Privacy

Privacy Policy

A plain-language description of the account, bytecode, API, billing, and support data PyDecode processes—and the choices available to you.

Last updated August 6, 2026Questions? Contact support
On this page12 sections
01

Scope and contact

This Privacy Policy explains how the PyDecode operator (“PyDecode,” “we,” or “us”) handles personal information when you use the website, dashboard, recovery engine, REST API, MCP server, billing, and support channels.

PyDecode determines how account and service information is processed. Privacy questions and requests may be sent to playsharp@playsharp.io.

02

Information we collect

Depending on how you use the Service, we process:

  • Account data: name, email address, password hash, account status, terms acceptance, and creation/update timestamps.
  • Authentication data: session tokens, expiry, approximate IP address, user agent, and active-session records.
  • Anonymous trial data: an essential random visitor cookie, lifetime upload count, job metadata, and keyed one-way hashes derived from network and basic browser signals. These hashes help enforce the free allowance without storing the raw IP address in the trial ledger.
  • Recovery data: uploaded .pyc or ZIP bytes, filenames, file and archive measurements, recovered source, audit bundles, errors, state events, and job timestamps.
  • API and MCP data: hashed API keys, non-secret key prefixes, labels, expiry and revocation dates, request counts, last use, request IDs, and idempotency identifiers.
  • Billing data: Stripe customer, checkout, price, and payment references; pack and credit quantities; amount, currency, status, and transaction timestamps. Stripe—not PyDecode—collects complete payment-card details.
  • Support and technical data: messages you send, diagnostic identifiers, pseudonymous Sentry error reports, server logs, append-only security and administrative audit events, and basic browser or device information needed to troubleshoot and protect the Service.
  • Transactional email data: recipient address, message category, delivery status and provider reference, retry history, notification preferences, and one-way hashes of short-lived verification codes.
03

How we use information

  • create and secure accounts, sessions, API keys, and MCP access;
  • validate uploads and provide static source recovery;
  • calculate, reserve, charge, adjust, and refund service credits;
  • process purchases and reconcile signed Stripe events;
  • operate support, investigate failures, and improve reliability;
  • detect abuse, fraud, security incidents, and policy violations;
  • comply with law and enforce our agreements; and
  • send password codes, new-login alerts, payment confirmations, credit-expiry reminders, and important service or policy notices.
05

How information is shared

We may share limited information with:

  • Stripe to create checkout sessions, grant purchased credits, reconcile transactions, and provide the billing portal;
  • Fly.io and infrastructure providers that host the application, network, persistent storage, and operational logs;
  • Resend to deliver transactional account, security, credit, and payment emails;
  • Sentry to detect application errors and reliability regressions without intentionally sending uploaded source, file contents, passwords, tokens, or raw IP addresses;
  • professional advisers or authorities when reasonably necessary to comply with law, prevent harm, or protect rights; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice obligations.

We do not sell personal information and do not use uploaded bytecode or recovered source for behavioral advertising.

06

Retention and deletion

Uploaded input, recovered source, and audit bundles are private service artifacts scheduled to expire after the period displayed by the Service, currently 12 hours. Operational deletion may take a short time to complete across active systems.

When recovery fails, a separate copy of the failed input and a bounded technical error log may be retained for up to 30 daysso authorized administrators can reproduce the failure and add engine support. These artifacts are access-controlled, never sent to Sentry, and may be purged earlier. Verified account deletion purges retained failed-file copies associated with that account.

Account, session, job, credit-ledger, API-key, purchase, security, and support records are retained for as long as reasonably needed to operate accounts, maintain transaction integrity, prevent abuse, resolve disputes, and meet legal, tax, or accounting duties. Retention periods vary by record and applicable law.

You can revoke API keys and sessions, update optional email preferences, and request verified account deletion in the dashboard. Contact support for other personal-data requests. We may retain limited records where deletion is not legally required or would compromise security, fraud prevention, transaction records, or another person’s rights.

07

Cookies and local storage

PyDecode uses essential authentication cookies to keep you signed in and protect account requests. The public recovery trial uses an essential random visitor cookie to remember the three-file allowance and reduce repeat abuse. The site also uses local browser storage for preferences such as light or dark appearance. We do not currently operate third-party behavioral advertising on the Service.

Blocking essential cookies may prevent authentication, the free trial, and dashboard features from working.

08

Security

We use safeguards designed for the nature of the Service, including password hashing, hashed API-key storage, revocable sessions and keys, HTTPS, upload limits, isolated static processing, signed Stripe webhook verification, private account scoping, and short artifact retention.

No system is perfectly secure. Protect your credentials, remove unnecessary secrets from files before upload, and notify support if you identify a suspected incident.

09

Your privacy choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; to withdraw consent; or to appeal or complain to a data-protection authority. California residents may also have rights to know, correct, delete, and receive equal service when exercising applicable rights.

Send requests to playsharp@playsharp.io. We may need to verify your identity and authority before responding. Authorized agents may be asked for proof of authorization. We will not discriminate against you for exercising a right protected by law.

10

International processing

PyDecode and its providers may process information in countries other than where you live. Data-protection laws may differ. Where required, we use recognized safeguards for international transfers or rely on another lawful transfer mechanism.

11

Children

The Service is intended for adults and is not directed to children under 13. Our Terms require users to be at least 18 or the age of legal majority. If you believe a child provided personal information, contact us so we can investigate and take appropriate action.

12

Policy changes

We may update this Policy when practices, providers, or legal requirements change. The revised date will appear at the top, and we will provide additional notice when required.

For related rules, read the Terms of Service and Refund Policy.