Legal

Privacy Policy

Last updated: February 4, 2026

This Privacy Policy describes how personal data is processed when using the ExitAnty website and mobile application. We do not use third‑party advertising trackers, do not run analytics collection, and do not sell personal data under applicable law and the EULA.

Scope

This Policy applies to all users of the ExitAnty software and website. Certain sections may vary depending on the user’s jurisdiction.

Data Controller

The data controller is the company that owns ExitAnty. For privacy inquiries, use the contact details in the ‘Contact’ section.

Data we process

  • Authentication data: session token stored on device in a secure store.
  • Device technical data: device session identifier (random ID) for active session management.
  • Optional work data: profile names, tags, session settings, supplied at the user’s discretion.

Purposes of processing

  • Providing and maintaining the software and service.
  • Authentication and session management.
  • Responding to user support requests.

Legal bases

  • Performance of the user agreement (EULA/Terms).
  • Legitimate interests to ensure service security and prevent abuse.
  • User consent — for specific actions where required.

Sharing with third parties

We do not sell personal data. Sharing may occur only with infrastructure/communications providers (processors) under data protection agreements and solely to deliver the service.

Security measures

We employ technical and organizational measures such as encryption, access control, logging, and secure transport (TLS). Only authorized personnel have access on a need‑to‑know basis.

Links

The site may contain links to third‑party resources; we are not responsible for their content or practices. Review their privacy policies before sharing data.

Automated decisions

We do not use automated decision‑making producing legal effects, and we do not perform automated profiling.

Data retained after account deletion

When you delete your account, we remove your personal data and all associated records. To prevent abuse and re‑registration with the same identifiers (e.g. to circumvent trial limits), we retain irreversible cryptographic hashes of your email address and Telegram ID. These hashes cannot be reversed to recover the original values and are used solely to block reuse of the same identifiers. This processing is based on our legitimate interest in protecting the service from abuse.

Your rights

  • Right of access and to obtain a copy.
  • Right to rectification.
  • Right to erasure where no legal basis applies.
  • Right to object to processing based on legitimate interests.
  • Right to data portability in machine‑readable form (where applicable).
  • Right to withdraw consent (if processing is based on consent).
  • Right to restrict processing in cases provided by law.

California Consumer Privacy Act (CCPA)

  • Right to opt out of ‘sale’ of personal data (we do not sell personal data).
  • Right to be informed about categories collected and to receive a copy for the last 12 months.
  • Right to request deletion of personal data collected in the last 12 months, subject to exceptions.

We endeavor to respond to verifiable CCPA requests within 45 days (extendable up to 90 days with notice and reasons). Identity verification is required.

Contact

For privacy inquiries, contact ExitAnty support support@exitanty.com