Privacy Policy

1. Who we are

Rendarium operates rendarium.com, the hosted API at api.rendarium.com and the portal at app.rendarium.com. For questions about this policy or your data write to support@rendarium.com.

2. What we collect

Account data — email address, a salted hash of your password (never the password), plan, role and timestamps. API keys — only a SHA-256 hash and a 12-character display prefix; the key itself is shown once and never stored. Usage data — for every API request: time, operation, key label, status, duration and error code; this is what your dashboard and credit ledger are built from. Support correspondence — the emails you send us. Server logs — IP address, user agent and request path, retained for security for up to 30 days.

3. What we do not collect

We do not store the documents you convert. Input HTML, files and generated PDFs or images exist in memory only for the duration of the request. The marketing website sets no cookies and uses no analytics or advertising trackers.

4. Why we process it

To provide the Service and account access (performance of contract); to bill and to keep a verifiable credit ledger (contract, legal obligation); to keep the Service secure, including rate limiting and abuse prevention (legitimate interest); and to answer your requests (legitimate interest). We send transactional emails only: confirmation, password reset, license delivery, usage warnings and important service notices.

5. Where data is processed

Documents are processed in the European Union. Account and usage data is stored on servers in the EU. Payment data is collected and processed by FastSpring, our merchant of record, under its own privacy policy; we receive order details (name, email, product, amount) but never card numbers.

6. Retention

Account and ledger data is kept for as long as your account exists and for 90 days after deletion, then erased; invoicing records held by our merchant of record are kept as required by tax law. Detailed per-request rows are retained for 13 months and then reduced to daily aggregates.

7. Cookies

The portal sets exactly two cookies: a session cookie (HttpOnly, Secure, SameSite=Lax) and an anti-forgery token cookie. Both are strictly necessary; no consent banner is required and no third-party cookies are set. The marketing website sets none.

8. Your rights

Under the GDPR and similar laws you may request access to, correction, export or deletion of your personal data, object to processing based on legitimate interest, and lodge a complaint with your supervisory authority. Most operations are self-service in the portal (change password, delete account); for anything else, email support@rendarium.com and we answer within 30 days.

9. Security

Passwords are hashed with PBKDF2; API keys and email tokens are stored only as hashes; license keys are encrypted at rest; all traffic is TLS-only; access to production systems is restricted and logged.

10. Changes

We may update this policy; the date at the top changes and material changes are announced in the portal.