Privacy policy
What data we collect, why, who sees it and how you stay in control.
Last updated: 7 October 2026. Draft — pending review by the site operator.
This privacy policy explains how Spicanet ("we", "us") handles personal data on the website spicanet.net and, as a baseline, in the software, apps and online services published under the Spicanet name ("Products"). Spicanet is operated by Egor Danilov, an independent product developer based in Thailand, who is the controller of the data described here.
1. Summary
- We collect the minimum needed to run the website and each Product.
- We do not sell personal data and we do not run advertising trackers on spicanet.net.
- Payments are handled by payment providers and app stores; we never see your full card number.
- You can access, correct, export and delete your data. See Account and data deletion.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Contact form | Name, email address, message, the product you ask about | To reply to you. |
| Abuse protection | A hashed form of your IP address | To limit spam on the contact form. |
| Server logs | Time, URL path, status code, user agent, IP address | Security, reliability and debugging. |
| Account data (Products) | Email address, display name, password hash or sign-in provider identifier, settings | To provide your account. |
| Content you create (Products) | Data you enter or upload | To provide the Product. |
| Purchase data | Order number, plan, amount, currency, country, tax status, subscription state, email | To provide access, support you and keep records. We do not receive your full payment card details. |
| Device and usage data (apps and web apps) | App version, device type, OS version, crash reports, basic usage events | To keep the Product working and improve it. |
| Analytics | Aggregate page views and events, if analytics are enabled | To understand what is useful. Disabled unless explicitly configured. |
| AI requests (Products with AI) | The prompt and the data you choose to send to an AI feature | To produce the response you asked for. |
We do not intentionally collect sensitive categories of personal data. Please do not submit them through contact forms.
3. Where data comes from
Mostly from you. Some comes from your device (logs, crash data) and from payment providers and app stores (purchase and subscription status).
4. How we use data, and our legal bases
| Purpose | Legal basis (GDPR/UK GDPR) |
|---|---|
| Provide the website and Products, and deliver what you purchased | Performance of a contract |
| Reply to messages and give support | Legitimate interests / contract |
| Process payments, issue invoices, comply with tax and accounting law | Contract; legal obligation |
| Security, fraud and abuse prevention | Legitimate interests |
| Improve Products with aggregate usage and crash data | Legitimate interests, or consent where the law requires it |
| Send product emails you asked for | Consent, which you can withdraw at any time |
We do not use personal data for automated decisions that have legal or similarly significant effects.
5. Payments, merchants of record and app stores
- Creem, Paddle and Lemon Squeezy act as merchant of record for purchases made through them. They are independent controllers of the payment data they collect and handle payment, fraud checks, tax and invoicing under their own privacy policies. They share with us the data needed to deliver your purchase, such as your email address, country, plan and subscription status.
- PayPal processes PayPal payments under its own privacy statement.
- Apple and Google process in-app purchases and subscriptions under their own policies and tell us whether a subscription is active.
6. Who we share data with
We share personal data only with:
- Service providers (processors) that help us operate the Products: hosting and storage, email delivery, error monitoring and, if enabled, privacy-friendly analytics. They may process data only on our instructions.
- Payment providers and app stores, as described above.
- AI model providers, only when you use an AI feature that needs them, and only the data required for the request.
- Authorities and advisers when the law requires it or to protect rights and safety.
- A successor, if the Products are transferred, subject to this policy.
We do not sell personal data, and we do not "share" it for cross-context behavioural advertising.
7. Cookies and similar technologies
spicanet.net uses only what it needs to work. It sets no advertising cookies. If analytics are enabled they are configured to avoid cross-site tracking. Products may use essential cookies or local storage for sign-in and preferences, and tell you about any others. We honour browser "Global Privacy Control" and "Do Not Track" signals by not enabling optional tracking.
8. International transfers
We and our providers may process data in countries other than your own, including countries that may not offer the same level of protection. Where required, we rely on safeguards such as the European Commission's standard contractual clauses or an adequacy decision.
9. How long we keep data
| Data | Retention |
|---|---|
| Contact-form messages | Up to 24 months after the conversation ends, then deleted |
| Server logs | Up to 90 days |
| Account and content data | While your account exists; deleted within 30 days after you delete the account |
| Backups | Overwritten on a rolling schedule, normally within 35 days |
| Purchase and tax records | As long as tax and accounting law require (often 5–10 years) |
10. Security
We use encryption in transit, access controls and least-privilege administration, and we keep software up to date. No system is perfectly secure; tell us at once if you notice a problem. If a breach affects you, we will notify you and the relevant authority as the law requires.
11. Your rights
Depending on where you live (for example the EU/EEA, the UK, California, Thailand and other places with data protection laws), you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data;
- restrict or object to certain processing;
- portability — receive your data in a common format;
- withdraw consent at any time, without affecting earlier processing;
- opt out of the sale or sharing of personal data (we do not sell or share it); and
- not be discriminated against for exercising your rights.
To use a right, email [email protected]. We may need to verify your identity, and we will respond within the time required by law (generally within one month). You can also complain to your local data protection authority.
12. Deleting your account and data
You can ask us to delete your account and associated data at any time, in the app where available or through our Account and data deletion page. Some records, such as purchase and tax records, must be kept for the legal minimum period.
13. Children
The website and Products are not directed to children and we do not knowingly collect personal data from anyone under 13 (or under 16 where that is the age of digital consent). If you believe a child has given us personal data, contact us and we will delete it.
14. Apps: App Store and Google Play disclosures
For mobile apps, the privacy information we give to Apple (App Privacy details) and to Google Play (Data safety section) is meant to match this policy and the in-app behaviour. Each app states which data types it collects, whether they are linked to you and whether they are used for tracking. We do not use data for cross-app tracking, and we do not share it with data brokers.
15. Changes to this policy
We may update this policy. We will change the "last updated" date and, for material changes, tell you in the Product or by email before they take effect.
16. Contact
Spicanet (operated by Egor Danilov), Thailand\ Email: [email protected] · Contact page

