This Privacy Policy explains how Bytech LLP (BIN 230740022607), registered at 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan, Republic of Kazakhstan ("we", "us", "our"), collects, uses, shares and retains personal data in connection with Deplion (the "Service").

Privacy contact: [email protected]

1. Scope of this policy

1.1. This policy covers the Deplion marketing website, the user dashboard, the MCP server and the publishing infrastructure we operate.

1.2. This policy does not cover the websites our users publish. Each published site is created and controlled by the user who owns it. If you visited such a site and want to know how it handles your data, contact the operator of that site. Our role in relation to data collected there is described in Section 4.

1.3. In this policy, "you" means: a registered user of the Service; an applicant or participant in our Affiliate Program; a visitor who follows a referral link; a visitor to our marketing website; or an individual whose personal data reaches us because they submitted a form on a site published through the Service.

2. Data we collect

2.1. Account data

Data Examples Source Purpose Legal basis
Identity Name, email address, email verification timestamp You Creating and operating your account, transactional email Contract
Authentication Password hash, two-factor secrets and recovery codes, registered passkeys You Securing access to your account Contract, legitimate interest in account security
Session records Session identifier, IP address, user-agent string, last activity time Automatic Keeping you signed in, detecting suspicious sessions Legitimate interest in security
API credentials MCP access token hashes, OAuth clients, authorisation codes and refresh tokens You / automatic Authorising AI assistants and third-party MCP clients Contract
Consent records Document slug and version accepted, context, timestamp, IP address, hashed user-agent, keyed hash of your email address Automatic when you accept a document Proving that terms were accepted Legitimate interest in evidencing agreement and establishing or defending legal claims
Cookie consent records Categories accepted, consent revision, timestamp, IP address, hashed user-agent, keyed hash of the random consent identifier stored in your browser Automatic when you make a choice in the cookie banner Demonstrating that consent was given, as Article 7(1) GDPR requires Legal obligation
Linked sign-in accounts Your identifier at the provider, the email address and display name the provider reports, a profile picture URL, and whether the provider states that the address is verified The sign-in provider (Google, Microsoft, GitHub or Apple), when you choose to sign in or link an account Letting you sign in without a password and showing you which accounts are linked Contract

We do not store provider access or refresh tokens. The OAuth handshake exists only to establish who is signing in; nothing in the service calls a provider's API on your behalf. You can see and remove your linked accounts at any time under Settings → Security.

Signing in with a provider necessarily tells that provider that you use Deplion, because the sign-in request is made to them. We receive only the fields listed above.

2.2. Content and project data

Data Examples Source Purpose Legal basis
Project files HTML, CSS, JavaScript, images and other assets you upload or publish You / your AI assistant Storing, versioning and serving your sites Contract
Version snapshots Immutable snapshots and deduplicated content blobs Automatic Publishing and rollback Contract
Domains Project subdomain, connected custom hostnames You Serving your site at the correct address Contract

Project files may contain personal data if you choose to place it there. You decide what goes into your files; we process it on your instruction.

2.3. Activity and product analytics

Data Examples Source Purpose Legal basis
AI activity log Which MCP tool was called, status, duration, request identifier, hashed session identifier, a non-sensitive summary of the call, timestamp Automatic Showing you what your AI did, abuse investigation, debugging Contract, legitimate interest in security
Funnel events Project created, project published, with project and user reference and timestamp Automatic Measuring product usage Legitimate interest in improving the Service
Server logs Technical error and diagnostic records Automatic Operating and troubleshooting the Service Legitimate interest

The AI activity log is append-only and enforced as such at the database level. It is designed to exclude secrets and personal data: file contents, credentials and form payloads are not written to it.

