This Privacy Policy explains how Bytech LLP (BIN 230740022607), registered at 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan, Republic of Kazakhstan ("we", "us", "our"), collects, uses, shares and retains personal data in connection with Deplion (the "Service").
Privacy contact: [email protected]
1. Scope of this policy
1.1. This policy covers the Deplion marketing website, the user dashboard, the MCP server and the publishing infrastructure we operate.
1.2. This policy does not cover the websites our users publish. Each published site is created and controlled by the user who owns it. If you visited such a site and want to know how it handles your data, contact the operator of that site. Our role in relation to data collected there is described in Section 4.
1.3. In this policy, "you" means: a registered user of the Service; a visitor to our marketing website; or an individual whose personal data reaches us because they submitted a form on a site published through the Service.
2. Data we collect
2.1. Account data
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Identity | Name, email address, email verification timestamp | You | Creating and operating your account, transactional email | Contract |
| Authentication | Password hash, two-factor secrets and recovery codes, registered passkeys | You | Securing access to your account | Contract, legitimate interest in account security |
| Session records | Session identifier, IP address, user-agent string, last activity time | Automatic | Keeping you signed in, detecting suspicious sessions | Legitimate interest in security |
| API credentials | MCP access token hashes, OAuth clients, authorisation codes and refresh tokens | You / automatic | Authorising AI assistants and third-party MCP clients | Contract |
| Consent records | Document slug and version accepted, context, timestamp, IP address, hashed user-agent, keyed hash of your email address | Automatic when you accept a document | Proving that terms were accepted | Legitimate interest in evidencing agreement and establishing or defending legal claims |
| Cookie consent records | Categories accepted, consent revision, timestamp, IP address, hashed user-agent, keyed hash of the random consent identifier stored in your browser | Automatic when you make a choice in the cookie banner | Demonstrating that consent was given, as Article 7(1) GDPR requires | Legal obligation |
2.2. Content and project data
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Project files | HTML, CSS, JavaScript, images and other assets you upload or publish | You / your AI assistant | Storing, versioning and serving your sites | Contract |
| Version snapshots | Immutable snapshots and deduplicated content blobs | Automatic | Publishing and rollback | Contract |
| Domains | Project subdomain, connected custom hostnames | You | Serving your site at the correct address | Contract |
Project files may contain personal data if you choose to place it there. You decide what goes into your files; we process it on your instruction.
2.3. Activity and product analytics
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| AI activity log | Which MCP tool was called, status, duration, request identifier, hashed session identifier, a non-sensitive summary of the call, timestamp | Automatic | Showing you what your AI did, abuse investigation, debugging | Contract, legitimate interest in security |
| Funnel events | Project created, project published, with project and user reference and timestamp | Automatic | Measuring product usage | Legitimate interest in improving the Service |
| Server logs | Technical error and diagnostic records | Automatic | Operating and troubleshooting the Service | Legitimate interest |
The AI activity log is append-only and enforced as such at the database level. It is designed to exclude secrets and personal data: file contents, credentials and form payloads are not written to it.
2.4. Form submissions from published sites ("leads")
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Submission payload | Whatever fields the site owner defined in their form — typically name, email, phone, message | The visitor who submitted the form | Delivering the submission to the site owner | See Section 4 |
| Delivery metadata | Ingestion request identifier, hashed client fingerprint, country and continent code, network operator (ASN), edge request identifier, receipt time | Automatic, from our content delivery provider | Anti-spam, rate limiting, abuse investigation | Legitimate interest in preventing abuse |
2.5. Moderation data
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Moderation verdicts | Automated risk scores and categories, model output, review case and incident records | Automatic | Detecting prohibited content | Legitimate interest in safety, legal obligation |
| Page renders | Full-page screenshots of published pages, stored with a short expiry | Automatic | Automated and human review of published content | Legitimate interest in safety |
| Enforcement history | Account state, strikes, restrictions, suspensions, bans, operator actions and reasons | Automatic / our operators | Enforcing the Acceptable Use Policy, preventing repeat abuse | Legitimate interest, legal obligation |
2.6. Billing data
| Data | Examples | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Subscription records | Plan, subscription status, billing period, price identifiers, transaction records, webhook events | Our payment provider | Providing paid plans, invoicing, accounting | Contract, legal obligation |
| Payment details | Card and payment information | You, directly to our payment provider | Taking payment | Contract |
We never see or store your full card details. Payments are processed by Polar Software, Inc., which acts as Merchant of Record and is an independent controller of the payment data you give it. Polar is based in the United States and may process payment data there; for personal data transferred out of the EEA or the United Kingdom it relies on the Standard Contractual Clauses adopted by the European Commission.
