Privacy Policy
How 13x handles personal data across the website, your account and billing. The desktop app is local-first and does not upload your code or send usage telemetry — see section 8.
1. Controller
Pascal Zagarolo, [street address], 42659 Solingen, Germany, support@get13x.dev, is the controller for the processing of personal data on this website and for the 13x account and billing services.
We have not appointed a data protection officer; for any data protection request, contact support@get13x.dev.
2. Hosting and technical provision
The website and its application/API are hosted on Vercel (Vercel Inc., USA, with infrastructure in the EU where available). When the site is accessed, technically necessary data is processed, for example IP address, date and time, requested URL, referrer, user agent and server log data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a secure, functioning service). Our database is hosted on Neon (Neon Inc.) and rate-limiting on Upstash (Upstash, Inc.). Where processing involves the USA, it is based on the providers' data processing agreements and EU standard contractual clauses / the EU–US Data Privacy Framework where applicable.
3. Accounts and authentication
To create a 13x account we process your email address and a salted password hash (Argon2; we never store the plaintext password). If you sign in with Google or GitHub (OAuth), we receive your email address and a provider account identifier from that provider to create or link your account.
We also store session tokens (as hashes), email-verification and password-reset tokens, and — if you enable two-factor authentication — an encrypted TOTP secret. Legal basis: Art. 6(1)(b) GDPR (performance of the contract / pre-contractual steps) and Art. 6(1)(f) for account security. Account data is retained for the life of the account and deleted on request, subject to legal retention duties.
4. Payments and subscriptions
Payments and subscriptions are processed by Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.). When you subscribe, you provide your payment and billing details directly to Stripe; we do not receive or store full card data. We store your Stripe customer and subscription identifiers, plan, status, billing period and trial dates to manage your subscription and entitlements.
Stripe also processes VAT/tax identifiers and billing address as required for invoicing. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (legal/tax obligations). See Stripe's privacy policy for its own processing.
5. Email communications
Transactional emails (email verification, password reset, billing and trial notices) are sent via Resend (Resend, Inc.). We process your email address and message metadata for delivery. Legal basis: Art. 6(1)(b) GDPR for transactional messages.
6. Waitlist and notifications
When you join the waitlist or ask to be notified about a plan, we store the email address (and the selected tool, if provided) in our database to inform you about availability and product updates. Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) for a pre-contractual request. You can withdraw at any time by emailing support@get13x.dev; we then delete the entry.
7. Analytics and cookies
We use Vercel Web Analytics, a privacy-friendly, cookieless analytics service that measures aggregate page views and performance without storing personal profiles or tracking you across sites. It does not set advertising or cross-site cookies. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding aggregate usage).
We set only technically necessary cookies (for example a session cookie after sign-in). If we introduce any non-essential cookies or tracking in future, we will request your consent beforehand.
8. The desktop application and your code
The 13x desktop application is local-first. Code mapping, symbol graphs, context packets, rigs and run/trace data are generated and stored on your device. We do not upload your source code, terminal output or local project data to our servers, and the app contains no usage telemetry.
The desktop app contacts our update endpoint to check for new versions (which may involve your IP address as a normal part of the HTTPS request) and, if you sign in for Pro, exchanges authentication and subscription-status data with our account services as described above. API keys you enter for third-party model providers ("bring your own key") are stored locally on your device (operating-system keychain) and are sent only to the provider you choose.
9. Recipients and third-country transfers
Recipients are the processors named above: Vercel (hosting, analytics), Neon (database), Upstash (rate limiting), Stripe (payments), Resend (email), and the OAuth providers you choose (Google, GitHub). Each acts under a data processing agreement with us where it processes data on our behalf.
Some providers are based in or transfer data to the USA. Such transfers rely on EU standard contractual clauses and/or the EU–US Data Privacy Framework, together with the providers' supplementary safeguards.
10. Rights of data subjects
Within the limits of the law, you may request access, rectification, erasure, restriction of processing, data portability and objection, and may withdraw consent with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority (in Germany, typically the authority of your state of residence). Contact for data protection requests: support@get13x.dev.
11. Status and changes
Last updated: [enter date before publishing]. We update this policy whenever our processing, providers, analytics, payment handling or communication channels change.