Privacy Policy

1. Data we collect

  • Account data — when you create an account: your email address and a securely hashed password. Required only for the paid features; the free generator works without an account.
  • Project data — the project configuration you enter (metadata, resources, relations, options) to generate your project and, for paid generations, to let you re-download it later.
  • Technical data — your IP address and a browser fingerprint, used to enforce the free usage quota and to protect the Service against abuse.
  • Payment data — handled by Stripe. We never receive or store your card details; we only keep a payment/subscription reference and your credit balance.
  • Usage & analytics — anonymous usage and funnel metrics via Google Analytics 4, only if you accept analytics cookies.
  • Feedback — if you voluntarily submit the feedback or bug-report form (Tally): your message and any contact detail you choose to provide.
  • Error reports — when an unexpected error occurs, a technical report (error message, stack trace, page URL, browser) is sent to help us fix it. It is scrubbed of credentials and contains no form content, and is only sent with your consent.

2. Why we process it and on what legal basis

  • Providing the Service (generation, account, downloads) — performance of a contract.
  • Billing and fraud/abuse prevention (payments, quota, captcha) — contract and our legitimate interest in a secure, sustainable service.
  • Analytics, feedback and error reporting — your consent, which you can withdraw at any time.
  • Transactional emails (email verification, purchase confirmation, renewal reminders) — performance of a contract.

3. Cookies and consent

We use a strictly necessary cookie to remember your cookie choice, and — only after you click “Accept” on the banner — analytics cookies (Google Analytics 4) and the Tally feedback widget. If you decline, no analytics or feedback third party is loaded and nothing is tracked. You can change your mind at any time by clearing the site data in your browser.

4. Service providers (processors)

We share data only with the providers needed to run the Service:

ProviderPurposeData
OVHHosting (EU)All application data
StripePayments & subscriptionsPayment details, email
Google Analytics 4Usage analytics (consent)Usage events, pseudonymous identifiers
TallyFeedback & bug forms (consent, EU-hosted)What you submit
Friendly CaptchaBot protectionTechnical signals
ResendTransactional emailEmail address
GrafanaError monitoringScrubbed technical error logs

Some providers (e.g. Google, Stripe) may process data outside the European Union; where they do, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.

5. Data retention

We keep account and billing data for as long as your account exists and as required by law (e.g. accounting obligations). Generation payloads tied to paid downloads are kept for the duration of the re-download link and then deleted. Analytics data follows the retention configured in Google Analytics. You can request deletion of your account and associated data at any time (see below).

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. To exercise these rights, email support@springboot-generator.com. You also have the right to lodge a complaint with your supervisory authority (in France, the CNIL).

7. Security

We use TLS in transit, hashed passwords, scoped access tokens and least-privilege operator access. No system is perfectly secure, but we take reasonable measures to protect your data.

8. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you.