2.7. Website analytics
Only if you consent may Google Tag Manager and the tags it loads set cookies or collect device identifiers on our marketing website and dashboard. With your consent it collects device identifiers, IP address, pages viewed and referral information. Legal basis: consent.
Before you consent, and if you refuse, the container is still loaded but is instructed that every storage purpose is denied. In that state it sends Google an anonymous, cookieless signal carrying your IP address, the page address, the referrer and your user agent, with no cookie and no identifier that could link this visit to any other. Legal basis: our legitimate interest in measuring how many people reach the Service, balanced against an impact limited to data every third-party request necessarily discloses. You can prevent it entirely by blocking googletagmanager.com in your browser.
Section 3 of our Cookie Policy describes this in full; see also Section 7 below.
3. How we use personal data
We use personal data to:
- create, operate and secure your account;
- store, version and publish your websites;
- deliver form submissions from your published sites to you;
- moderate published content and enforce the Acceptable Use Policy;
- detect, investigate and prevent abuse, fraud and security incidents;
- process payments, issue invoices and meet accounting obligations;
- send transactional messages such as verification, security and billing notices;
- measure how the product is used so we can improve it;
- respond to your requests and to legal claims; and
- comply with applicable law.
We do not sell personal data. We do not use your project content or form submissions to train our own machine-learning models.
4. Roles for form submissions — read this if you publish forms
4.1. When a visitor submits a form on a website published through the Service, the site owner is the data controller for that submission, and we act as a data processor on the site owner's behalf.
4.2. This means the site owner — not us — decides which fields are collected, why, and for how long. If you publish a form, you are responsible for:
- having a lawful basis to collect that data;
- publishing your own privacy notice on your site;
- telling visitors that submissions are processed through Deplion;
- responding to access, correction and deletion requests from your visitors; and
- notifying your visitors of a breach if one occurs on your side.
4.3. We process submissions only to deliver them to the site owner, to prevent abuse of the ingestion endpoint, and as otherwise instructed by the site owner. We use our sub-processors for this, listed in the Sub-processors page.
4.4. If you submitted a form on a site published through Deplion and cannot reach that site's owner, write to [email protected] and we will make reasonable efforts to route your request to them.
4.5. The delivery metadata described in Section 2.4 is processed by us as controller, for our own anti-abuse purposes.
5. Content moderation and automated decisions
5.1. When a project is published, its content is checked automatically. This involves rule-based heuristics, automated rendering of the page into a screenshot, and analysis of the page content and screenshot by a third-party AI model.
5.2. These checks can result in automated decisions, including refusing to publish a snapshot and removing an already-published site from public availability. Repeated or severe findings can lead to automated restriction of an account.
5.3. Where such a decision produces legal effects or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to [email protected] and a human operator will review the case.
5.4. Content sent for automated analysis is treated strictly as data, never as instructions. Screenshots created for moderation are stored with a short expiry and are not publicly accessible.
6. Sharing personal data
6.1. We share personal data with the sub-processors listed in the Sub-processors page, under contracts that restrict them to processing on our instructions.
6.2. We may also disclose personal data:
- to competent authorities where required by law, court order or valid legal process;
- to protect our rights, safety, property, or those of our users or the public, including reporting unlawful content;
- to professional advisers under a duty of confidentiality; and
- to a successor entity in connection with a merger, acquisition or sale of assets, subject to this policy.
6.3. We do not share personal data with advertisers or data brokers.
7. Cookies and analytics
7.1. We use the following categories of cookies and similar technologies:
| Category | Examples | Purpose |
|---|---|---|
| Strictly necessary | Session cookie, CSRF token cookie, "remember me" cookie, the cookie storing your consent choice | Keeping you signed in, protecting form submissions and remembering your cookie choice. The Service cannot function without these. |
| Analytics | Google Tag Manager and the tags it loads | Understanding how visitors use our marketing website and dashboard |
7.2. Analytics storage is off until you turn it on. No analytics cookie is set and no identifier on your device is read until you accept the Analytics category in our cookie banner. The Google Tag Manager container is itself loaded on every page, in a state where all storage is denied, and in that state sends only the cookieless signal described in Section 2.7 — we say so rather than describing it as absent. Strictly necessary cookies are set without consent, as the ePrivacy rules permit, because the Service cannot work without them.
7.3. You can change or withdraw your choice at any time from Cookie settings in the footer of any public page, in the Legal section of the dashboard sidebar, or in Settings → Privacy. Withdrawal takes effect immediately and does not affect processing carried out beforehand. Full details are in our Cookie Policy.
