This Privacy Policy explains how Bytech LLP (BIN 230740022607), registered at 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan, Republic of Kazakhstan ("we", "us", "our"), collects, uses, shares and retains personal data in connection with Deplion (the "Service").

Privacy contact: [email protected]

1. Scope of this policy

1.1. This policy covers the Deplion marketing website, the user dashboard, the MCP server and the publishing infrastructure we operate.

1.2. This policy does not cover the websites our users publish. Each published site is created and controlled by the user who owns it. If you visited such a site and want to know how it handles your data, contact the operator of that site. Our role in relation to data collected there is described in Section 4.

1.3. In this policy, "you" means: a registered user of the Service; a visitor to our marketing website; or an individual whose personal data reaches us because they submitted a form on a site published through the Service.

2. Data we collect

2.1. Account data

Data Examples Source Purpose Legal basis
Identity Name, email address, email verification timestamp You Creating and operating your account, transactional email Contract
Authentication Password hash, two-factor secrets and recovery codes, registered passkeys You Securing access to your account Contract, legitimate interest in account security
Session records Session identifier, IP address, user-agent string, last activity time Automatic Keeping you signed in, detecting suspicious sessions Legitimate interest in security
API credentials MCP access token hashes, OAuth clients, authorisation codes and refresh tokens You / automatic Authorising AI assistants and third-party MCP clients Contract
Consent records Document slug and version accepted, context, timestamp, IP address, hashed user-agent, keyed hash of your email address Automatic when you accept a document Proving that terms were accepted Legitimate interest in evidencing agreement and establishing or defending legal claims
Cookie consent records Categories accepted, consent revision, timestamp, IP address, hashed user-agent, keyed hash of the random consent identifier stored in your browser Automatic when you make a choice in the cookie banner Demonstrating that consent was given, as Article 7(1) GDPR requires Legal obligation

2.2. Content and project data

Data Examples Source Purpose Legal basis
Project files HTML, CSS, JavaScript, images and other assets you upload or publish You / your AI assistant Storing, versioning and serving your sites Contract
Version snapshots Immutable snapshots and deduplicated content blobs Automatic Publishing and rollback Contract
Domains Project subdomain, connected custom hostnames You Serving your site at the correct address Contract

Project files may contain personal data if you choose to place it there. You decide what goes into your files; we process it on your instruction.

2.3. Activity and product analytics

Data Examples Source Purpose Legal basis
AI activity log Which MCP tool was called, status, duration, request identifier, hashed session identifier, a non-sensitive summary of the call, timestamp Automatic Showing you what your AI did, abuse investigation, debugging Contract, legitimate interest in security
Funnel events Project created, project published, with project and user reference and timestamp Automatic Measuring product usage Legitimate interest in improving the Service
Server logs Technical error and diagnostic records Automatic Operating and troubleshooting the Service Legitimate interest

The AI activity log is append-only and enforced as such at the database level. It is designed to exclude secrets and personal data: file contents, credentials and form payloads are not written to it.

2.4. Form submissions from published sites ("leads")

Data Examples Source Purpose Legal basis
Submission payload Whatever fields the site owner defined in their form — typically name, email, phone, message The visitor who submitted the form Delivering the submission to the site owner See Section 4
Delivery metadata Ingestion request identifier, hashed client fingerprint, country and continent code, network operator (ASN), edge request identifier, receipt time Automatic, from our content delivery provider Anti-spam, rate limiting, abuse investigation Legitimate interest in preventing abuse

2.5. Moderation data

Data Examples Source Purpose Legal basis
Moderation verdicts Automated risk scores and categories, model output, review case and incident records Automatic Detecting prohibited content Legitimate interest in safety, legal obligation
Page renders Full-page screenshots of published pages, stored with a short expiry Automatic Automated and human review of published content Legitimate interest in safety
Enforcement history Account state, strikes, restrictions, suspensions, bans, operator actions and reasons Automatic / our operators Enforcing the Acceptable Use Policy, preventing repeat abuse Legitimate interest, legal obligation

