną i dzienną (UTC). Tylko jeśli zgodziłeś się na pomiar reklam i wszedłeś z naszej reklamy Google, zliczenie ma etykietę gads, a przeglądarka przechowuje wartość 1 w session storage danej karty do jej zamknięcia; bez tej zgody zliczenie z wizyty z reklamy nie ma żadnej etykiety i nic nie jest zapisywane. Identyfikator kliknięcia reklamy z paska adresu nie jest przez ten licznik ani zapisywany, ani wysyłany. Jeśli wejdziesz na stronę główną z linku oznaczonego kanałem (np. ?src=reddit albo parametr utm_source), zliczenie ma etykietę kanału z zamkniętej listy: reddit, ssc (SQLServerCentral), linkedin, github, newsletter, hn (Hacker News), x, youtube albo other dla każdego innego oznaczenia; sama wartość z adresu nie jest ani wysyłana, ani zapisywana, a serwer przyjmuje wyłącznie etykiety z tej listy. Etykieta pochodzi z adresu bieżącej strony i nie zawiera identyfikatora (mówi, którego linku użyto, a nie kto go użył), więc nie wymaga zapisu ani zgody. Tylko jeśli zgodziłeś się na statystyki, przeglądarka przechowuje tę etykietę w session storage danej karty (sqlsage-channel, do zamknięcia karty; zachowywany jest pierwszy kanał), żeby późniejsze pobranie w tej samej karcie liczyło się dla tego kanału; przy wycofaniu zgody na statystyki usuwamy ją. Podstawa: nasz prawnie uzasadniony interes w liczeniu pobrań i w tym, które nasze linki prowadzą do pobrań (art. 6 ust. 1 lit. f RODO); etykieta gads oraz zapis etykiety w session storage — Twoja zgoda.

Twoje prawa (RODO): dostęp, sprostowanie, usunięcie, ograniczenie i sprzeciw wobec przetwarzania, przenoszenie danych, cofnięcie zgody oraz skarga do Prezesa UODO. Wnioski: [email protected]; wnioski dotyczące danych płatniczych kierujemy do Paddle (Merchant of Record) jako administratora tych danych.

Pełną, wiążącą treść znajdziesz w wersji angielskiej powyżej.