Privacy policy
Founder-approved — effective October 3, 2026
This policy describes the privacy practices for SiteDatum, software created and operated by Francisco Cabrera as an individual developer.
Scope and local project data
SiteDatum is a local-first Windows application. Project records are stored in a local SQLite database and project documents remain ordinary Windows files. SiteDatum’s billing, licensing, support, and operational systems must not receive project names, tasks, RFIs, submittals, notes, contacts, file paths, documents, screenshots of private records, or database contents.
Accountless Free use
The Free edition works without registration. Ordinary local project work does not require a SiteDatum account or an internet connection, and no product analytics are authorized for the initial release.
Information used for Pro licensing
If a customer chooses Pro, SiteDatum’s licensing service may process the minimum information required to authenticate the customer, project subscription state, recover entitlement, and enforce the two-computer allowance. This may include an email address, authentication subject, provider customer and subscription references, plan and subscription status, paid-through date, pseudonymous device identity, device label supplied by the customer, entitlement timestamps, and content-free request and audit identifiers.
The licensing service must not receive local project content. Payment-card information is entered into Stripe-hosted surfaces and is not stored by the SiteDatum desktop application or licensing database.
Service providers
Stripe Managed Payments is the intended merchant of record for eligible Pro transactions and processes checkout, transaction, tax, subscription, refund, dispute, and related support information under Stripe’s privacy policy. Supabase hosts the separate SiteDatum authentication and licensing boundary. Provider access is limited to the minimum commercial data required for those services.
Support information
SiteDatum processes information a user deliberately sends to private support to answer and document the request. Customers should not send project documents, workspace databases, secrets, authentication codes, full payment-card information, or private customer data. Public GitLab issues must use fictional information only.
Telemetry and diagnostics
No product analytics, remote crash reporting, or operational telemetry are authorized for the initial release. If any collection is proposed later, it requires a separate data-minimization review and an updated privacy notice before collection begins.
Security
Licensing credentials are designed to use protected Windows credential storage. Server-only credentials and billing-provider secrets are not shipped in the desktop application. No method of storage or transmission is guaranteed to be completely secure.
Retention and deletion
Local project data remains under the customer’s control and has no SiteDatum cloud-retention period. SiteDatum retains active licensing records and content-free licensing audit events while needed to provide Pro and for up to 24 months after account closure or final subscription end. Ordinary closed support messages are retained for up to 12 months. Closed security, privacy, billing-dispute, or legal-hold cases are retained for up to 24 months, or longer only when applicable law, accounting obligations, an unresolved dispute, or a legal hold requires it. Provider-controlled transaction records follow the provider’s and applicable legal retention requirements. Deleted information may remain in protected backups until those backups expire through normal rotation.
Choices and requests
Customers may request access, correction, or deletion of SiteDatum-controlled licensing or support information through the private contact below. A request may be limited where retention is required by law, necessary to complete a transaction or resolve a dispute, or controlled directly by Stripe or another service provider. Local project records and ordinary Windows files are managed by the customer on the customer’s computer.
Children
SiteDatum is professional project-engineering software and is not directed to children under 13.
Changes
Material changes to this policy will be identified by a new effective date and communicated through the SiteDatum website or application before taking effect when notice is appropriate.
Contact
Privacy and security questions may be sent privately to supportsitedatum@protonmail.com.