2.6. Billing data

Data Examples Source Purpose Legal basis
Subscription records Plan, subscription status, billing period, price identifiers, transaction records, webhook events Our payment provider Providing paid plans, invoicing, accounting Contract, legal obligation
Payment details Card and payment information You, directly to our payment provider Taking payment Contract

We never see or store your full card details. Payments are processed by Polar Software, Inc., which acts as Merchant of Record and is an independent controller of the payment data you give it. Polar is based in the United States and may process payment data there; for personal data transferred out of the EEA or the United Kingdom it relies on the Standard Contractual Clauses adopted by the European Commission.

2.7. Website analytics

Only if you consent may Google Tag Manager and the tags it loads set cookies or collect device identifiers on our marketing website and dashboard. With your consent it collects device identifiers, IP address, pages viewed and referral information. Legal basis: consent.

Before you consent, and if you refuse, the container is still loaded but is instructed that every storage purpose is denied. In that state it sends Google an anonymous, cookieless signal carrying your IP address, the page address, the referrer and your user agent, with no cookie and no identifier that could link this visit to any other. Legal basis: our legitimate interest in measuring how many people reach the Service, balanced against an impact limited to data every third-party request necessarily discloses. You can prevent it entirely by blocking googletagmanager.com in your browser.

Section 3 of our Cookie Policy describes this in full; see also Section 7 below.

3. How we use personal data

We use personal data to:

We do not sell personal data. We do not use your project content or form submissions to train our own machine-learning models.

4. Roles for form submissions — read this if you publish forms

4.1. When a visitor submits a form on a website published through the Service, the site owner is the data controller for that submission, and we act as a data processor on the site owner's behalf.

4.2. This means the site owner — not us — decides which fields are collected, why, and for how long. If you publish a form, you are responsible for:

4.3. We process submissions only to deliver them to the site owner, to prevent abuse of the ingestion endpoint, and as otherwise instructed by the site owner. We use our sub-processors for this, listed in the Sub-processors page.

4.4. If you submitted a form on a site published through Deplion and cannot reach that site's owner, write to [email protected] and we will make reasonable efforts to route your request to them.

4.5. The delivery metadata described in Section 2.4 is processed by us as controller, for our own anti-abuse purposes.

5. Content moderation and automated decisions

5.1. When a project is published, its content is checked automatically. This involves rule-based heuristics, automated rendering of the page into a screenshot, and analysis of the page content and screenshot by a third-party AI model.

5.2. These checks can result in automated decisions, including refusing to publish a snapshot and removing an already-published site from public availability. Repeated or severe findings can lead to automated restriction of an account.

5.3. Where such a decision produces legal effects or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to [email protected] and a human operator will review the case.

5.4. Content sent for automated analysis is treated strictly as data, never as instructions. Screenshots created for moderation are stored with a short expiry and are not publicly accessible.

6. Sharing personal data

6.1. We share personal data with the sub-processors listed in the Sub-processors page, under contracts that restrict them to processing on our instructions.

6.2. We may also disclose personal data:

6.3. We do not share personal data with advertisers or data brokers.

7. Cookies and analytics

7.1. We use the following categories of cookies and similar technologies:

Category Examples Purpose
Strictly necessary Session cookie, CSRF token cookie, "remember me" cookie, the cookie storing your consent choice Keeping you signed in, protecting form submissions and remembering your cookie choice. The Service cannot function without these.
Analytics Google Tag Manager and the tags it loads Understanding how visitors use our marketing website and dashboard

7.2. Analytics storage is off until you turn it on. No analytics cookie is set and no identifier on your device is read until you accept the Analytics category in our cookie banner. The Google Tag Manager container is itself loaded on every page, in a state where all storage is denied, and in that state sends only the cookieless signal described in Section 2.7 — we say so rather than describing it as absent. Strictly necessary cookies are set without consent, as the ePrivacy rules permit, because the Service cannot work without them.

