# Privacy Policy

**Last Updated: 20 July 2026**

## 1. Introduction

We respect your privacy and are committed to protecting your personal data. This Privacy Policy ("Policy") explains how we collect, use, share, and safeguard information about you when you use our Website, API, and Console (together, "Our Services").

Because our servers are located in the European Union and we may make Our Services available to users in the European Economic Area ("EEA"), this Policy is designed to comply with both the Swiss Federal Act on Data Protection ("FADP") and the EU General Data Protection Regulation ("GDPR").

By accessing or using Our Services, you acknowledge that you have read and understood this Policy. Our Services are currently offered as a free, open beta; the practices described here apply during the beta and will be updated before any paid features are introduced.

## 2. Who We Are (Data Controller)

The data controller responsible for your personal data is:

- **Operator:** Alexandre van Beurden, a sole proprietor (*raison individuelle* / *Einzelfirma*) established in Switzerland.
- **Address:** [BUSINESS ADDRESS, SWITZERLAND] {/* to be completed */}
- **Contact:** legal@regexsolver.com

{/* If Our Services are directed at EEA users, an EU representative under GDPR Article 27 may be required. Add representative details here if/when appointed. */}
For any question relating to this Policy or the processing of your personal data, please contact us at legal@regexsolver.com.

## 3. Definitions

 - **"Website":** The websites accessible at regexsolver.com and its subdomains.
 - **"API":** The programming interfaces accessible at api.regexsolver.com.
 - **"Console":** The user account management interface located at console.regexsolver.com.
 - **"Our Services":** Includes the Website, API, and Console.
 - **"Authentication Provider":** The third-party service that provides identity verification and authentication, currently Firebase (Google). Refer to https://firebase.google.com/ for its terms and privacy policy.
 - **"Analytics Provider":** The third-party service that provides product and usage analytics, currently PostHog, operated on European Union infrastructure (EU region). Refer to https://posthog.com/privacy for its terms and privacy policy.
 - **"API Endpoint":** A specific function of the API that performs a designated task when provided with the necessary parameters.
 - **"API Request":** An operation where parameters are sent to an API Endpoint to execute a specific function.
 - **"User Data":** Consists of:
    - **"User Information":**
        - **"User Fullname":** The full name of the user as provided by the Authentication Provider.
        - **"User Email Address":** The email address of the user as provided by the Authentication Provider.
    - **"Usage Metadata":** Metadata related to each API Request, which includes:
        - **"Request Timestamp":** The date and time when the API Request is made.
        - **"Request Endpoint":** The API Endpoint on which the API Request is made.
        - **"Aggregate Counters":** Counts of requests used for rate limiting, quotas, and billing.

## 4. Information We Collect

 - **User Information:** We collect your full name and email address as provided by our Authentication Provider, Firebase, when you create or sign in to an account.
 - **Usage Metadata:** We collect metadata about how you use Our Services, such as the endpoint called, timestamps, and aggregate request counters used for rate limiting and quota enforcement.
 - **Analytics Data:** Through our Analytics Provider, PostHog, we collect data about how you interact with the Website and Console — such as pages viewed, buttons and links clicked, features used (for example, operations run in the online demo), approximate location derived from your IP address, and technical information about your device and browser. By default this is collected on a **cookieless and anonymous** basis (no persistent identifier is stored on your device). When you sign in to the Console, this data may be associated with your account identifier, name, and email address; if you have not accepted analytics cookies, this association is not stored persistently on your device. We do **not** record your screen or session, and we do not capture the content of the regular expressions or automata you submit. See Section 10 for how consent and cookies apply.
 - **Diagnostic Data:** In exceptional cases (such as errors or crashes), we may capture limited technical data to diagnose the problem. See Section 6.

**We do not store the content of your API Requests in the normal course of operation.** The regular expressions, automata, and other parameters you submit are processed in memory to compute a response and are not retained.

## 5. Legal Bases for Processing

Where the GDPR applies, we process your personal data on the following legal bases:

 - **Performance of a contract** — to create and operate your account and to provide the API functionality you request.
 - **Legitimate interests** — to secure Our Services, prevent fraud and abuse, diagnose technical issues, and improve Our Services (including cookieless, anonymous analytics), provided these interests are not overridden by your rights.
 - **Legal obligation** — to comply with applicable laws and lawful requests.
 - **Consent** — where we rely on your consent (for example, for non-essential analytics cookies that recognize you across sessions), which you may withdraw at any time.

Where the FADP applies, we process personal data in accordance with the principles of lawfulness, good faith, proportionality, and purpose limitation.

## 6. Diagnostic Data and Anonymization

To keep Our Services reliable, we operate error- and crash-reporting mechanisms. In these exceptional cases, technical data associated with a failing request — which may include the structure of a submitted regular expression or automaton — can be captured for debugging.

