Privacy Policy
Last updated: February 4, 2026
This Privacy Policy describes how personal data is processed when using the ExitAnty website and mobile application. We do not use third‑party advertising trackers, do not run analytics collection, and do not sell personal data under applicable law and the EULA.
Scope
This Policy applies to all users of the ExitAnty software and website. Certain sections may vary depending on the user’s jurisdiction.
Data Controller
The data controller is the company that owns ExitAnty. For privacy inquiries, use the contact details in the ‘Contact’ section.
Data we process
- Authentication data: session token stored on device in a secure store.
- Device technical data: device session identifier (random ID) for active session management.
- Optional work data: profile names, tags, session settings, supplied at the user’s discretion.
Purposes of processing
- Providing and maintaining the software and service.
- Authentication and session management.
- Responding to user support requests.
Legal bases
- Performance of the user agreement (EULA/Terms).
- Legitimate interests to ensure service security and prevent abuse.
- User consent — for specific actions where required.
Sharing with third parties
We do not sell personal data. Sharing may occur only with infrastructure/communications providers (processors) under data protection agreements and solely to deliver the service.
Security measures
We employ technical and organizational measures such as encryption, access control, logging, and secure transport (TLS). Only authorized personnel have access on a need‑to‑know basis.
Links
The site may contain links to third‑party resources; we are not responsible for their content or practices. Review their privacy policies before sharing data.
Automated decisions
We do not use automated decision‑making producing legal effects, and we do not perform automated profiling.
Data retained after account deletion
When you delete your account, we remove your personal data and all associated records. To prevent abuse and re‑registration with the same identifiers (e.g. to circumvent trial limits), we retain irreversible cryptographic hashes of your email address and Telegram ID. These hashes cannot be reversed to recover the original values and are used solely to block reuse of the same identifiers. This processing is based on our legitimate interest in protecting the service from abuse.
Your rights
- Right of access and to obtain a copy.
- Right to rectification.
- Right to erasure where no legal basis applies.
- Right to object to processing based on legitimate interests.
- Right to data portability in machine‑readable form (where applicable).
- Right to withdraw consent (if processing is based on consent).
- Right to restrict processing in cases provided by law.
California Consumer Privacy Act (CCPA)
- Right to opt out of ‘sale’ of personal data (we do not sell personal data).
- Right to be informed about categories collected and to receive a copy for the last 12 months.
- Right to request deletion of personal data collected in the last 12 months, subject to exceptions.
We endeavor to respond to verifiable CCPA requests within 45 days (extendable up to 90 days with notice and reasons). Identity verification is required.
Contact
For privacy inquiries, contact ExitAnty support support@exitanty.com