Back

Data Protection

Privacy Policy

Effective date: 29 August 2026

This Privacy Policy explains how Sinlege processes personal data in connection with account registration and security (including email verification, optional two-factor authentication via authenticator app, email codes, or WebAuthn/passkeys, and backup codes), wallet top-ups (including third-party top-ups via payment links), Shop and Servers (VPS and game hosting), Game Panel, Support tickets, Status interactions where logged, optional Quests and wallet rewards, customer reviews, Radio where offered, IP Transit (WireGuard peer configuration, assigned public IP addresses, and traffic metering counters), Sinbox (inbound disposable email at @sinlege.eu), Translations for invited translators, Referral Program identifiers, API and OAuth access, SinlegePass, SinlegeLicense, Sinlege2FA, optional identity verification via Stripe Identity where requested in specific cases, and related electronic services.

This Policy is provided under Article 13 and 14 of Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law. It is not legal advice.

1. Data Controller

  1. The controller of your personal data is Krzysztof Mańczak, Gumna 2a, 64-420 Kwilcz, Poland, conducting unregistered business activity (nierejestrowana działalność gospodarcza) within the meaning of Article 5 of the Act of 6 March 2018 - Entrepreneurs' Law (Prawo przedsiębiorców), trading as Sinlege. The controller is not registered in CEIDG and does not hold a NIP or REGON number in connection with this activity.
  2. You can contact the controller regarding data protection at [email protected] or by phone at +48 720 370 960.
  3. Sinlege has not appointed a Data Protection Officer; the controller remains the contact point for GDPR requests unless mandatory law requires otherwise.
  4. This Privacy Policy applies to the website sinlege.com and related systems operated as part of Sinlege.

2. What Data We Process

Depending on how you use the Service, we may process the following data:

