Privacy Policy
Last updated: 3 September 2026
This policy describes diskpast.com and the DiskPast Windows application (GUI, service, and CLI). Contact: legal@diskpast.com. It describes what we actually collect. It is not a GDPR, CCPA, or “certified” privacy badge.
Polar Software, Inc. is merchant of record for the purchase. Polar’s identity appears on the tax receipt. Polar’s privacy notice covers card, tax, and checkout data Polar collects. DiskPast does not take the card.
Who we are
For website accounts, license keys, and activation, DiskPast is the controller of the data listed below. Until a legal entity name and postal address are published here, contact is email only. Polar is the controller (or joint controller, as Polar describes) of payment data collected at Polar Checkout.
Disk history stays on your PC
File history, NTFS USN journal data, paths, folder contents, process names, and storage maps stay on the Windows PC. DiskPast does not upload your disk to diskpast.com. We cannot see your files from this site.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email; display name and Google account id if you use Google OAuth; password hash if you create a password (held by Supabase, not in plaintext on DiskPast) | Sign-in, show the key, seats |
| Purchase | Polar order id, Polar checkout id, Polar customer id, purchaser email Polar sends us, license key we mint | Prove payment, show the key, refunds |
| Activation | License key (or its hash), hashed device id (SHA-256 of a Windows machine id, not the raw MachineGuid), last seen time, HMAC JWT we issue | One PC seat, refresh, revoke |
| Site use | IP address and standard request logs on Cloudflare; theme preference in the browser | Run the site, abuse rate-limits, remember theme |
Signing into the website does not activate a PC and does not charge a card. The Windows app never uses Google or your site password; it pastes a key.
Processors
| Who | Role |
|---|---|
| Polar Software, Inc. and Polar’s payment processor | Checkout, tax, receipt, refunds, chargebacks. Card data never hits diskpast.com. See Polar Buyer Terms. |
| Supabase | Auth (Google or email) and license / activation rows |
| Optional OAuth. Google’s terms apply to that sign-in path | |
| Cloudflare | DNS, TLS, hosting of diskpast.com and API workers |
Those providers may process data outside your country. We do not run advertising pixels or a marketing-mail list in v1.
Legal bases (where that language applies)
Contract: delivering the license, account, and activation you asked for. Legitimate interests: securing the APIs, attaching a license when Polar’s email matches yours, keeping seats honest. Consent: optional Google sign-in and optional marketing we do not run today. Polar relies on Polar’s own bases for the payment.
License attachment
When Polar’s purchaser email matches a signed-in email (case-insensitive), we attach the license row so you can see the key on /account. If the emails differ, the key still appeared on checkout success; sign in with the Polar email or contact support.
Retention
License and activation rows last as long as we need them to honor the seat, move a PC, and process refunds or chargebacks. You may delete the website account from /account; that does not refund Polar and does not by itself delete Polar’s payment records. Auth sessions follow Supabase’s defaults. Polar retains payment records under Polar’s policy.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export account data, or to object to certain processing. Email legal@diskpast.com. You can delete the site account on /account. We do not sell personal information and we do not share it for cross-context behavioral advertising.
We do not knowingly collect personal information from children under 13. Do not create an account or buy DiskPast for that age group.
Security
TLS on diskpast.com. License tokens are HMAC JWTs; the Windows service stores the token blob, not Polar’s card data. Report vulnerabilities to security@diskpast.com (see /security.txt).
Changes
We will post a new “Last updated” date on this page when the policy changes. Material changes that affect how we use account data will also be noted on /legal.