7.3. You can change or withdraw your choice at any time from Cookie settings in the footer of any public page, in the Legal section of the dashboard sidebar, or in Settings → Privacy. Withdrawal takes effect immediately and does not affect processing carried out beforehand. Full details are in our Cookie Policy.

7.4. We keep a record of each cookie consent choice — see the cookie consent row in Section 2.1 — because Article 7(1) of the GDPR requires us to be able to demonstrate that consent was given.

7.5. We do not control cookies set by websites published by our users. Those are the responsibility of the site owner.

8. International transfers

8.1. We are established in the Republic of Kazakhstan and our sub-processors operate globally. Personal data is therefore transferred outside the European Economic Area, the United Kingdom and your country of residence.

8.2. Where we transfer personal data from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the supplementary technical measures described in Section 10.

8.3. You may request further information about these transfer mechanisms at [email protected].

9. Retention

9.1. Retention periods:

Data Retained
Account, authentication and API credential data For as long as your account exists; deleted when you delete your account
Project files, snapshots and blobs For as long as the project exists; deleted with the project or with the account
Form submissions For as long as the project exists, subject to plan limits on what is visible to you; deleted with the project or with the account
Consent records Retained after account deletion, with the link to your account removed. What remains is the document and version accepted, the timestamp, the IP address used, and one-way keyed hashes of your email address and user agent — kept to establish or defend legal claims about what was agreed (Article 17(3)(e) GDPR)
Cookie consent records Retained on the same basis, with the link to your account removed on deletion. Most such records never belong to an account at all, since consent is usually given before signing up. Kept to demonstrate compliance with Article 7(1) GDPR
Funnel events For as long as your account exists; deleted with the account
AI activity log Retained after account deletion in anonymised form: the link to your user account is removed, and the remaining record contains no personal data
Moderation verdicts, review cases and enforcement history Retained after account deletion where necessary to prevent repeat abuse and to defend legal claims
Page render screenshots Short-lived; expire automatically
Billing and transaction records Retained for the period required by applicable tax and accounting law
Backups Until the backup cycle in which they were captured expires

9.2. Free-plan projects that stay inactive for the period set by the applicable limit profile (currently 45 days) are archived automatically. Archived projects become read-only and can be restored by you.

9.3. Honest note on enforcement of these periods. Deletion of account-linked data is enforced by database-level cascade when you delete your account, and screenshot expiry is enforced automatically. We do not currently run scheduled pruning of activity or analytics records for accounts that remain open — those records are retained for the life of the account as stated above. If you want specific records removed sooner, contact [email protected].

10. Security

10.1. We apply measures including: encryption of data in transit; password hashing; optional two-factor authentication and passkeys; scoped and revocable API tokens; strict isolation between the free and paid serving zones; rate limiting on the MCP, publishing and form-ingestion paths; signed internal requests between our edge and application layers; an append-only activity log enforced at the database level; and a policy of never writing secrets or personal data into application logs.

10.2. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your own credentials safe.

10.3. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, without undue delay.

11. Your rights

11.1. Depending on where you live, you may have the right to:

11.2. You can exercise several of these rights directly in the Service, without contacting us:

11.3. For anything else, write to [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting, and we may extend the deadline where the law permits, telling you why.

11.4. If your request concerns data submitted through a form on a user's published site, see Section 4 — the site owner is the controller and we will route your request to them.

11.5. If you are in the EEA or the UK, you have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to address your concern first.

12. Children

The Service is not directed at children. You must be at least 18 years old to hold an account, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

13. Changes to this policy

13.1. We may update this policy. The current version is always published at https://deplion.cc/legal/privacy-policy with its version identifier and effective date.

13.2. For material changes we will give notice by email or through the dashboard before they take effect.

14. Contact

Bytech LLP (Товарищество с ограниченной ответственностью «Bytech») BIN 230740022607 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan

Version 2026-07-31 — effective 2026-07-31.