  1. registration and account data, including email address, first name, last name, account identifiers, account currency (PLN), account status, and optional referral source identifier if you arrived via a referral link;
  2. where you register or log in using Discord, identifiers and profile data received from Discord, Inc. (for example Discord user id and avatar), within the scopes shown when you authorise the application;
  3. authentication and security data, including hashed password data, two-factor authentication status and method (authenticator app, email OTP, or WebAuthn/passkey credentials), TOTP secret data stored in hashed/encrypted form for app-based 2FA, backup code related data (stored in hashed form), login history, session identifiers, login pending tokens, IP addresses, and User-Agent strings;
  4. wallet and payment data, including transaction identifiers, payment status, top-up amounts, currency, payment method, wallet balance, and anti-fraud information;
  5. Quest participation and progress data, including which Quests you completed or claimed, associated one-time Wallet reward transactions, Quest progress indicators, and tracker-related records such as: unlocked site easter-egg identifiers synced from your browser when logged in; sampled resource-usage metrics for your hosted services used to verify metric Quests (for example CPU, memory utilisation, and uptime streaks); and, where you have linked Discord and a Quest requires Discord activity, Discord user id-linked counters and membership timestamps (for example number of messages sent in Sinlege's Discord guild and approximate days since joining that guild);
  6. optional customer reviews you submit (rating, text, display name preference, moderation status, and language/translation metadata where applied for display);
  7. where you use Sinlege Radio (if access is granted), Radio access status and listening session / usage statistics (for example session identifiers, listen duration, last-seen timestamps, and related operational counters);
  8. where you use IP Transit, WireGuard peer metadata (public keys, tunnel addresses, endpoints), assigned public IPv4 addresses, subscription and credit records (including purchase timestamps and expiry), and traffic metering counters (bytes transferred) used for billing and abuse prevention. Traffic counters record only the volume of transferred data and do not inspect or store the payload of communications;
  9. where you use Sinbox, your chosen local-part and full @sinlege.eu address, subscription and renewal records, storage usage counters, a last-read timestamp used to calculate unread indicators in the dashboard, and the content of received inbound messages stored within the 1 GB per-Account storage limit (sanitised plain text and HTML body fields; attachments are not stored). Inbound messages may contain personal data sent by third-party services (for example verification codes) and are processed to display them to you in the panel. You may delete individual messages or all stored messages at once from the panel while Sinbox is active. Search within the inbox is performed locally in your browser on message data already loaded for your Account and is not sent to Sinlege as a separate search log;
  10. where you use Support, ticket content, attachments, timestamps, and related communication metadata;
  11. where you are invited as a translator, proposed localisation strings, language codes, submission timestamps, and review outcomes;
  12. where the Referral Program is enabled, referral link identifiers/slugs and attribution events (for example registration or purchase events linked to a referral source);
  13. third-party top-up data, including Payment Link identifiers, declared payer first and last name, payment timestamps, and crediting status (recipients may see limited payer information in transaction history where the Service displays it). Where a payer completes payment through Stripe's payment interface (including the Payment Request Button), Stripe may collect and record the payer's email address as part of the payment process under Stripe's own terms and privacy policy. If Stripe transmits the payer's email to Sinlege as part of the payment confirmation, Sinlege processes it solely to record the transaction and for anti-fraud and complaint-handling purposes, and retains it together with the associated transaction record for the periods described in section 7;
  14. API-related metadata, including API Key labels, prefixes, creation and last-use timestamps, IP whitelist configuration, and rate-limit counters (the raw API Key is not stored; only a cryptographic hash);
  15. OAuth provider data, where you authorise third-party applications to access your Sinlege account: client identifiers, granted scopes (openid, profile, email), authorisation codes, access tokens, and refresh tokens with associated expiry times;
  16. service usage and technical data, including browser type, operating system, language, time zone, device information, screen resolution, session identifiers, request logs (which may include the requested URL, HTTP method, response status code, timestamp, IP address, and User-Agent), and error logs;
  17. support and complaint data, including the content of your messages, attachments, and related communications;
  18. hosting-related data to the extent necessary to provide services, secure infrastructure, respond to abuse, and handle legal obligations related to user-hosted content;
  19. infrastructure and network security data related to hosting, including server and virtual-machine resource-usage metrics (CPU, memory, disk, and network utilisation), connection and network-flow metadata (source and destination IP addresses, ports, protocols, packet and byte counts, and timestamps), abuse-detection signals, and DDoS-mitigation logs;
  20. identity verification data, only where an identity check is requested in a specific case (see section 18): government-issued identity document data returned by Stripe Identity - such as document type, document number, date of expiry, date of birth, verified first and last name, and address - together with the verification result and timestamp. Document images and any selfie/likeness captured during verification are collected and processed by Stripe as part of its identity service; Sinlege receives and stores the verified outputs described above in encrypted form and does not receive raw biometric templates.

