Legal
Privacy Policy
Effective 18 June 2026
Ameretat LLC ("Ameretat", "we", "us") builds privacy-first software. This policy explains what personal data we collect, why we collect it, the legal bases we rely on, who we share it with, how long we keep it, and the choices and rights you have. Our guiding principle is data minimization: we try not to collect what we don't need. This policy also serves as our notice at collection for purposes of US state privacy laws. It should be read together with our Terms of Service and Refund Policy.
Ameretat is a limited liability company organized in the State of Wyoming, USA, with a registered address at 30 N Gould St, Ste N, Sheridan, WY 82801, USA. Our paid products are sold through Paddle, our authorized reseller and Merchant of Record. Paddle is the seller of record for purchases and is a separate, independent data controller for the checkout and billing data it collects; this is explained in section 2 below.
1. Who we are and how to contact us
For the personal data Ameretat collects directly — described in this policy — the data controller is Ameretat LLC, a State of Wyoming, USA limited liability company at 30 N Gould St, Ste N, Sheridan, WY 82801, USA. You can reach us about any privacy matter, including to exercise your rights, at support@ameret.at.
Paddle, our Merchant of Record, is a separate and independent data controller for the payment and billing data it collects to complete your purchase. Paddle's identity, address, and contact details are provided to you at checkout and on your receipt or invoice, and it operates under its own privacy policy. Requests about payment or billing data are routed to Paddle as the controller of that data.
2. The controllers and their roles
Because purchases run through a Merchant of Record, two organizations act as independent controllers for different sets of data. We are not joint controllers, and Paddle is not our processor.
- Ameretat is the controller for data it collects directly: account email addresses (for products that use an account), public-key entitlement and license records, support correspondence, consented product analytics, and minimal operational and security logs. Ameretat is also the controller for the limited transaction data it receives from Paddle (such as an order reference and subscription status).
- Paddle is the independent controller for the payment and billing personal data it collects at checkout (such as your email, billing and tax details, and full payment-card data), which it processes under its own privacy policy and determines the retention and security of. Ameretat does not receive or store your full payment-card details.
3. Payments and your purchase
When you buy a product, Paddle acts as our authorized reseller and Merchant of Record and is the seller of record responsible for checkout, invoicing, the calculation, collection, and remittance of applicable VAT and sales taxes in your jurisdiction, chargebacks, and the EU right-of-withdrawal consent collected at checkout. Paddle's Buyer Terms apply to the sale. Ameretat does not charge, collect, file, or remit any tax, and is not registered for VAT or OSS; Ameretat is the publisher and supplier of the underlying software and the party responsible for the product, licensing, support, and the privacy practices described here. We receive only limited transaction data (for example, an order reference and subscription status) to deliver and support your purchase.
4. What we collect and the data we receive from others
What we hold depends on the product. We collect the following categories of personal data directly from you:
- Account email — for products that use a standard account, identified by your email address.
- Entitlement and license records — for products designed for privacy, access is tied to a key or credential you control, and entitlement is linked to a public key rather than to your identity. For these products there is no account email; they are designed so that we cannot read your content, and we store only what is needed to enforce your plan.
- Support correspondence — the contents of messages you send us when you ask for help.
- Usage activity — internet and usage activity collected through analytics, only after you opt in (see section 5).
- Operational and security logs — minimal technical logs needed to run and secure the Services. We minimize or avoid retaining identifiers such as IP addresses.
We do not draw inferences or build profiles about you, and we do not collect "sensitive personal information" as defined under US state laws (such as government identifiers, precise geolocation, the contents of your communications beyond support you choose to send, financial-account login credentials, or genetic or biometric data) for any purpose that would trigger a right to limit its use.
We also receive a limited amount of data that does not come from you directly. Paddle, as the source, passes us limited buyer data — typically an order reference, the email associated with your order, and your subscription status — so that we can fulfil your purchase, provide support, and provision your license or entitlement. We process this received data on the basis of contract and our legitimate interest in fulfilment, support, and fraud prevention, and we restrict its use to those purposes.
5. Usage analytics, only with your consent
We use PostHog (EU-hosted) to understand how our products are used so we can improve them. Analytics load only after you opt in via the consent banner. PostHog analytics load only after you opt in, and we do not set non-essential analytics storage before then. You can change your choice at any time using in the footer, which re-opens the consent control so you can withdraw consent as easily as you granted it. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
The consent banner offers a symmetrical, equal-weight choice: declining is no harder or slower than allowing, there are no pre-checked boxes, no double negatives, and no dark patterns. Analytics are configured to avoid collecting unnecessary personal information, and we do not use them for advertising. We do not sell or share your personal data.
6. Cookies and local storage
We use your browser's local storage for strictly necessary purposes that do not require consent: remembering your theme preference and your analytics-consent choice. PostHog analytics cookies or storage are set only after you opt in via the banner, and your choice is re-openable through Privacy choices in the footer. We do not set non-essential analytics storage before you opt in.
