Information we collect
- Account information: name, email, password hash, plan, policy-acceptance version, license status, and session records.
- Billing information: Stripe customer, subscription, invoice, and checkout identifiers. Stripe—not SealedOps—handles your subscription payment method.
- Connected-account information: Discord account identifiers and authorization state when you choose to connect Discord.
- Support and reliability information: messages you send and redacted diagnostics about crashes or failures when production error reporting is enabled.
- Desktop operational information: monitors, checkout identities, proxy configuration, and activity are primarily stored in the encrypted vault on your device. The app may send necessary license, account, update, or explicitly requested service calls.
Payment and checkout data
The desktop app stores full card numbers (PAN) and CVV values for checkout profiles inside the AES-256-GCM encrypted local vault on your device. The direct-API checkout engine submits these values to the retailer over HTTPS at checkout time; without them, direct-API checkout cannot place an order. The browser extension is narrower by design and never receives a full card number or a CVV — it uses only each profile's card network, last 4, and expiry.
For retailers that require authentication (Sam's Club, Costco, etc.), the checkout profile also stores the retailer account email and password in the same encrypted vault. The direct-API checkout engine uses these to log in and establish an authenticated session before adding items to cart. Retailer passwords are never displayed or returned to the browser after saving.
Retailers and the configured payment-token provider receive the information necessary to process a transaction. Their privacy terms govern their processing.
How we use information
- Authenticate accounts, manage subscriptions and licenses, and deliver the service.
- Process your requested Discord connection, billing, updates, monitoring, and checkout actions.
- Protect the service, investigate abuse, diagnose failures, and improve reliability.
- Comply with law and enforce our Terms.
Production diagnostics
Production error reports are designed to remove passwords, authorization headers, cookies, payment credentials, proxy credentials, email addresses, phone numbers, and street addresses before transmission. Reports may still include app version, operating-system details, route or operation name, retailer category, timing, and a stack trace. Do not place secrets in free-form names or support messages.
Retention and choices
We retain hosted account and billing records while your account is active and as needed for tax, fraud prevention, disputes, security, and legal obligations. Local desktop data remains on your device until you delete it or uninstall and choose to remove app data.
You may request account access, correction, or deletion by emailing support@sealedops.com. Some records may be retained where law or legitimate security and accounting needs require it. You can disconnect Discord from your account and manage billing through the account page.
Security, children, and changes
We use technical and organizational safeguards, but no system is perfectly secure. Keep your device, email, Discord, and SealedOps credentials protected. SealedOps is not directed to children under 13, and we do not knowingly collect their personal information.
We may revise this policy as the service changes. Material updates will be identified with a new effective date. Privacy questions can be sent to support@sealedops.com.