3. Purposes and Legal Bases

  1. We process your data to create and maintain your account and provide electronic services under Article 6(1)(b) GDPR.
  2. We process payment and wallet data to perform contracts, handle wallet top-ups, verify transactions, and manage billing under Article 6(1)(b) GDPR.
  3. We process third-party top-up and payer data to provide payment links, process payments through the payment operator, credit recipients' Wallets, prevent abuse, and handle complaints under Article 6(1)(b) and, where applicable, Article 6(1)(f) GDPR.
  4. We process certain data to comply with legal obligations, including tax, accounting, consumer, anti-money laundering where applicable, and data protection obligations, under Article 6(1)(c) GDPR.
  5. We process technical, security, and anti-fraud data to protect the Service, prevent abuse, investigate incidents, and defend legal claims under Article 6(1)(f) GDPR.
  6. We process support and complaint communications to answer requests and resolve issues under Article 6(1)(b), (c), or (f) GDPR, depending on the case.
  7. We process hosting infrastructure metrics, network-flow metadata, and abuse-detection logs to secure and maintain the stability of the shared infrastructure, detect and mitigate attacks (including DoS/DDoS), enforce fair-use and resource limits, prevent abuse and fraud, and investigate incidents, under Article 6(1)(f) GDPR (legitimate interest) and, where applicable, Article 6(1)(c) GDPR.
  8. We process authentication and security data - including hashed passwords, 2FA configuration, backup codes (hashed), login OTPs (held only for the validity period), session tokens, IP addresses, and User-Agent data - to secure your Account and enforce technical limits under Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
  9. Where you use OAuth to authorise third-party applications, we process the minimum data necessary to issue tokens and honour granted scopes under Article 6(1)(b) GDPR.
  10. We process Quest participation, progress, and tracker data to operate optional Quests, verify completion, credit Wallet rewards, prevent abuse, and display progress in the panel under Article 6(1)(b) GDPR (performance of the electronic service / Account features you use) and, where necessary for security and anti-abuse integrity of the reward system, Article 6(1)(f) GDPR.
  11. We process optional Reviews you submit to publish and moderate customer feedback under Article 6(1)(b) GDPR and, for moderation and abuse prevention, Article 6(1)(f) GDPR.
  12. Where you use IP Transit, we process WireGuard peer metadata, assigned public IP addresses, subscription/credit records, and traffic metering counters to provide the service, bill usage, prevent spoofing and abuse, and secure shared infrastructure under Article 6(1)(b) and Article 6(1)(f) GDPR.
  13. Where you use Sinbox, we process your assigned address, subscription records, inbound message content, storage usage, and last-read timestamps to provide the inbound-only mailbox, enforce the 1 GB storage limit per Account, display messages securely in the panel, show unread indicators and optional in-dashboard notifications, process deletions you request in the panel (including delete-all), and prevent abuse under Article 6(1)(b) and Article 6(1)(f) GDPR. Third-party senders are independent controllers or processors of data they include in emails to your Sinbox address.
  14. Where you use Support or Translations features, we process ticket and translation-submission content to handle requests and publish approved localisations under Article 6(1)(b) and, where applicable, Article 6(1)(f) GDPR.
  15. Where the Referral Program is enabled, we process referral identifiers and attribution events to operate the program under Article 6(1)(b) and Article 6(1)(f) GDPR.
  16. Where processing is based on Article 6(1)(f) GDPR, Sinlege has carried out a balancing test and considers that its legitimate interests are not overridden by the rights and freedoms of data subjects.

4. Data Sources

  1. Most data is provided directly by you when you register, complete your account, contact us, use the customer panel, top up your wallet, create Payment Links, pay a third-party wallet top-up as a Payer, or purchase services.
  2. Some data is generated automatically by your use of the Service, including logs, session identifiers, technical metadata, service resource samples, and Quest progress signals.
  3. Some payment-related or verification-related data may be received from payment processors or security providers.
  4. Where you link Discord and participate in Sinlege's Discord server, certain Quest-related signals (message activity counts and membership join timestamps) may be derived from Discord guild events observed by Sinlege's Discord bot, linked to your Account via your Discord user id.

5. Recipients of Data

Your data may be shared, to the extent necessary, with the following categories of recipients:

  1. hosting and infrastructure providers used to operate the Service;
  2. Discord, Inc., where you use Discord authentication or account linking, to the extent data is transmitted through their systems;
  3. payment service providers, including Stripe Payments Europe, Ltd. (or entities indicated at checkout), which act as independent controllers or processors for payment data under their own policies;
  4. identity verification providers, namely Stripe (Stripe Identity), where an identity check is requested in a specific case; Stripe collects and processes the identity document and any selfie under its own terms and privacy policy and returns verified outputs to Sinlege (see sections 2 and 18);
  5. security and anti-bot technology - the Service uses its own SinlegePass captcha widget; no third-party captcha provider receives user data;
  6. IT service providers, technical support providers, and email delivery / SMTP providers where necessary to operate the Service (for example providers used to send account verification, password reset, security alerts, wallet or service confirmations, and other transactional emails). Such providers process email addresses and related message metadata solely for delivery of those communications on Sinlege's instructions;
  7. where Discord is used for Support tickets or staff operational channels, Discord, Inc. may process ticket content and related metadata transmitted to Discord for that purpose, in addition to Discord authentication/linking described above;
  8. internal administration tools, including an Admin AI assistant used only by authorised Sinlege administrators. Depending on configuration, prompts and tool outputs that may include customer-related data can be sent to self-hosted or third-party large-language-model providers selected by Sinlege for that internal purpose. Sinlege does not use those providers to serve ads. Where Telegram or Discord bots are connected for admin operations, message content necessary for that admin workflow may be processed on those platforms;
  9. legal, accounting, or advisory providers where disclosure is necessary to comply with law or protect legitimate interests;
  10. public authorities or law enforcement bodies where disclosure is required by applicable law.