7. Legal bases for processing
Where the EU or UK GDPR applies, we rely on a specific lawful basis for each purpose:
- Delivering and enforcing a purchased product and its license — performance of a contract (Art. 6(1)(b)).
- Maintaining your account email for products that use an account — performance of a contract (Art. 6(1)(b)).
- Product analytics (PostHog) — your consent (Art. 6(1)(a)), loaded only after opt-in.
- Minimal operational and security logs, and abuse and fraud prevention — our legitimate interests in the security and integrity of the Services (Art. 6(1)(f)).
- Responding to data-subject-rights requests and legal requests — compliance with a legal obligation (Art. 6(1)(c)).
8. Where your data is stored and international transfers
Our systems and databases are hosted in the European Union (Hetzner, Germany), and we choose service providers that allow us to keep data within the EU where practical.
Ameretat is a US entity, so any access to or export of EU or UK personal data back to the US is treated as a restricted international transfer under Chapter V of the GDPR. Where such a transfer occurs, we put an appropriate Chapter V safeguard in place before relying on it: typically the European Commission's Standard Contractual Clauses (including Module Four where relevant), or the EU-US Data Privacy Framework where the recipient is certified, together with a transfer-impact assessment where one is required. Paddle relies on its own transfer mechanism for the payment data it controls, as described in its privacy policy. We do not claim that data is never accessible from outside the EU.
9. Recipients and service providers
We disclose personal data only to the following recipients, for the business purposes shown. These disclosures are to service providers and processors acting on our behalf, and, in the case of Paddle, to an independent controller of payment data. They are not sales or shares of your personal information.
- Paddle — payments and Merchant-of-Record services; an independent controller for the checkout and billing data it collects (email, billing and tax details, and full card data) under its own privacy policy. Requests about that payment data are routed to Paddle.
- PostHog (EU-hosted) — product analytics as our processor, only after you consent. Data stays in the EU.
- Hetzner (Germany) — hosting and infrastructure as our processor. Data stays in the EU.
We aim to keep this list current; the providers above reflect our current setup, which we review at least every twelve months.
10. How long we keep data
We keep personal data only as long as needed for the purpose it was collected for, applying the following criteria per category:
- License and entitlement records — kept for the life of your entitlement, plus a short tail afterward for support and audit purposes.
- Operational and security logs — kept only briefly, typically for a small number of days, then deleted or de-identified.
- Support correspondence — kept for as long as needed to resolve your request and a reasonable period afterward.
- Analytics — retained according to the consented PostHog configuration.
- Payment and billing records — retained by Paddle under its own policy and applicable tax law, not by Ameretat.
For zero-knowledge products such as sukey.sh, we store only minimal entitlement data keyed to a public key; we do not store readable user content, and we cannot read it or recover a lost key.
11. Security
We take technical and organizational measures appropriate to the nature of each product and the risks involved, and we strengthen them as our products develop. In every case, connections use encryption in transit (TLS), our systems and databases are hosted in the European Union (Germany), and zero-knowledge products such as sukey.sh encrypt your content under a key you control so that we cannot read it and cannot recover a lost key. No method of storage or transmission is perfectly secure, and the security of payment data is handled by Paddle.
12. Automated decision-making
Ameretat does not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects, within the meaning of Article 22 of the GDPR. Any payment-fraud screening is performed by Paddle under its own terms. If we ever introduce automated processing that falls within Article 22, we will disclose it, identify the basis we rely on, and offer you human review, the ability to express your point of view, and the ability to contest the decision.
13. Your rights (EU / UK GDPR)
If the EU or UK GDPR applies to you, you have the right to: access your personal data; have it rectified; have it erased; restrict its processing; data portability; object to processing based on our legitimate interests; and not be subject to a solely automated decision that produces legal or similarly significant effects. Where we rely on consent (for analytics), you have the right to withdraw it at any time using Privacy choices in the footer, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email support@ameret.at. Requests concerning payment or billing data are routed to Paddle as the controller of that data.
We act on requests unless an exception applies. We may decline or defer erasure or deletion where we still need the data to provide a product or honour a live entitlement, to meet a legal or tax retention obligation, or where we cannot verify a request from a public-key-only user who has no account. Deleting a key-based entitlement record ends the entitlement bound to that key (see our Terms of Service, section 3).
Nothing in this policy limits, waives, or replaces any data-protection right or remedy that cannot be excluded or limited under applicable mandatory law. Where this policy and a non-waivable statutory right conflict, the statutory right prevails.
You also have the right to lodge a complaint with a supervisory authority. You can always complain to the authority in your own country or region. Because Ameretat operates from Germany, our own supervisory authority is the competent German state (Land) data protection authority. UK data subjects may complain to the UK data protection regulator.
14. EU and UK representatives
Ameretat is incorporated in the United States but carries out its activities from within the European Union. Because we operate from the EU, we are subject to the GDPR directly, and the Article 27 obligation to appoint an EU representative (which applies only to controllers that have no establishment in the EU) does not apply to us while this remains the case.
