ยังไม่มีหน้านี้ในภาษาของคุณ คุณกำลังอ่านข้อความภาษาอังกฤษ
Legal
Privacy Policy
Edition 1, in force since 5 October 2026
Who is responsible for your data
The operator of ARMANOS decides why and how your data is used. The operator's legal name will appear on the Company and contact page; until then, reach us through the form at armanos.io/support.
What we collect
The table names each kind of data and where it comes from. The whole list, field by field, is on the What the server holds page.
Every sign-in is recorded with its time and the IP address it came from, and with its country when our network provider reports one. The entry lands in the History of one workspace, the one the sign-in opens: your Default workspace, else the first team you joined, else your own. Its owner and admins see it there, and so do scripts they give a key to read History.
Sessions of a login that belongs to a team, with their IP addresses, are also seen by the owner of that team and by its admins for logins with a lower role, under Team.
| What | Example | Where it comes from |
|---|---|---|
| Your account | email, password hash, language, plan | you, when you sign up |
| Sign-ins | time, IP address, country if reported | each sign-in and each new device |
| Profiles and workspace | profile settings, proxies, notes, team | the app and the site, when you save them |
| Plan and payments | your plan and its end date; the amount, currency, date and method of a payment | the payment service, or us when a plan is paid by letter and we record the payment |
| Support | the email you gave, the text, a machine description | the form, on the site or in the app |
What we do not collect
Your cookies, your sign-ins to other sites and what you browse do not reach our server. The server keeps the template and the seed a profile's fingerprint is worked out from; the values themselves are worked out on your computer and are not sent.
We do not sell your data, we show no advertising, and there are no analytics counters on the site or in the app.
Why we use it
To run your account and your plan, to carry your profiles between your computers and your team, and to answer your messages.
And to keep accounts safe: the History shows sign-ins, so the owner of a workspace can spot one that is not theirs.
Who else handles it
Our hosting provider runs the server and the database. Every service we send data to, and which of them see your own address, is on the Third-party services page.
One road is not ours. The owner of a workspace can set up Event calls (webhooks): then the events of that workspace go to an address the owner chose, on their own server.
They carry changes to profiles, proxies, API keys and the plan, the email of a colleague who was invited or removed, and for an accepted profile transfer the emails of both sides. Invitation codes, links and secrets are left out.
How long we keep it
The same table is shown on the What the server holds page. Where the server does not delete something, the row says so.
| What | Where | How long |
|---|---|---|
| Your account: email, password hash, language, plan, the devices you signed in from, the two-step secret, who invited you | Our server | While the account exists; erased 3 days after you ask to delete it on your account page. |
| Sign-ins: time, IP address, and the country when our network provider reports one | Our server, under History | While the account exists, and until then the server deletes no History row. When the account is erased, its sign-ins go with it, from other workspaces' History as well. |
| Sign-in keys and API keys, kept as a hash (an API key also by its short prefix) | Our server | A sign-in key works for 30 days, an API key until you revoke it or its end date passes. The records stay while the account exists. |
| Sign-in sessions: app or browser, computer name, system, app version, IP address and the country when our network provider reports one | Our server, on your Account page | While the session is open and 90 days after it ends |
| Links in our letters | Our server | Confirming an address: 24 hours. Resetting a password: 1 hour. Joining a team: 7 days. |
| Profiles and their settings, groups, statuses, who a profile is shared with, sync reports, wrong profile password counters | Our server | Until you delete them. A profile leaves the server when you delete it permanently; the recycle bin does not empty itself. |
| Flows and their steps, schedules, webhook addresses and secrets, creatives (a text, or the path to a file on your disk: the file itself is not uploaded) | Our server | Until you delete them. |
| Your team: members and their roles, invitations, team bookmarks, workspace settings | Our server | A member's record stays while they are in the team; the rest until you change or delete it. |
| Saved proxies, with the password and the IP change link | Our server | Until you delete the proxy. |
| Workspace History: who did what, in which workspace, when, and a few details | Our server, under History | While the account of the workspace owner exists, and until then the server deletes no History row. |
| Messages to support: the email you gave, the subject, the text, your plan at the time, and a description of the machine when sent from the app | Our server | 2 years after our last answer, with the email you gave, also after the account is deleted. |
| Our letters to you: the address, the subject and the whole text | Our server | With the account; a letter to someone without an account is erased 2 years after it was written. |
| Payments and subscriptions, with refunds and disputes, and proxy orders | Our server | No time limit: the server does not delete them, and after the account is deleted they stay without your email. The period the law requires will be named together with the operator. |
| Profile transfers: the emails of both sides, the profiles, the exit country, and the sealed key of the session file | Our server | 48 hours to answer. The key of an accepted file waits 7 days and is then erased. The record stays until the account of either side is erased. |
| Cookies, sign-ins to sites, browsing data | Only your disk | Not on our server. On your disk until you delete the profile permanently. |
Your rights
You can ask for a copy of what we hold about you or ask us to correct it. Sign in, open the form at armanos.io/support and pick Your data: without signing in the form does not offer it, because the request has to come from the account it is about.
A request sent while signed in is tied to your account, and our answer appears under Your requests on your account page. We answer within 30 days. You can delete your account yourself from your account page.
Age
ARMANOS is for people aged 18 and over. If we learn that an account belongs to someone younger, we delete it.
How it is protected
Passwords are kept as hashes. Proxy passwords, IP change links, two-step secrets, webhook secrets and the keys of profile transfers are sealed with a server key before they are stored.
API keys are kept as a hash and a short prefix.
Changes
We change this policy the same way as the Terms of Service: date and edition at the top, all editions at the bottom, and 30 days' notice for a change that takes something from you, except changes the law or the safety of the service requires.
Contact
Write to us through the form at armanos.io/support. Who runs ARMANOS is on the Company and contact page.
What this page does not cover
- It does not name the region where our hosting keeps the database, or how long its copies are kept. Neither is stated here yet.
- It does not give a legal basis for each use of data. That column is written by a lawyer and will come as a new edition.
- It does not cover what a site you open through a profile learns about you. That is theirs, and nothing here reaches it.
- It is not legal advice and does not claim compliance with any regime by name.
Where this is decided
Each line is a file you can open.
- Your cookies and site sign-ins do not leave the machine, checked by running the app
- apps/desktop/test/login-stays-local.js
- What the server holds and for how long, checked against the schema
- apps/web/content/право/хранение.json · apps/server/test/право-схема-и-страница.js
- Who may read the sign-in History
- apps/server/src/logs/logs.controller.ts
- How secrets are sealed, the road without a key, and older values sealed when the server starts, checked by running the code
- apps/server/src/common/crypto/secret-box.ts · apps/server/src/common/crypto/закрыть-старые-секреты.ts · apps/web/test/право-секреты-без-оговорки.js
Questions
- Do you sell my data?
- No. We show no advertising and pass nothing to advertisers; the services that do see some of it are named on the Third-party services page.
- Do you count visits to the site or use of the app?
- No. There are no analytics counters on the site or in the app, and the site sets one cookie, for the language you pick.
- Who in my team sees my sign-ins?
- The owner and the admins of the one workspace your sign-in opens, under History. Other members do not, and neither does any other team you are in.
- How do I get a copy of my data?
- Sign in, open the form and pick Your data. The answer appears under Your requests on your account page.
Editions of this document
- Edition 1, 5 October 2026: First edition.
A line here is unclear?
Write to us and quote it. A legal page is worth only as much as its least clear sentence.