Privacy Policy
The short version. You can use the editor without an account, and your code then stays in your browser. If you create an account, we store your email, a securely hashed password and the projects you choose to save. We use a single essential cookie to keep you signed in. No ads, no analytics trackers, and we never sell your data.
- Who we are
- What we collect
- How we use it
- Legal bases
- Cookies and local storage
- Who we share it with
- International transfers
- Retention
- Security
- Your rights
- Children
- Changes
- Contact
1. Who we are
Adamant JS Compiler (the "Service") is provided by Adamant ("Adamant", "we", "us"). Adamant is responsible for the personal data processed through the Service. This policy explains what we collect, why, and the choices you have. It should be read together with our Terms of Service.
2. What we collect
2.1 If you use the editor without an account
- Your code and preferences stay on your device. The editor saves your code, file name, theme and layout settings in your browser's local storage. We do not receive them.
- Share links. A share link carries your code in the part of the address after the "#" sign. Browsers do not send that part to our servers when the link is opened, so we do not see the code in shared links. Anyone you give the link to, and any app where you paste it, can.
- Technical request data. Like any website, our servers and our hosting provider receive technical information with each request, such as your IP address, browser type, the page requested, the time and error details. We use it to deliver the Service, keep it secure and fix problems.
2.2 If you create an account
| Data | Why |
|---|---|
| Email address | To identify your account, let you sign in, and contact you about your account or important changes. |
| Password | Stored only as a salted, one-way PBKDF2-SHA-256 hash. We never store or see your actual password. |
| Saved projects (name, code, size and dates) | To store the projects you choose to save and show them back to you. |
| Account dates, accepted Terms version, failed sign-in counter | To run the account, record your acceptance of the Terms, and protect your account from password guessing. |
| Session records | A hashed session identifier with its creation, last-use and expiry times, so you stay signed in. |
2.3 Abuse prevention
To enforce fair use limits, we keep short-lived counters keyed by IP address and, for sign-in and password reset, by a one-way hash of the email entered. If a verification check (Cloudflare Turnstile) is enabled on sign-up, Cloudflare processes signals from your browser to tell people from bots, under its own privacy notice.
2.4 What we do not collect
We do not use advertising, analytics or social media trackers, we do not build profiles about you, and we do not sell or rent personal data. Please do not put personal or sensitive information in your code or project names.
3. How we use it
- To provide the Service: run the editor, create and secure accounts, save and return your projects, and send password reset emails you ask for.
- To keep the Service safe: detect and prevent abuse, fraud, attacks and violations of our Terms, and enforce limits.
- To maintain and improve the Service: troubleshoot errors and understand reliability issues from technical logs.
- To communicate with you: respond to requests and send important notices about your account, security or changes to our Terms or this policy. We do not send marketing email.
- To comply with the law and protect rights: respond to valid legal requests and establish, exercise or defend legal claims.
4. Legal bases
We process personal data with your consent, which you give when you create an account and accept this policy and can withdraw at any time by deleting your account; because it is necessary to provide the Service you request; for our legitimate interests in keeping the Service secure, available and free of abuse, balanced against your rights; and to comply with legal obligations. Where the Costa Rican Law on the Protection of Individuals Regarding the Processing of Their Personal Data (Law No. 8968) applies, your account registration constitutes your informed consent to the processing described in this policy.
5. Cookies and local storage
- Session cookie. When you sign in, we set one essential cookie that keeps you signed in for up to 30 days. It is HttpOnly and SameSite=Strict, so scripts and other websites cannot read or send it. It is removed when you sign out. Without it, accounts cannot work.
- Local storage. The editor stores your code and settings in your browser so your work survives a reload. This data stays on your device. You can clear it at any time from your browser settings.
- Offline cache. The Service may store its own files in your browser so it loads faster and works offline.
We do not use cookies for advertising or analytics, so we do not show a cookie consent banner.
6. Who we share it with
We share personal data only as needed to run the Service, with service providers that process it on our behalf and under confidentiality and data protection terms:
- Cloudflare, Inc. hosts the Service, its database and its security features, and processes request data across its global network.
- An email delivery provider (such as Resend) sends password reset emails if you ask for one.
We may also disclose information if required by law or a valid legal process, to protect the rights, safety or property of Adamant, our users or others, or as part of a merger, acquisition or transfer of the Service, in which case this policy continues to apply to your data.
7. International transfers
Our providers operate in many countries, including the United States. Your data may be processed outside your country, where data protection laws may differ. When we transfer data, we rely on our providers' contractual safeguards, such as standard contractual clauses where applicable, to protect it.
8. Retention
| Data | How long |
|---|---|
| Account data and saved projects | Until you delete them or your account. Accounts inactive for more than 24 months may be deleted after notice to the account email. |
| Deleted data in provider backups | Removed from backups in the normal course, generally within 30 days. |
| Sessions | Up to 30 days after last use, or until you sign out or change your password. |
| Password reset links | 30 minutes, and they work only once. |
| Rate-limit counters | Usually minutes to an hour, and deleted by an automatic daily cleanup. |
| Technical request logs | A short period, typically a few days, unless needed longer to investigate abuse or a security incident. |
We may keep information longer where the law requires it or to establish, exercise or defend legal claims.
9. Security
We protect data with measures including encrypted connections (HTTPS with HSTS), salted password hashing, hashed session and reset tokens, HttpOnly and SameSite cookies, request origin checks, rate limiting and account lockout after repeated failed sign-ins, and an isolated sandbox that keeps code you run away from your account. No system is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the authorities as required by law.
10. Your rights
Depending on where you live, including under Costa Rica's Law No. 8968, the EU and UK GDPR, and US state privacy laws such as the California Consumer Privacy Act, you may have the right to:
- Access the personal data we hold about you, and receive it in a portable format. Use Export my data in the account menu, or ask us.
- Correct inaccurate data.
- Delete your data. Use Delete account in the account menu, which permanently removes your account and saved projects, or ask us.
- Object to or restrict certain processing, and withdraw consent at any time, without affecting processing done before.
- Not be discriminated against for exercising your rights. We do not sell or share personal data for cross-context behavioral advertising.
- Complain to a data protection authority, such as the Agencia de Protección de Datos de los Habitantes (PRODHAB) in Costa Rica or your local authority.
To make a request, write to info@valeriogroup.co from the email on your account. We may need to verify your identity, and we will respond within the time required by applicable law.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we will delete it.
12. Changes
We may update this policy. We will post the new version here with a new effective date and, if the changes are material, give reasonable notice in the Service or by email to account holders before they take effect.
13. Contact
Privacy questions and requests: info@valeriogroup.co.