2.4. Form submissions from published sites ("leads")

Data Examples Source Purpose Legal basis
Submission payload Whatever fields the site owner defined in their form — typically name, email, phone, message The visitor who submitted the form Delivering the submission to the site owner See Section 4
Delivery metadata Ingestion request identifier, hashed client fingerprint, country and continent code, network operator (ASN), edge request identifier, receipt time Automatic, from our content delivery provider Anti-spam, rate limiting, abuse investigation Legitimate interest in preventing abuse

2.5. Moderation data

Data Examples Source Purpose Legal basis
Moderation verdicts Automated risk scores and categories, model output, review case and incident records Automatic Detecting prohibited content Legitimate interest in safety, legal obligation
Page renders Full-page screenshots of published pages, stored with a short expiry Automatic Automated and human review of published content Legitimate interest in safety
Enforcement history Account state, strikes, restrictions, suspensions, bans, operator actions and reasons Automatic / our operators Enforcing the Acceptable Use Policy, preventing repeat abuse Legitimate interest, legal obligation

2.6. Billing data

Data Examples Source Purpose Legal basis
Subscription records Plan, subscription status, billing period, price identifiers, transaction records, webhook events Our payment provider Providing paid plans, invoicing, accounting Contract, legal obligation
Payment details Card and payment information You, directly to our payment provider Taking payment Contract

We never see or store your full card details. Payments are processed by Polar Software, Inc., which acts as Merchant of Record and is an independent controller of the payment data you give it. Polar is based in the United States and may process payment data there; for personal data transferred out of the EEA or the United Kingdom it relies on the Standard Contractual Clauses adopted by the European Commission.

2.7. Website analytics

Only if you consent may Google Tag Manager and the tags it loads set cookies or collect device identifiers on our marketing website and dashboard. With your consent it collects device identifiers, IP address, pages viewed and referral information. Legal basis: consent.

Before you consent, and if you refuse, the container is still loaded but is instructed that every storage purpose is denied. In that state it sends Google an anonymous, cookieless signal carrying your IP address, the page address, the referrer and your user agent, with no cookie and no identifier that could link this visit to any other. Legal basis: our legitimate interest in measuring how many people reach the Service, balanced against an impact limited to data every third-party request necessarily discloses. You can prevent it entirely by blocking googletagmanager.com in your browser.

Section 3 of our Cookie Policy describes this in full; see also Section 7 below.

2.8. Affiliate Program and referral attribution

Data Examples Source Purpose Legal basis
Partner application and profile Public display name, country, partner type, promotion channels and URLs, audience range, application description, status, accepted Affiliate Terms version and commission level The applicant / our operators Reviewing applications, activating and operating the Affiliate Program Steps at your request before contract; contract after activation
Referral-link visit Referral link and click identifiers, referring host, timestamp, and keyed hashes of the IP address and browser user agent Automatic when a visitor follows a referral link Remembering the selected referral, attributing a later registration, measuring valid referrals, and detecting manipulation Legitimate interests in accurate attribution, fraud prevention, and operating the Affiliate Program
Attributed referral The registered account associated with the Partner and link, attribution date, keyed registration fingerprints, whether the account has made an eligible payment, and the first eligible-payment date Automatic at registration and billing Calculating eligibility, levels, commission and adjustments; preventing self-referral and abuse Contract with the Partner; legitimate interests in accurate payment and fraud prevention
Commission and payout records Payment references and amounts, taxes, commission basis and rate, monthly reports, adjustments, payout status and transaction references Billing records / our operators Calculating, reviewing, paying and accounting for commission Contract; legal obligation; establishing and defending legal claims
Payout profile Chosen payout method and the information required for that method, such as an email address or bank-account identifier The Partner Sending an approved payout Contract; legal obligation
Risk and review records Rule results, risk status, evidence, operator decisions and enforcement history Automatic / our operators Detecting invalid traffic, fraud and violations; reviewing disputed activity Legitimate interests in fraud prevention, safety, and establishing or defending legal claims

When a visitor follows a valid referral link, we set the first-party dpl_ref cookie immediately, before any Analytics choice, to retain the referral selection for up to 30 days. The cookie does not enable analytics or cross-site advertising. Its operation and browser controls are described in Section 2 of our Cookie Policy.