6. Transfers Outside the EEA

  1. Some third-party providers used by the Service, especially payment or security providers, may process data outside the European Economic Area.
  2. Where such transfers occur, they are based on lawful transfer mechanisms recognized by the GDPR, such as adequacy decisions or standard contractual clauses, as applicable to the relevant provider.
  3. Stripe and Discord may process certain data internationally in accordance with their own legal documentation and safeguards.

7. Data Retention

  1. Account data is kept for as long as your account remains active and, after closure, for as long as necessary to comply with legal obligations or defend against claims.
  2. Payment, billing, and transaction records are retained for the period required by applicable tax and accounting law (generally up to 5 years from the end of the tax year in Poland unless a longer period applies).
  3. Payment Link and payer name records linked to a transaction are retained with the relevant transaction history for the same periods where they form part of accounting or complaint evidence.
  4. Security logs, login records, rate-limit counters, and anti-fraud records are retained for as long as needed for security, abuse prevention, or legal protection, and in any event for periods proportionate to the risk (as a rule up to 180 days, unless a specific incident or legal claim requires longer retention). Application audit log files are routinely pruned to that period. Login OTP codes are stored only in pending-verification records for the validity period (as a rule five minutes) and are deleted or overwritten when expired or successfully used.
  5. Web server request / access logs (URL, HTTP method, response status, timestamp, IP address, and User-Agent) are retained as a rule up to 14 days in accordance with server log rotation, unless a longer period is needed for a specific security investigation or legal claim.
  6. Support and complaint communications are retained for as long as needed to resolve the matter and for any subsequent limitation period.
  7. Network-flow metadata and abuse-detection traffic samples used for hosting security (including DoS/DDoS monitoring) are retained only for a short operational window (as a rule up to about 25 hours for detailed samples). Aggregated traffic totals used for operational charts may be retained longer (as a rule up to about 10 days) and are then deleted, unless a longer period is required to investigate a specific incident or to establish, exercise, or defend legal claims.
  8. Hosted service data follows the service lifecycle: a paid service is provided for the billing period (as a rule 30 days) and, upon expiry, enters a grace period (as a rule 7 days) during which it may be renewed. If the service is not renewed, the virtual machine and all associated hosted data - including disks and any snapshots - are permanently removed after the grace period ends. Where a service is suspended, hosted data is retained for the duration of the suspension; if the underlying cause is not resolved, the service and its data are removed on the same basis. After permanent removal, hosted data cannot be recovered. These periods may be adjusted and are reflected in the customer panel; statutory retention obligations (e.g. billing records) are unaffected.
  9. Identity verification data (see section 18) is retained in encrypted form only for as long as necessary for the purpose for which the check was requested - for example resolving a payment dispute or fraud investigation, meeting a security or legal-compliance need, or establishing, exercising, or defending legal claims - and is then deleted. Document images and any selfie remain with Stripe and are subject to Stripe's own retention practices.
  10. Quest claim records and Wallet reward transactions are retained with wallet/transaction history for the periods applicable to billing and complaint evidence (see payment retention above). Quest progress and Discord Quest counters are retained while useful to operate Quests and prevent duplicate claims, and are deleted or anonymised when no longer needed or upon account deletion subject to legal retention obligations.
  11. IP Transit records - including WireGuard peer metadata, assigned public IP assignment history, Traffic credit balances and purchase/expiry timestamps, and traffic metering counters - are retained while the service is active and thereafter for as long as needed for billing, abuse prevention, security, and legal claims (as a rule aligned with payment/transaction retention where they form part of billing evidence). After the Customer's IP Transit access ends, technical peer configuration that is no longer needed may be deleted or anonymised, subject to those retention needs.
  12. Sinbox message content is retained only within the service storage limit (1 GB total stored text per Account). There is no separate message-count cap. When storage would be exceeded, the oldest messages are deleted automatically; you may delete individual messages or all stored messages in the panel. The last-read timestamp is updated when you open Sinbox or view messages and is retained with your mailbox record while Sinbox is active. Sinbox address assignment and subscription/billing records are retained while the service is active and thereafter as needed for billing, abuse prevention, and legal claims (as a rule aligned with payment/transaction retention).
  13. Translator submissions and related review metadata are retained while useful to operate Translations and for moderation/audit, and may be deleted or anonymised when no longer needed or upon account deletion subject to legal retention obligations. Referral Program events are retained while useful to operate attribution and prevent abuse, aligned with Account and billing retention where rewards are involved.

