Who we are
Pithy, LLC (“Pithy”, “we”, “us”) is a limited liability company registered in TKTK-STATE, with its principal place of business at TKTK-REGISTERED-ADDRESS.
We are the controller of the personal data described in this notice — that is, we decide what is collected and why. For privacy questions, requests, or complaints, email support@help.pithy.sh, or write to us at the address above.
The thing worth knowing first
Pithy is a backend kit that runs in your Cloudflare account. Your databases, buckets, indexes and Workers are provisioned into infrastructure you own, under credentials you hold. Your application’s data — your records, your files, and the personal data of your users — is never sent to us, never passes through our systems, and is not something we could produce if asked.
What this notice covers is the much smaller set of data involved in you having an account with us: who you are, which organizations and projects you have, and where your Workers are so the dashboard can talk to them.
What we collect, and why
Account data
Your email address, and your display name and avatar if you set them. Collected when you sign up or accept an invitation, and used to identify you, sign you in, and contact you about your account. Our legal basis is performance of a contract — we cannot give you an account without it.
Organization and membership data
The name of your organization, the projects and environments inside it, and each member’s role. Used to decide who can see and do what. Legal basis: performance of a contract.
Where you invite someone, we store the email address you supplied and the status of the invitation until it is accepted or expires. Legal basis: our legitimate interest in letting you assemble a team, balanced against a narrow use and a short retention.
Connection data
For each environment you connect, we store the URL of your Worker, its base path, the scopes you granted, the last time it answered, and the version it reported. We also store a public key and a sealed private key used to authenticate the connection.
This is metadata about where your application is and what it will let us ask it. It is not your application’s data. Legal basis: performance of a contract.
Support data
If you write to us or use the contact form, we keep the message and your email address so we can answer, and so a later conversation makes sense in the light of an earlier one. Legal basis: legitimate interest in answering the people who write to us.
Security data
Our site and dashboard record request metadata — IP address, user agent, timestamps — to detect and block abuse. Legal basis: legitimate interest in keeping the service available and unabused.
What we do not collect
We do not run advertising or marketing analytics on this site. We do not sell data, and there is no third-party tracker on these pages. Payment data — your card, your billing address, your invoices — is collected by Paddle rather than by us, and we never see it.
Cookies
This site sets one cookie, and it is strictly necessary. It belongs to the bot check that guards the dynamic parts of the site — the parts that accept input and talk to a server rather than just rendering. Today that means two things:
- the contact form, and
- the newsletter signup on the blog.
Everything else on this site is a static page and sets nothing at all. The check is what tells a person from a script; without the cookie it cannot carry its result from one step to the next, so those two forms stop working.
There are no analytics cookies and no advertising cookies on this site, which is why you are not being asked to consent to any. A strictly necessary cookie does not require consent, and there is nothing here to switch off. If you block it in your browser, the site still works — the forms will not.
The dashboard sets a session cookie when you sign in, for the same reason every signed-in application does.
Who else sees it
We share personal data with a small number of providers, each for a stated purpose and none for their own:
| Who | What for | Where |
|---|---|---|
| Paddle | Merchant of record — the sale, subscriptions, payments, invoicing and tax compliance | United Kingdom, United States |
| Cloudflare | Hosting, delivery and security for this site and the dashboard | Global network |
| Our email provider | Sending account, security and support mail | United States |
Paddle is a controller of the payment data it collects, independently of us, under its own privacy policy.
Beyond that, we disclose personal data only to professional advisers under a duty of confidence, to authorities where the law requires it or where it is needed to protect rights or safety, or to an acquirer if the business is sold — in which case this notice binds them until it is replaced.
International transfers
We are based in the United States and our providers process data in the United States and elsewhere. If you are in the United Kingdom or the European Economic Area, that means your personal data leaves your jurisdiction.
Where it does, the transfer relies on the UK International Data Transfer Agreement or the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies, together with the technical measures described below.
How long we keep it
- Account and organization data — for as long as your account exists, and for 30 days after you close it, so that an accidental deletion can be undone.
- Connection data — until the connection is removed, and then deleted with it.
- Invitations — until accepted, or 30 days after they expire.
- Support mail — 24 months from the last message in the conversation.
- Security logs — 90 days.
Where a longer period is required by law — a tax record, for example — we keep only what the law requires, and only for as long as it requires it. Anything else is deleted or irreversibly anonymized when it is no longer needed for the purpose it was collected for.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct it, if it is wrong or incomplete;
- delete it;
- restrict what we do with it, or object to processing we base on legitimate interests;
- port it to you or to someone else in a structured, machine-readable form; and
- withdraw consent, where we relied on consent — which does not affect what we did before you withdrew it.
Email support@help.pithy.sh and we will respond within one month. If a request is complex we may extend that, as the law allows, and we will tell you if we do. We do not charge for this.
If you are in the United Kingdom or the EEA and you think we have got it wrong, you can complain to your local supervisory authority — in the UK, the Information Commissioner’s Office. We would rather you told us first, but that right does not depend on it.
Security
We protect personal data with technical and organizational measures appropriate to the risk. In practice that means encryption in transit and at rest, access limited to the people who need it, private keys held sealed rather than in plaintext, and credentials that rotate.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the relevant authority within the time the law allows.
Children
The service is not for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
Changes
We will update this notice when what we do changes. The effective date at the top is the date the current version applies from, and if a change materially affects your rights we will tell you before it takes effect rather than after.