Legal

Privacy Policy

Version 1.0 · Effective 01/01/2026 · Last updated 01/01/2026

The summary, in three sentences. Your account store, on-machine data and backup packages stay on your machine — we do not receive, read or store them. Our server only receives key-check requests and records minimal technical logs to prevent unauthorised key sharing. Those logs are deleted after 30 days.

1. What we do NOT collect

This is the most important part, so it goes first:

  • Your account store. The usernames, passwords, cookies and tokens of the accounts you manage stay entirely on your computer. The software does not send them anywhere.
  • The contents of backup packages. Backups are created and kept on your machine. We receive no copy and cannot read them.
  • Data inside the device. Messages, photos, contacts, browsing history, application content.
  • The device's real location.
  • Payment details. Transactions run through a separate channel; we do not store card numbers.

2. What we DO collect

The licensing server records the following fields each time a device or the software calls it:

Data Why it is needed
Key To identify the license and check its expiry
IP address To detect one key running across too many network ranges — a sign of unauthorised key sharing
Call timestamp & processing time To detect abnormal call rates and block automated key probing
HTTP status code & result To distinguish valid / expired / rejected calls
Name of the function called To know which software build is in use and to support you when something fails
Account email (if you sign in) To link the key to its owner and help you when you lose the key
Installation identifier To count how many devices share one key

Note: an IP address is personal data under Decree 13/2023/ND-CP. We collect the minimum necessary for licensing and anti-abuse purposes, never for advertising and never for behavioural profiling.

3. How we use the data

  1. Authenticating keys and checking their expiry.
  2. Detecting and preventing unauthorised key sharing, key probing and attacks on the server.
  3. Technical support when you report a problem.
  4. Aggregate statistics (call counts, error rates) — in aggregate form, not tied to individuals.
  5. Responding to lawful requests from competent state authorities.

We do not use the data to sell, to advertise, or to share with third parties for commercial purposes.

4. Legal basis

  • Performance of a contract — key and email data are necessary to provide the service you bought.
  • Legitimate interest — IP and call-rate logs are necessary to protect the system from abuse.
  • Legal obligation — where we must provide data on a lawful request.

5. Retention

  • Technical logs (IP, timestamp, result): 30 days.
  • Abuse alert records: kept for up to 12 months for enforcement purposes.
  • Key details and owner email: kept for as long as the key is valid and for 12 months after expiry, to support renewals and resolve complaints.
  • Data we are required to retain by a competent authority: for the period required.

6. Data sharing

We do not sell, rent or trade your data. Data is shared only in the following cases:

  • Infrastructure providers — servers and authentication services, only to the extent needed to operate.
  • Competent state authorities — on a lawful written request, within the scope requested and as the law requires.
  • Protecting legitimate interests — where necessary to prevent fraud or protect system safety.

7. Security

  • Connections to the server are encrypted.
  • Access to the logs is restricted by a separate token, not shared with user accounts.
  • The server has rate limiting and an IP blocklist to limit attacks.
  • Even so, no system is perfectly secure. We cannot promise absolute security.
  • If a personal-data breach occurs, we will notify the affected users and the authorities as required.

8. Your rights

Under Decree 13/2023/ND-CP on personal data protection, you have the right to:

  • Know what data of yours is being processed.
  • Request a copy of your data.
  • Request correction of inaccurate data.
  • Request deletion, except what we must keep by legal obligation or for enforcement purposes.
  • Withdraw consent (note: we can then no longer license the software to you).
  • Complain to a competent authority.

Send requests to support@suchange.com. We respond within 30 days.

9. Cookies & website

This marketing site uses no tracking cookies, embeds no advertising code and embeds no third-party analytics. The server records ordinary technical access logs, as any web server does.

The application uses a session cookie when you sign in, solely to keep you signed in.

10. Children

The service is not intended for anyone under 18. We do not knowingly collect children's data. If we find any, we delete it immediately.

11. Changes to this policy

Updates are published on this page with a new effective date. For material changes we give at least 15 days' notice through your registered contact channel.

12. Contact

  • Email: support@suchange.com
  • Telegram: @suchange95
  • Data controller: [Legal entity / individual name — to be filled in]
  • Address: [Registered address — to be filled in]

See also: Terms of Use & Acceptable Use Policy.