8. Your Rights

Subject to applicable law, you have the right to:

  1. access your personal data;
  2. request rectification of inaccurate or incomplete data;
  3. request erasure of data where legal grounds exist;
  4. request restriction of processing;
  5. object to processing based on legitimate interests;
  6. request data portability where processing is based on a contract or consent and is carried out by automated means;
  7. lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland (uodo.gov.pl) or another competent EU supervisory authority.

To exercise your rights, contact [email protected]. We respond without undue delay and within one month as a rule, extendable where permitted by Article 12 GDPR.

9. Whether Providing Data Is Mandatory

  1. Providing data is voluntary in principle, but certain data is necessary to create and maintain an account, complete payments, provide hosting services, respond to support requests, or comply with legal obligations.
  2. If you do not provide data required for a given action - including a valid email address, password, verified email, name, PLN currency selection, captcha completion, or payment details - we may be unable to create your account, process a payment, activate a service, or respond properly to your request.

10. Automated Decision-Making

  1. We do not state that we carry out solely automated decision-making producing legal effects on users within the meaning of Article 22 GDPR as part of the standard operation of the Service.
  2. Security, anti-fraud, and abuse prevention mechanisms may nevertheless involve automated signals or technical scoring used to support manual or operational decisions concerning access security or payment verification.

11. Cookies, Session Technologies, and Local Preferences

  1. The Service uses session and preference-related technologies necessary for authentication, maintaining sessions, and remembering interface choices.
  2. The Service also uses technical preference storage for visual settings such as theme preferences.
  3. The Service may set a first-party cookie named _ee (or similar) to remember which optional site easter eggs you have unlocked in your browser. This is a preference cookie, not an advertising or analytics cookie. If you are logged in, unlock state may be synchronised to your Account solely to verify related Quests (see section 19).
  4. We currently do not state that we use analytics cookies, advertising cookies, remarketing cookies, or newsletter tracking cookies as part of the Service's standard operation.
  5. Stripe may use its own cookies or similar technologies when its payment components are loaded, according to its own policies. The SinlegePass captcha widget is first-party: it does not set third-party captcha cookies, but may set a first-party tutorial cookie and use sessionStorage for short-lived challenge nonces, as described in the Cookie Policy and section 15.
  6. You can manage cookies through your browser settings, but disabling strictly necessary cookies may impair the functionality of the Service. Clearing the easter-egg cookie may reset local easter-egg state.
  7. For a structured overview of cookie categories and legal bases, see the Cookie Policy.

12. Security Measures

  1. We apply technical and organizational measures appropriate to the risk, including authentication controls, password hashing with argon2id (legacy bcrypt hashes may still be verified and upgraded on successful login), cryptographic hashing of API keys and backup codes, access restrictions, protective logging, payment verification, rate limiting, IP-based abuse controls, and first-party SinlegePass captcha verification.
  2. You are responsible for securing your account credentials, using a strong unique password, safeguarding backup codes and 2FA devices, and enabling two-factor authentication where available.