7.4. We keep a record of each cookie consent choice — see the cookie consent row in Section 2.1 — because Article 7(1) of the GDPR requires us to be able to demonstrate that consent was given.
7.5. We do not control cookies set by websites published by our users. Those are the responsibility of the site owner.
8. International transfers
8.1. We are established in the Republic of Kazakhstan and our sub-processors operate globally. Personal data is therefore transferred outside the European Economic Area, the United Kingdom and your country of residence.
8.2. Where we transfer personal data from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the supplementary technical measures described in Section 10.
8.3. You may request further information about these transfer mechanisms at [email protected].
9. Retention
9.1. Retention periods:
| Data | Retained |
|---|---|
| Account, authentication and API credential data | For as long as your account exists; deleted when you delete your account |
| Project files, snapshots and blobs | For as long as the project exists; deleted with the project or with the account |
| Form submissions | For as long as the project exists, subject to plan limits on what is visible to you; deleted with the project or with the account |
| Consent records | Retained after account deletion, with the link to your account removed. What remains is the document and version accepted, the timestamp, the IP address used, and one-way keyed hashes of your email address and user agent — kept to establish or defend legal claims about what was agreed (Article 17(3)(e) GDPR) |
| Cookie consent records | Retained on the same basis, with the link to your account removed on deletion. Most such records never belong to an account at all, since consent is usually given before signing up. Kept to demonstrate compliance with Article 7(1) GDPR |
| Funnel events | For as long as your account exists; deleted with the account |
| AI activity log | Retained after account deletion in anonymised form: the link to your user account is removed, and the remaining record contains no personal data |
| Moderation verdicts, review cases and enforcement history | Retained after account deletion where necessary to prevent repeat abuse and to defend legal claims |
| Page render screenshots | Short-lived; expire automatically |
| Billing and transaction records | Retained for the period required by applicable tax and accounting law |
| Backups | Until the backup cycle in which they were captured expires |
9.2. Free-plan projects that stay inactive for the period set by the applicable limit profile (currently 45 days) are archived automatically. Archived projects become read-only and can be restored by you.
9.3. Honest note on enforcement of these periods. Deletion of account-linked data is enforced by database-level cascade when you delete your account, and screenshot expiry is enforced automatically. We do not currently run scheduled pruning of activity or analytics records for accounts that remain open — those records are retained for the life of the account as stated above. If you want specific records removed sooner, contact [email protected].
10. Security
10.1. We apply measures including: encryption of data in transit; password hashing; optional two-factor authentication and passkeys; scoped and revocable API tokens; strict isolation between the free and paid serving zones; rate limiting on the MCP, publishing and form-ingestion paths; signed internal requests between our edge and application layers; an append-only activity log enforced at the database level; and a policy of never writing secrets or personal data into application logs.
10.2. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your own credentials safe.
10.3. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, without undue delay.
11. Your rights
11.1. Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests;
- portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal; and
- not be subject to a solely automated decision with legal or similarly significant effects — see Section 5.3.
11.2. You can exercise several of these rights directly in the Service, without contacting us:
- access and portability — Settings → Privacy → "Download my data" produces a JSON file containing your profile, projects and file metadata, published versions, form submissions received by your sites, your AI activity log, your consent records, your billing history and any restrictions applied to your account. For security, we ask you to confirm your password first, and the download is limited to a few requests per hour. The file excludes security material (password hash, tokens, audit fingerprints) and internal moderation records; it also excludes the contents of your files, which you can read in your projects at any time;
- rectification — update your profile in Settings → Profile;
- erasure — delete individual projects, or delete your account permanently from Settings → Profile. Deleting the account takes your published sites offline first, then removes the account;
- withdraw cookie consent — Settings → Privacy → "Cookie settings", or the same link in the footer of any public page.
11.3. For anything else, write to [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting, and we may extend the deadline where the law permits, telling you why.
11.4. If your request concerns data submitted through a form on a user's published site, see Section 4 — the site owner is the controller and we will route your request to them.
11.5. If you are in the EEA or the UK, you have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to address your concern first.
12. Children
The Service is not directed at children. You must be at least 18 years old to hold an account, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
13. Changes to this policy
13.1. We may update this policy. The current version is always published at https://deplion.cc/legal/privacy-policy with its version identifier and effective date.
13.2. For material changes we will give notice by email or through the dashboard before they take effect.
14. Contact
Bytech LLP (Товарищество с ограниченной ответственностью «Bytech») BIN 230740022607 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan
- Privacy and data protection: [email protected]
- Abuse and content complaints: [email protected]
- General support: [email protected]
Version 2026-07-31 — effective 2026-07-31.