Privacy Policy
Last updated: July 19, 2026 · Effective: July 19, 2026
1. Who We Are
HugMyTools.com ("we", "us", "our") is a digital service for online file processing. This Privacy Policy explains what information we collect, why, and how we protect it.
Data controller / Privacy Officer: The operator of HugMyTools.com · Contact: privacy@hugmytools.com
This policy applies to users worldwide, including residents of the European Union, Canada, and the United States.
2. Information We Collect
Account information (if you register): email address, hashed password, display name (optional). We never store plaintext passwords — bcrypt is used with cost factor 12.
Files you upload: temporarily stored in encrypted ephemeral storage for processing and delivery. See Section 4 for retention periods. We do not read or analyze file contents beyond what is required to complete your requested operation.
Usage data: operation counts per tool (for tier enforcement), timestamps, tool slug used, file sizes (bytes only). No file names or content are logged.
Technical data: IP address (for rate limiting and abuse prevention), browser User-Agent (for session security), error logs (anonymized after 7 days).
Payment data: handled entirely by Paddle (our Merchant of Record). We never see or store full card numbers. We receive only a Paddle customer ID and subscription status.
3. How We Use Your Information
- Delivering the file processing operations you request
- Enforcing tier limits and premium usage allowances
- Authenticating your account and maintaining session security
- Preventing abuse, spam, and unauthorized access
- Billing and subscription management via Paddle
- Sending transactional emails (email verification, password reset, billing receipts)
We do not use your data for: advertising targeting, selling to third parties, training AI/ML models, behavioral profiling, or any purpose not listed above.
3a. Legal Basis for Processing (GDPR — EU/EEA Users)
If you are located in the EU or EEA, we process your personal data on the following legal bases under Article 6 of the GDPR:
- Contract performance (Art. 6(1)(b)): Processing your files, managing your account, billing, and delivering the service you subscribed to.
- Legitimate interests (Art. 6(1)(f)): Rate limiting, abuse prevention, security monitoring, and error logging — necessary to operate a reliable and secure service.
- Legal obligation (Art. 6(1)(c)): Retaining billing records as required by applicable law.
- Consent (Art. 6(1)(a)): Any processing that is optional and not required to deliver the Service (currently none beyond the above).
You may withdraw consent at any time where consent is the basis. Withdrawal does not affect the lawfulness of prior processing.
Data retention periods: Account data is retained until you delete your account. Billing records are retained for 7 years as required by applicable tax law. Processed files are auto-deleted per your tier (see Section 4). Anonymized usage logs are retained for 90 days.
International transfers: Some processors listed in Section 6 are located in the United States. Where personal data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or on the processor's participation in an equivalent transfer mechanism.
4. File Retention
Files are stored only for the duration needed to deliver the result and for a short retention window so you can re-download:
- Free: 1 hour
- Starter: 6 hours
- Pro: 24 hours
- Business: 72 hours
- Enterprise: 7 days
After retention expires, files are permanently deleted from storage using secure deletion. They are not recoverable. Unauthenticated sessions: files are deleted 1 hour after processing regardless of any other setting.
5. Cookies & Local Storage
We use minimal storage:
- HttpOnly cookie: refresh token (JWT) — necessary for authenticated sessions, inaccessible to JavaScript
- sessionStorage: access token (JWT) — cleared when browser tab closes
- locale cookie: your language preference — no personal data, 1-year expiry
We do not use third-party tracking cookies. We do not use Google Analytics or any behavioral analytics platform.
6. Third-Party Processors
We use a small number of trusted processors. Where applicable, each is bound by a Data Processing Agreement and SCCs for EU data transfers:
- Paddle (UK / US) — payment processing and Merchant of Record (PCI-DSS Level 1 certified). Paddle is itself a data controller for payment data.
- Google LLC (US) — Google Sign-In / Google OAuth, if you choose to authenticate via Google.
- Apple Inc. (US) — Sign in with Apple, if you choose to authenticate via Apple.
- Cloudflare R2 / S3-compatible storage (US) — encrypted ephemeral file storage for processing and temporary result delivery.
Each processor operates under its own privacy policy. We do not share data beyond what is strictly required to operate the Service. We do not use advertising networks, analytics platforms, or data brokers.
7. Security
Security measures in place:
- TLS encryption for all data in transit
- AES-256 encryption for files at rest
- bcrypt (cost 12) for all password hashes
- JWT with short-lived access tokens (15 min) and rotated refresh tokens
- Workers run in egress-disabled sandboxes — no outbound network access
- Magic-byte file validation before processing
- Rate limiting on all endpoints
- Security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options
To report a security vulnerability: security@hugmytools.com. We respond within 24 hours and follow responsible disclosure.
8. Your Rights
Depending on where you are located, you have some or all of the following rights regarding your personal data:
- Access: request a copy of data we hold about you
- Correction / Rectification: update inaccurate account information (directly via Settings, or by emailing us)
- Deletion / Erasure: delete your account and all associated data (via Settings → Danger Zone, or by request)
- Portability: export your account data in a machine-readable format (JSON)
- Restriction: request that we limit processing of your data pending a dispute
- Objection: object to processing based on legitimate interests
- Withdraw consent: where processing is based on consent, withdraw it at any time
EU/EEA users (GDPR): You also have the right to lodge a complaint with your national data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
Canadian users (PIPEDA / Quebec Law 25): You may request access to and correction of your personal information. We have designated privacy@hugmytools.com as our Privacy Officer. You may also file a complaint with the Office of the Privacy Commissioner of Canada (OPC) or, for Quebec residents, the Commission d'accès à l'information (CAI).
California users (CCPA/CPRA): You have the right to know what personal information we collect about you, the right to delete it, and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information with third parties for advertising or cross-context behavioral advertising. To exercise your rights, email privacy@hugmytools.com. We will not discriminate against you for exercising these rights.
To exercise any right, email privacy@hugmytools.com. We respond within 30 days (45 days for CCPA where an extension applies).
9. Children (COPPA)
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such data, we will delete it without delay.
For EU/EEA users, the minimum age for consent is 16 years. Users between 13 and 16 in the EU/EEA must have verifiable parental consent before using the Service.
If you are a parent or guardian and believe your child has used the Service without authorization, contact privacy@hugmytools.com and we will take immediate action.
10. Data Breach Notification
In the event of a data breach that is likely to result in risk to individuals, we will notify affected users and relevant supervisory authorities as required by applicable law:
- EU/EEA (GDPR): We will notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach. Affected users will be notified without undue delay where the breach is likely to result in high risk.
- Canada (PIPEDA / Quebec Law 25): We will report breaches posing real risk of significant harm to the Office of the Privacy Commissioner (OPC) and notify affected individuals as soon as feasible.
- Other jurisdictions: We will comply with applicable state and national breach notification laws.
Security incidents can be reported to security@hugmytools.com. We acknowledge reports within 24 hours.
11. Email Communications (CAN-SPAM / CASL)
We only send emails you have explicitly requested or that are necessary to operate your account (transactional emails: email verification, password reset, billing receipts, service notices).
We do not send unsolicited marketing emails. If you receive a promotional communication from us in the future, it will include an unsubscribe link. Canadian users: we comply with CASL and will only send commercial electronic messages with your express or implied consent.
To opt out of any email communication, use the unsubscribe link in the email or contact privacy@hugmytools.com.
12. Changes to This Policy
We will notify registered users by email of material changes at least 14 days before they take effect. The "Last updated" date at the top of this page will always reflect the current version. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact & Privacy Officer
Privacy inquiries and rights requests: privacy@hugmytools.com
General contact: Contact page
Security reports: security@hugmytools.com