13. User-Hosted Content and Abuse Handling

  1. Where you use purchased hosting services to upload or store your own content, we may process technical and operational data related to such content to provide the service, maintain security, investigate abuse, and comply with legal obligations.
  2. We do not perform general monitoring of all hosted content, but we may review data where necessary to investigate abuse, respond to notices of illegal content, or protect infrastructure and other users.

14. Children

  1. The Service is available only to natural persons who are at least 18 years of age, as described in the Terms of Service. Accounts for persons under 18 are not permitted.
  2. If we learn that personal data has been provided unlawfully, we may delete the relevant account and associated data where appropriate.

15. SinlegePass Captcha Widget - Data Processing

This section applies when the SinlegePass captcha widget is embedded on a third-party website using our API.

  1. What the widget collects. When a visitor encounters a SinlegePass captcha, the widget running in the visitor's browser collects the following data solely for the purpose of distinguishing human users from automated bots: (a) browser environment signals - User-Agent string hash, screen resolution, timezone, device pixel ratio; (b) anonymised mouse/pointer movement samples captured during the slider interaction; (c) canvas fingerprint - a hash of a rendered image used to detect software renderers typical of headless browsers; (d) WebGL renderer identifier, used to detect virtualised or emulated GPU environments; (e) a font availability probe (presence/absence of standard system fonts, not the font names themselves); (f) interaction timing data - time elapsed from page load to widget interaction start; (g) count of page-level mouse, click, and scroll events prior to widget interaction; (h) touch point count; and (i) other limited client capability signals used for bot detection (for example hardware concurrency or language count where available). The interactive challenge puzzle expires after about five (5) minutes; a successful response token remains valid for up to ten (10) minutes.
  2. Retention. The data described above is bound to an individual challenge session (challenge ID). Each challenge expires automatically after the periods stated above or immediately upon use, whichever comes first. Challenge signals are not used to build advertising profiles.
  3. IP address. The visitor's IP address is transiently associated with the challenge for the duration of the challenge session (as a rule up to 10 minutes for the response token). The IP address is used exclusively for challenge integrity, replay prevention, and abuse detection. After expiry or successful use, the challenge record is invalidated; expired records are deleted when accessed or during routine cleanup and are not retained for profiling.
  4. Legal basis. Processing is based on our legitimate interest (Article 6(1)(f) GDPR) in operating a fraud-prevention and bot-detection service. The data collected is the minimum necessary to distinguish human from automated interaction. The processing does not involve profiling or automated decisions that produce legal or similarly significant effects on data subjects.
  5. Responsibility of the site owner (API customer). The operator of any website that embeds the SinlegePass widget is responsible for informing their own visitors about the use of the captcha service in their privacy policy, in accordance with applicable law.
  6. First-party storage; no third-party captcha cookies. The widget does not set third-party advertising cookies and does not load third-party captcha providers. It may set a first-party cookie (for example sp_captcha_tutorial, typically up to about one year) to remember that the on-widget tutorial was shown, and may use sessionStorage for short-lived page nonces used in challenge integrity. These are not advertising identifiers and are not sold.

16. SinlegeLicense - Key Validation Data

This section applies when the SinlegeLicense public validation endpoint is called by end-user software on behalf of a SinlegeLicense account holder.

  1. What is processed during validation. When a validation request is received, Sinlege processes: (a) the license key string being validated; (b) the client IP address, if the key is configured as IP-bound; (c) the hardware ID (HWID) string, if the key is configured as HWID-bound; (d) the validation result (valid/invalid) and timestamp. No other end-user data is collected.
  2. Retention. Sinlege retains only the last 5 validation entries per key. Each new validation replaces the oldest stored entry. There is no long-term validation log.
  3. Legal basis. Processing is carried out on the basis of legitimate interest (Article 6(1)(f) GDPR) in providing the key validation service and enabling the account holder to detect abuse.
  4. Controller and processor relationship. The SinlegeLicense account holder is the data controller in relation to their own end-users whose IP addresses or HWIDs are processed through key validation. Sinlege acts as a data processor for that purpose and processes such data solely on the account holder's instructions. The terms of this processing relationship are governed by Section 23 of the Terms of Service (Data Processing Agreement - SinlegeLicense Annex), which is accepted automatically upon first use of the SinlegeLicense service. Account holders are responsible for ensuring they have an appropriate legal basis for collecting end-user IPs and HWIDs, and for providing their end-users with the required privacy disclosures.
  5. No cross-application tracking. Validation data is strictly scoped to the specific license key and account. Sinlege does not use this data for any purpose other than performing the validation and providing the account holder with usage records.