Before such data is stored, it is **anonymized**: the characters that compose the pattern are stripped and replaced with substitute characters, so that the stored artifact preserves only the structural shape needed for debugging and cannot be used to reconstruct the original content or identify a person. We do not attempt to re-identify anonymized diagnostic data.

## 7. How We Use Your Information

 - **To provide and maintain Our Services** — to operate your account and deliver the API functionality.
 - **To secure Our Services** — to enforce rate limits and quotas, and to detect, prevent, and address fraud, abuse, or security and technical issues.
 - **To improve Our Services** — to analyze aggregate usage, analytics, and diagnostic data, and to understand how features are used.
 - **To communicate with you** — to respond to your inquiries and send service-related notifications.

## 8. How We Share Your Information and Sub-processors

We do not sell your personal data. We share data only as necessary to operate Our Services, with the following categories of recipients:

 - **Infrastructure and hosting providers:**
     - **OVH** — server hosting (France, EU).
     - **netcup** — server hosting (Germany, EU).
 - **Authentication Provider:** **Google Firebase** — user identity and authentication.
 - **Payment processor:** *(none currently — a third-party payment processor may be engaged when paid plans are introduced, at which point this Policy will be updated).*
 - **Analytics provider:** **PostHog** — product and usage analytics, processed on European Union infrastructure (EU region).
 - **Compliance and harm prevention:** We may disclose information if we believe it is necessary to comply with applicable laws, regulations, legal processes, or governmental requests; to protect the rights, property, and safety of us, our users, or others; or to detect, prevent, or address fraud, security, or technical issues.

## 9. International Data Transfers

Our servers are located in the European Union (France and Germany). Some sub-processors, such as Google Firebase, may process data on infrastructure located outside Switzerland and the EEA, including in the United States.

Where personal data is transferred outside Switzerland or the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the Swiss addendum where applicable) or an applicable adequacy decision, to ensure your data receives an equivalent level of protection.

## 10. Cookies and Similar Technologies

We use **strictly necessary cookies** required to operate Our Services and keep you signed in (for example, authentication cookies set by our Authentication Provider, and a cookie that stores your cookie-consent choice and display preferences). These do not require consent.

We also use **analytics cookies** through our Analytics Provider, PostHog. By default, analytics runs in a **cookieless, anonymous** mode that stores no identifier on your device and does not create a persistent profile — this relies on our legitimate interest in understanding and improving Our Services. We ask for your consent through a **cookie banner** before setting any non-essential analytics cookies; only if you **accept** do we store persistent analytics cookies that recognize you across sessions and subdomains. You can change or withdraw your choice at any time via the cookie banner, and declining leaves you on the cookieless, anonymous mode. We do not use analytics cookies for advertising, and session/screen recording is disabled.

## 11. Data Security

We implement reasonable technical and organizational measures designed to protect your information from unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

## 12. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law:

 - **User Information** is retained for the life of your account and deleted or anonymized after account closure, subject to any legal retention obligations.
 - **Usage Metadata** is retained as needed for billing, security, and abuse prevention.
 - **Analytics Data** is retained by our Analytics Provider for a limited period sufficient to analyze trends and improve Our Services, after which it is deleted or aggregated.
 - **Anonymized diagnostic data** contains no identifiable information and may be retained for debugging purposes.

Once the applicable retention period expires, we will securely erase or anonymize the personal data, unless there is a legal requirement to keep it longer.

## 13. Your Rights

Subject to applicable law (GDPR and/or FADP), you have the right to:

 - **Access** the personal data we hold about you;
 - **Rectify** inaccurate or incomplete data;
 - **Erase** your data ("right to be forgotten") in certain circumstances;
 - **Restrict** or **object** to certain processing;
 - **Data portability** — receive your data in a structured, commonly used, machine-readable format;
 - **Withdraw consent** at any time, where processing is based on consent, without affecting prior processing.

To exercise any of these rights, contact us at legal@regexsolver.com. We will respond within the timeframes required by applicable law.

You also have the right to lodge a complaint with a supervisory authority: in Switzerland, the **Federal Data Protection and Information Commissioner (FDPIC)**; in the EEA, your local **data protection authority**.

## 14. Children's Privacy

Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, please contact us at legal@regexsolver.com and we will take appropriate steps to delete it.

## 15. Changes to This Privacy Policy

We may update this Policy from time to time. We will notify you of any changes by posting the updated Policy on this page and updating the "Last Updated" date at the top. Material changes will be communicated more prominently where appropriate.

## 16. Contact

If you have any questions about this Privacy Policy, please contact us at legal@regexsolver.com.