For the United Kingdom, the requirement for a non-UK controller to appoint a UK representative under the UK GDPR has been affected by the Data (Use and Access) Act 2025. Where a UK representative is required, we will appoint one and name them here.
You can contact us about any data-protection matter at support@ameret.at, and you may lodge a complaint with the data-protection authority in your country of residence.
15. Your privacy rights (US states)
Depending on the US state in which you reside, you may have rights under laws such as the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), and the Connecticut Data Privacy Act (CTDPA). We extend the core of these rights to all US users, regardless of whether a given law's applicability thresholds are met.
Ameretat does not sell your personal information and does not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA, and we do not engage in targeted or behavioral advertising.
The rights we honor include:
- Right to know and access — the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties to whom we disclose it.
- Right to delete — to request deletion of your personal information.
- Right to correct — to request correction of inaccurate personal information.
- Right to opt out of sale or sharing — not applicable, because we do not sell or share personal information.
- Right to limit the use of sensitive personal information — not applicable, because we do not collect sensitive personal information for purposes that would require limitation.
- Right to non-discrimination — equal service and price whether or not you exercise a privacy right (see section 18).
You can submit a request in at least two ways: by emailing support@ameret.at, or by writing to us at 30 N Gould St, Ste N, Sheridan, WY 82801, USA. We will take reasonable steps to verify your identity before acting on a request, using the information we already hold (such as your order reference or account email), and an authorized agent may submit a request on your behalf with proof of authorization.
16. Categories collected and disclosed (US notice at collection)
This section maps the data above to US state-law categories so this policy also serves as our notice at collection:
- Identifiers — an email address where a product uses an account; a user-controlled public key or entitlement identifier. Purpose: delivering and supporting the product and enforcing entitlements. Basis of disclosure: not sold or shared.
- Commercial / transaction information — a limited order reference and subscription status received from Paddle. Purpose: fulfilment, support, and refunds processed via Paddle.
- Internet or other electronic network activity — usage activity via opt-in analytics only. Purpose: product improvement.
- Inferences — none. We do not draw inferences or build profiles.
We do not sell or share any of these categories. Retention is described in section 10. This policy is our full notice; the categories and purposes described reflect our practices in the preceding twelve months.
17. Sensitive personal information
Ameretat does not collect "sensitive personal information" as defined by the CCPA — such as government identifiers, precise geolocation, the contents of your communications, financial-account login credentials, or genetic or biometric data — for any purpose that would trigger the right to limit its use. For zero-knowledge products, your content and secrets are encrypted under a key you control and are unreadable to us, and full payment-card details are handled by Paddle and never received by us. The "right to limit the use of sensitive personal information" therefore does not apply, and we do not display a "Limit the Use of My Sensitive Personal Information" link.
18. Non-discrimination
We will not deny you products or services, charge you a different price or rate, or provide you a different level or quality of products or services because you exercised a privacy right. Our free tier and your rights under our Refund Policy are unaffected by exercising any privacy right.
19. No "Do Not Sell or Share" link
We do not provide a "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" opt-out link, because we do not sell or share personal information and do not engage in cross-context behavioral advertising. The "Privacy choices" control in our footer is an opt-in analytics-consent gate (it lets you choose whether to load PostHog), not a CCPA sale/share opt-out.
20. Additional state-law commitments
Consistent with the VCDPA, CPA, and CTDPA, we commit to: collecting only personal data that is adequate, relevant, and reasonably necessary for the disclosed purposes (data minimization); processing it only for those disclosed or compatible purposes (purpose limitation); and obtaining consent before processing sensitive data. If we decline a privacy request, you may appeal by replying to our response to support@ameret.at; we will respond within the applicable statutory window and, where required (for example, in Colorado), tell you how to contact the state Attorney General.
21. Children
The Services are general-audience and not directed to children. We do not knowingly collect personal data from children under 13, and we do not ask for ages or dates of birth that would give us actual knowledge that a user is a child. Where consent is the basis for an information-society service offered to a child below the applicable age of digital consent (16 under the EU GDPR default, lower in member states that legislate down to 13; 13 under the UK GDPR), parental consent would be required. If we learn that we have collected personal data from a child under the applicable age, we will delete it. A parent or guardian can request deletion by emailing support@ameret.at.
22. Changes to this policy
We may update this policy. We review it at least every twelve months, and the categories and purposes described reflect our practices in the preceding twelve months. When we make changes, we update the effective date above. For material changes, we provide additional notice through appropriate means before they take effect — for example, an in-product or on-site notice, or, for products that use an account, by email. For privacy-first products that have no account or email, in-product or on-site notice is the channel we use. Significant changes are communicated in clear, plain language.
23. Contact
Ameretat LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA. Privacy questions? Email support@ameret.at. For payment or billing data, Paddle's contact details are on your checkout receipt or invoice.