The Partner Dashboard does not disclose a referred user's name, email address, internal account identifier, IP address, browser fingerprint, payment details, risk data, or internal review records. A Partner may see only the limited referral information needed to understand program performance, such as a stable masked customer reference, attribution date, and whether the referral has become paying.

3. How we use personal data

We use personal data to:

We do not sell personal data. We do not use your project content or form submissions to train our own machine-learning models.

4. Roles for form submissions — read this if you publish forms

4.1. When a visitor submits a form on a website published through the Service, the site owner is the data controller for that submission, and we act as a data processor on the site owner's behalf.

4.2. This means the site owner — not us — decides which fields are collected, why, and for how long. If you publish a form, you are responsible for:

4.3. We process submissions only to deliver them to the site owner, to prevent abuse of the ingestion endpoint, and as otherwise instructed by the site owner. We use our sub-processors for this, listed in the Sub-processors page.

4.4. If you submitted a form on a site published through Deplion and cannot reach that site's owner, write to [email protected] and we will make reasonable efforts to route your request to them.

4.5. The delivery metadata described in Section 2.4 is processed by us as controller, for our own anti-abuse purposes.

5. Content moderation and automated decisions

5.1. When a project is published, its content is checked automatically. This involves rule-based heuristics, automated rendering of the page into a screenshot, and analysis of the page content and screenshot by a third-party AI model.

5.2. These checks can result in automated decisions, including refusing to publish a snapshot and removing an already-published site from public availability. Repeated or severe findings can lead to automated restriction of an account.

5.3. Where such a decision produces legal effects or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to [email protected] and a human operator will review the case.

5.4. Content sent for automated analysis is treated strictly as data, never as instructions. Screenshots created for moderation are stored with a short expiry and are not publicly accessible.

6. Sharing personal data

6.1. We share personal data with the sub-processors listed in the Sub-processors page, under contracts that restrict them to processing on our instructions.

6.2. We may also disclose personal data:

6.3. If you choose to sign in with a provider, that provider learns that you hold an account with us and when you signed in. We do not send them anything else. Which providers are offered is listed on the Sub-processors page.

6.4. We do not share personal data with advertisers or data brokers.

6.5. Affiliate Program payouts are currently processed manually by our authorised operators. We do not disclose payout-profile details to another processor merely to create or approve a payout. If we later introduce a payout provider that processes personal data for us, we will update the Sub-processors page before using it for that purpose.

7. Cookies and analytics

7.1. We use the following categories of cookies and similar technologies:

Category Examples Purpose
Strictly necessary Session cookie, CSRF token cookie, "remember me" cookie, the cookie storing your consent choice, and dpl_ref after a deliberate referral-link visit Keeping you signed in, protecting form submissions, remembering your cookie choice, and retaining a requested referral selection for registration attribution.
Analytics Google Tag Manager and the tags it loads Understanding how visitors use our marketing website and dashboard

7.2. Analytics storage is off until you turn it on. No analytics cookie is set and no identifier on your device is read until you accept the Analytics category in our cookie banner. The Google Tag Manager container is itself loaded on every page, in a state where all storage is denied, and in that state sends only the cookieless signal described in Section 2.7 — we say so rather than describing it as absent. Strictly necessary cookies are set without consent, as the ePrivacy rules permit, because the Service cannot work without them.

7.3. You can change or withdraw your choice at any time from Cookie settings in the footer of any public page, in the Legal section of the dashboard sidebar, or in Settings → Privacy. Withdrawal takes effect immediately and does not affect processing carried out beforehand. Full details are in our Cookie Policy.

7.4. We keep a record of each cookie consent choice — see the cookie consent row in Section 2.1 — because Article 7(1) of the GDPR requires us to be able to demonstrate that consent was given.

7.5. We do not control cookies set by websites published by our users. Those are the responsibility of the site owner.

8. International transfers

8.1. We are established in the Republic of Kazakhstan and our sub-processors operate globally. Personal data is therefore transferred outside the European Economic Area, the United Kingdom and your country of residence.