17. Sinlege2FA - Encrypted TOTP Vault

This section applies to the Sinlege2FA feature, which allows logged-in users to store Time-based One-Time Password (TOTP) secrets encrypted within their account.

  1. What is stored. When a user adds a 2FA account to their vault, the following data is stored: (a) an account name (user-provided, up to 60 characters); (b) an optional description (user-provided, up to 200 characters); (c) the TOTP secret encrypted with AES-256-GCM; (d) the AES-GCM initialisation vector (IV) used for encryption; (e) a per-user random salt ("vaultSalt") used for key derivation, stored separately from the encrypted secret. The plaintext TOTP secret is never transmitted to or stored on Sinlege servers.
  2. Client-side encryption. Encryption and decryption occur exclusively in the user's browser. The vault key is derived client-side via PBKDF2-SHA-256 (200 000 iterations) from the user's account password and the vaultSalt. The derived key is held only in memory for the duration of the session and is cleared on page unload. Sinlege cannot decrypt vault contents and has no access to the user's TOTP secrets.
  3. Password verification. To unlock the vault, the user submits their account password and passes a SinlegePass captcha. Sinlege verifies the account password hash (argon2id, or a legacy bcrypt hash pending upgrade) server-side solely for the purpose of authorising the release of the vaultSalt. The password itself is not stored in cleartext at any point.
  4. Legal basis. Processing is carried out on the basis of contract performance (Article 6(1)(b) GDPR) - the encrypted vault is a service feature the user has opted to use. Password verification is a security measure required to perform the service.
  5. Retention. Encrypted vault entries are retained for as long as the user's account exists. Users may delete individual entries or their entire account at any time. Upon account deletion all vault entries and the associated vaultSalt are permanently erased.
  6. No cross-device synchronisation by third parties. Vault data is stored exclusively in Sinlege's infrastructure. It is not shared with or accessible to any third party.
  7. User responsibility. Users are responsible for ensuring their account password is sufficiently strong, as the security of the encrypted vault depends on the confidentiality of the password. Sinlege recommends using a strong, unique password and enabling account-level two-factor authentication where available.

18. Identity Verification (Stripe Identity)

This section applies where Sinlege requests that a person complete an identity verification through a verification link. Identity verification is not part of standard self-service registration; it may be requested in specific cases, for example to prevent or investigate fraud, to resolve a payment dispute or chargeback, to protect account or infrastructure security, or to comply with a legal obligation.

  1. How it works. The verification itself is performed by Stripe Identity. The person is directed to a Stripe-hosted flow in which Stripe asks for a government-issued identity document and, where applicable, a selfie. The document images and any selfie are collected and processed by Stripe under Stripe's own terms and privacy policy; Sinlege does not have access to the raw document images or biometric templates.
  2. What Sinlege receives and stores. Sinlege receives from Stripe the verified outputs of the check - such as document type, document number, date of expiry, date of birth, verified first and last name, address, and the verification status and timestamp. These outputs are stored by Sinlege in encrypted form and are accessible only to authorised administrators for the purpose of the specific check.
  3. Legal basis. Where an identity check is requested for fraud prevention, dispute resolution, or protection of the Service, processing is based on Sinlege's legitimate interest (Article 6(1)(f) GDPR) and, where the check is required to meet a legal obligation, on Article 6(1)(c) GDPR. To the extent any special-category or biometric processing takes place during document and selfie matching, it is carried out by Stripe as part of its identity service under its own legal basis and safeguards; Sinlege does not receive or store such biometric data.
  4. Retention. The encrypted verification outputs held by Sinlege are retained only for as long as necessary for the purpose for which the check was requested, and are then deleted (see section 7). Data held by Stripe is subject to Stripe's own retention practices.
  5. International transfers. Stripe may process identity data outside the European Economic Area under the transfer mechanisms described in section 6.
  6. Your rights. The rights described in section 8 apply to identity verification data held by Sinlege. Requests concerning data held directly by Stripe should also be addressed to Stripe as described in Stripe's privacy policy.

