Privacy policy
Effective 22 August 2026
This policy explains how SaveState processes personal data when you visit the website, create an account, buy a subscription, contact support, or use the encrypted backup service.
Who controls your personal data
SaveState is the data controller for account, website, support, security, and billing-administration data. When a business customer backs up personal data under its own instructions, that customer is normally the controller and SaveState acts as its processor as described in the Data Processing Addendum.
Data we process
- Account and subscription data: email address, password hash, internal identifiers, selected plan, subscription status, usage allowances, and billing references.
- Backup operations: encrypted repository objects and limited readable metadata needed to operate the service, including source paths, snapshot identifiers, timestamps, object sizes, file counts, logical folders, schedules, job status, and storage or transfer usage.
- Security and recovery: encrypted TOTP seeds, hashed one-time recovery tokens or codes, authentication version, security audit events, and one-way request fingerprints used for abuse prevention.
- Support: messages, attachments, contact details, and diagnostic details you choose to send.
- Notification settings: event preferences and an optional Discord webhook credential. The credential is write-only in current clients and is used only to deliver the notifications you request.
- Optional analytics: consented pseudonymous visitor and session identifiers, page path without query data, referring hostname, campaign labels, country supplied by Cloudflare, selected plan, and checkout stage.
- Affiliate attribution and portals: an affiliate code from a referral link or code entry, attribution source and timestamps, pseudonymous customer label, signup and subscription status, finalized payment references and amounts, commission, reversal, payout, bank-reference, agreement-acceptance, portal-session, and receipt records. Affiliates do not receive customer email addresses, payment credentials, account access, or backup data.
Why we use it
- To provide accounts, subscriptions, encrypted storage, backup, restore, support, and account recovery under our contract with you.
- To process payments and keep legally required transaction records.
- To secure the service, prevent fraud and abuse, diagnose failures, and protect customers based on our legitimate interests in operating a reliable service.
- To send service, security, expiry, and billing messages needed to perform the contract or protect an account.
- To measure website and purchase activity only after consent. You can withdraw that consent through “Analytics preferences” in the footer.
- To apply affiliate discounts, enforce one exclusive Affiliate per customer, calculate commission only from finalized positive payments, prevent duplicate commission, administer agreement acceptance and manual bank-transfer payouts, and keep corresponding transaction records.
- To comply with legal obligations and respond to valid legal requests.
Encrypted backup contents
Backup contents are encrypted on the customer device before upload. SaveState’s gateway does not receive the repository password, decrypted vault master key, or plaintext backup contents. Existing backups still depend on the customer-controlled key envelope; an account-password reset does not create a server-side plaintext copy of that key. Backblaze also applies SSE-B2 AES-256 encryption as an additional storage layer.
Providers, locations, and transfers
- Backblaze B2 stores encrypted backup objects in its EU Central region in Amsterdam. SaveState does not configure separate cross-region or multi-cloud replication for those objects. Backblaze’s EEA/EU Data Processing Addendum applies to its processing for SaveState.
- Cloudflare provides DNS, edge delivery, application infrastructure, queues, email sending, and databases. Network and operational requests may be processed at Cloudflare locations outside the EU under Cloudflare’s Data Processing Addendum.
- Stripe processes payment, tax-ID, and subscription information under Stripe’s own privacy terms.
Where a provider processes data outside the EEA, SaveState relies on an applicable adequacy decision, approved contractual safeguards such as the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism made available by that provider. We do not sell personal data or use backup contents for advertising.
Browser storage and analytics
The dashboard stores an authentication token in browser storage so a signed-in session can continue between page loads; signing out removes it from that browser. Essential storage is used for login, security, your selected checkout currency, and your optional-storage preference.
If optional storage is accepted, the browser creates random visitor and per-tab session identifiers. The API replaces them with independently keyed one-way pseudonyms before sending events to the private Engine database. A valid affiliate referral may also be stored in one first-party savestate_ref cookie for the period configured for that Affiliate, capped at 365 days and normally 30 days. The cookie contains only the latest affiliate code. A code entered by the customer takes priority over a link before the first finalized payment. If optional storage is declined, no analytics identifiers are created and a referral remains only in the current tab’s session storage so its discount can still be used during that visit.
Affiliate portal authentication uses a short-lived, single-use email link followed by a private browser session token. The portal exposes only pseudonymous customer labels and limited funnel, plan, subscription, revenue, commission, and timing data. Payout receipts can be downloaded only by the matching Affiliate or an authorised SaveState owner.
Retention and deletion
- When any subscription ends, backup objects remain available for restore only during the three-day grace period. At the deadline, the backup bucket, every object version, snapshot and folder metadata, related service-usage state, and any vault-key envelope no longer used by another service are permanently deleted.
- Login, account-security, and subscription-administration data remains while the account is open so the customer can sign in, protect the account, and purchase another service. A verified erasure request deletes this data unless retention is legally required.
- Completed or cancelled erasure workflow records are removed after 30 days; the Engine keeps a minimal, email-free completion marker for up to one year.
- Operational request logs are retained for up to 90 days and job or delivery events for up to 180 days.
- Consented visitor analytics is retained for up to 13 months and commerce analytics for up to 25 months.
- Affiliate attribution, agreement, commission, payout, and receipt records are retained with the related commercial, accounting, and dispute records. Removing the browser cookie prevents future link attribution but does not move or erase attribution finalised by a completed payment.
- Accounting records are retained for the current accounting year and at least five years after that year ends where Danish bookkeeping law requires it. Payment, dispute, and fraud-prevention records may be retained for a longer applicable limitation or legal-compliance period.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. You may also complain to the Danish Data Protection Agency (Datatilsynet).
Send a request to privacy@savestate.dk. We may ask for reasonable proof that you control the relevant account. SaveState does not make decisions producing legal or similarly significant effects solely through automated processing.
Security and policy changes
SaveState uses transport encryption, least-privilege administrative access, encrypted secrets, rate limits, security logging, and client-side backup encryption. No system is risk-free. Material changes will be posted here with a new effective date and, where appropriate, communicated through the service or account email.