8.2. Where we transfer personal data from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the supplementary technical measures described in Section 10.

8.3. You may request further information about these transfer mechanisms at [email protected].

9. Retention

9.1. Retention periods:

Data Retained
Account, authentication and API credential data For as long as your account exists; deleted when you delete your account
Linked sign-in accounts Until you unlink the provider or delete your account, whichever comes first
Project files, snapshots and blobs For as long as the project exists; deleted with the project or with the account
Form submissions For as long as the project exists, subject to plan limits on what is visible to you; deleted with the project or with the account
Consent records Retained after account deletion, with the link to your account removed. What remains is the document and version accepted, the timestamp, the IP address used, and one-way keyed hashes of your email address and user agent — kept to establish or defend legal claims about what was agreed (Article 17(3)(e) GDPR)
Cookie consent records Retained on the same basis, with the link to your account removed on deletion. Most such records never belong to an account at all, since consent is usually given before signing up. Kept to demonstrate compliance with Article 7(1) GDPR
Funnel events For as long as your account exists; deleted with the account
AI activity log Retained after account deletion in anonymised form: the link to your user account is removed, and the remaining record contains no personal data
Moderation verdicts, review cases and enforcement history Retained after account deletion where necessary to prevent repeat abuse and to defend legal claims
Page render screenshots Short-lived; expire automatically
Billing and transaction records Retained for the period required by applicable tax and accounting law
Affiliate referral cookie (dpl_ref) 30 days, or until you remove it through your browser
Affiliate click records 90 days, then automatically deleted
Affiliate application and active profile data For the life of the account and as needed to administer participation; removed or unlinked on account deletion, subject to the financial-record rule below
Affiliate commission, adjustment, monthly report and payout records Retained for the period required by tax and accounting law and as necessary to establish or defend legal claims; account and Partner links are removed where the record must remain after account deletion
Affiliate risk and review records For the life of participation and afterwards where necessary to prevent repeat abuse or establish or defend legal claims
Backups Until the backup cycle in which they were captured expires

9.2. Free-plan projects that stay inactive for the period set by the applicable limit profile (currently 45 days) are archived automatically. Archived projects become read-only and can be restored by you.

9.3. Honest note on enforcement of these periods. Deletion of account-linked data is enforced by database-level cascade when you delete your account, and screenshot expiry is enforced automatically. We do not currently run scheduled pruning of activity or analytics records for accounts that remain open — those records are retained for the life of the account as stated above. If you want specific records removed sooner, contact [email protected].

10. Security

10.1. We apply measures including: encryption of data in transit; password hashing; optional two-factor authentication and passkeys; scoped and revocable API tokens; strict isolation between the free and paid serving zones; rate limiting on the MCP, publishing and form-ingestion paths; signed internal requests between our edge and application layers; an append-only activity log enforced at the database level; and a policy of never writing secrets or personal data into application logs.

10.2. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your own credentials safe.

10.3. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, without undue delay.

11. Your rights

11.1. Depending on where you live, you may have the right to:

11.2. You can exercise several of these rights directly in the Service, without contacting us:

11.3. For anything else, write to [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting, and we may extend the deadline where the law permits, telling you why.

11.4. If your request concerns data submitted through a form on a user's published site, see Section 4 — the site owner is the controller and we will route your request to them.

11.5. If you are in the EEA or the UK, you have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to address your concern first.

12. Children

The Service is not directed at children. You must be at least 18 years old to hold an account, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

13. Changes to this policy

13.1. We may update this policy. The current version is always published at https://deplion.cc/legal/privacy-policy with its version identifier and effective date.

13.2. For material changes we will give notice by email or through the dashboard before they take effect.

14. Contact

Bytech LLP (Limited Liability Partnership «Bytech») BIN 230740022607 29A microdistrict, building 90, office 202, Aktau, Mangystau region, 130000, Republic of Kazakhstan

Version 2026-08-15 — effective 2026-08-15.