19. Quests - Progress and Tracker Data

This section applies when you use optional Quests in the customer panel.

  1. What is processed. Depending on the Quest, Sinlege may process: Quest identifiers and claim status; Wallet reward amounts and related transaction records; easter-egg unlock identifiers synced from your browser when logged in; resource-usage samples and streak data for your hosted services (CPU, memory utilisation, uptime) used only to verify metric Quests; and, where Discord is linked and required by a Quest, Discord user id, guild message counts attributable to that id on Sinlege's Discord server, and guild membership join timestamps / derived day counts.
  2. What is not processed for Quests. Sinlege does not store the full text content of Discord messages for Quest purposes - only aggregate counts and membership timing needed for verification. Easter-egg data is limited to unlock keys, not browsing history outside the Service.
  3. Legal basis. Processing is based on Article 6(1)(b) GDPR where Quests form part of the Account features you choose to use, and Article 6(1)(f) GDPR where necessary to protect the integrity of the promotional reward system against abuse.
  4. Voluntary nature. Quests are optional. You may refrain from linking Discord, clearing preference cookies, or claiming rewards; paid Services you have ordered remain available subject to the Terms of Service.
  5. Retention. See section 7. Progress data that is no longer needed for active Quests or anti-abuse may be deleted or anonymised.

20. Sinbox - Inbound Email Data

This section applies when you use Sinbox.

  1. What we process. Your chosen local-part and assigned @sinlege.eu address; subscription activation and renewal timestamps; storage usage; a last-read timestamp for unread indicators; and inbound message metadata and body (sender address, subject, received time, sanitised plain text and HTML). Attachments are not stored.
  2. Third-party senders. Verification emails are usually sent by services you register with. Those senders may process your Sinbox address and message content under their own policies. Sinlege processes received messages solely to deliver them to your panel.
  3. Automated review of address names. When you choose a local-part, Sinlege may apply rule-based checks and optional automated review (including AI-assisted classification) to block reserved, misleading, or abusive names. This processing is based on Article 6(1)(b) and Article 6(1)(f) GDPR.
  4. Security processing. Message bodies are sanitised server-side before display (scripts, iframes, and dangerous markup are removed). Content is rendered in an isolated panel view (closed shadow root). Optional remote image loading uses Sinlege's proxy and may temporarily process image URLs you enable.
  5. Unread indicators and notifications. While Sinbox is active, Sinlege may compare message received times with your last-read timestamp to show unread counts in the dashboard and, where enabled in your browser session, play a short notification sound. This uses data already stored for your Account and does not involve reading message bodies for notification purposes beyond what is needed to display the inbox.
  6. Search. Inbox search filters messages already loaded in your browser. Sinlege does not maintain a separate server-side search log for this feature.
  7. Retention. See section 7. Message content beyond the 1 GB storage limit is deleted automatically (oldest first). You may delete individual messages or all stored messages in the panel while Sinbox is active.
  8. Deletion by you. When you delete a message or use delete-all in the panel, Sinlege removes the affected message(s) and associated stored body content from active storage without undue delay, subject to routine backups and security logs retained under section 7.
  9. Address changes. After confirmation, the address is locked in the panel. Change requests are handled manually via Support where permitted under the Terms of Service.

21. Changes to This Policy

  1. We may update this Privacy Policy where necessary due to legal, technical, or operational changes.
  2. The updated version will be published in the Service with a revised effective date.