Privacy Policy
Last updated: 16 July 2026
The short version: your video, audio, and snapshots live on your hardware and never touch our servers — Calyston is built so that we couldn't watch your cameras even if we wanted to. What little we do process is listed on this page, completely.
1. What the software sends us
A licensed installation periodically checks in with our license server. Each check-in contains, in full:
| Field | Why |
|---|---|
| Your license key | To confirm the license is valid |
| A hardware fingerprint (one-way hash) | To enforce one-machine-per-license. It's a hash — it can't be reversed into details about your machine |
| Software version & uptime | To know which versions are in use and stable |
| Camera count | To size our performance work (the number only — never names, models, addresses, or footage) |
| A crash flag & error class | To spot widespread problems (e.g. "DatabaseError" — no messages, no file paths) |
That's the entire list. No footage, no snapshots, no camera details, no user accounts, no IP addresses of anything on your network. There is no analytics or telemetry beyond it — this table is the whole of it. And because a check-in is a single ordinary HTTPS request, you can watch it leave on your own network and confirm there is nothing more to it.
One optional extra: if — and only if — you tick "Share device-type metrics" (off by default), the same check-in also carries three booleans: opened from a phone, opened from a desktop, installed as an app. They tell us whether to build a native mobile app, and nothing else. Untick it and the field disappears from the very next check-in, along with what was collected.
2. When you buy a license
Checkout is handled by Paddle, our merchant of record — your payment details go to Paddle, not to us, under Paddle's privacy policy. We receive and keep exactly two things: your email address and your license record. We use the email to deliver your key, send receipts, and — for subscriptions — remind you before expiry. No marketing lists, no sharing, no selling, ever.
3. Crash reports
If the software crashes, it can send us an anonymous crash report — scrubbed on your machine before sending, containing no identifiers of any kind, and sent to our error-reporting service (GlitchTip, hosted in the EU). There is nothing in a crash report that could be traced back to you.
4. This website
- No cookies, no analytics, no trackers. Your theme preference is kept in your own browser and never sent anywhere.
- Contact form — we receive your email address and message, use them to reply, and nothing else.
- Community key signup — we receive your email address and use it to send your free key (and nothing else, per section 2).
- Launch notifications — before Calyston is released, the signup form stores your email for exactly one purpose: a single message telling you we're live. If you signed up from the Founder card, we also store that one-word preference so your copy of that message goes out 24 hours earlier. No newsletter follows, and we remove it all on request.
- Survey — anonymous by design: your answers are stored with no IP address, no browser details, and no identifiers whatsoever.
5. Who processes data for us
The list is short, and we name everyone. Where a provider is US-based, transfers are safeguarded by the European Commission's Standard Contractual Clauses (and, where the provider is certified, the EU–US Data Privacy Framework).
- Paddle — merchant of record: checkout, payment, VAT and invoices, under their own privacy policy (section 2).
- Cloudflare (US) — runs our license server, this website and our download infrastructure; your license record (email + license) is stored there.
- Resend (US) — delivers our transactional email: your license key, receipts, and replies to the contact form.
- GlitchTip (error-reporting service, hosted in the EU) — receives the anonymous crash reports described in section 3; they contain no personal data by design.
Legal bases (GDPR art. 6): delivering your license, sending your key and answering support = performance of a contract; keeping purchase records = legal obligation; crash reports and the launch list = consent (both opt-in); protecting the license system against abuse = legitimate interest.
6. How long we keep things
License records (email + license) are kept for as long as your license exists, then as long as tax law requires for purchase records. Contact-form emails are kept only as long as the conversation needs. Anonymous data (crash reports, surveys) has nothing in it to delete on request — but we prune it routinely anyway.
7. Your rights (GDPR)
You can ask us at any time what we hold about you, ask us to correct it, or ask us to delete it (deleting your license record means the license can no longer be reactivated — we'll confirm before doing it). You also have the right to complain to your data-protection authority. For any of these, contact us or email [email protected] — the developer answers personally.
The data controller is Calyston Systems S.R.L., B-dul Dinicu Golescu, Nr. 7, Parter, Ap. SP. COM. 3, Sector 1, Bucharest, Romania (Trade Register No. J2026047335006, CUI 55334253).