← Back to Talarius

Privacy Policy

How Talarius collects, uses, protects, and retains service data.

Effective August 3, 2026

Controller and data-protection contact

vcraft.sg in Singapore is the controller for Talarius. [email protected] is the published business contact for the designated data protection officer. Contact us there for privacy questions or requests.

Information, sources, and required data

We receive account and authentication details from you and GitHub; project, receiver, alert, heartbeat, and Usage metadata from your use of Talarius; device registration metadata from paired devices and Apple; and transaction references from Stripe. Authentication, project configuration, delivery metadata, and billing details are required to provide the requested service. Without them, the related account, delivery, receiver, or purchase cannot operate. Do not include secrets, credentials, personal, confidential, regulated, or other sensitive information in notification or free-form support content. A support request may include only the minimum account or payment identifiers Talarius explicitly requests.

Purposes and legal bases

We process data to authenticate users, perform the service contract, deliver and meter alerts, secure the service, prevent abuse, provide support, reconcile payments, improve reliability, and meet tax and other legal obligations. Under the GDPR, these purposes rely on contract, legitimate interests in security and reliable operation, and legal obligations; consent is used only where specifically requested. Talarius does not use personal data for advertising, profiling, or automated decisions with legal or similarly significant effects.

Retention and inactive accounts

Talarius persists service data only for as long as necessary for essential operations and legal obligations. Identifiable customer Usage metadata is kept for 13 calendar months. Revoked configuration is normally removed after 30 days. Daily business totals are retained for 25 months and may then be compacted into permanent monthly totals only after they pass a re-identification assessment and are anonymous. Accounts inactive for 24 months are scheduled for deletion after attempted warnings 30 days and 7 days beforehand. Failed or expired checkout attempts are retained for 13 months. Minimum pseudonymous financial records follow the applicable tax, refund, dispute, and legal-hold schedule.

Deletion, backups, and iPhone history

Account deletion immediately blocks access and delivery, deletes operational identity and configuration, and commits retryable live-store cleanup that completes within 24 hours. Encrypted deployment backups expire within 35 days, and deletion is reapplied before restored service can become ready. Notification history on a paired iPhone remains on that iPhone until it is deleted locally. Talarius does not sync or remotely erase that history, and new local history is marked for exclusion from device backup.

Essential cookies

Talarius uses HTTP-only essential cookies only: Dashboard session — 30 days; GitHub OAuth state and CSRF protection — 10 minutes; Magic-link confirmation staging — at most 5 minutes or the link’s remaining life; Browser virtual-device session — 30 days. Talarius sets no advertising or analytics cookies.

Providers and international transfers

Talarius uses hosting and backup providers, Cloudflare, GitHub, AhaSend, Apple/APNs, Stripe, and the support mailbox only for the service purposes described above. AhaSend open and click tracking is disabled. Third-party processing and retention follow each provider's terms and applicable operational, security, and legal lifecycle. Provider regions, data-processing terms, deletion controls, and any required international-transfer safeguard must be reviewed before paid launch.

Your rights and complaints

Email [email protected] to request access, portability, correction, restriction, objection, or deletion. We use fresh Talarius authentication or the minimum payment evidence necessary to verify a request and respond without undue delay, within 30 calendar days or earlier where applicable law requires. Some rights depend on the applicable law and financial or legal records may need to remain pseudonymously until their deadline. You may complain to Singapore’s Personal Data Protection Commission or the competent supervisory authority where you live. We will explain any refusal or delay and the available escalation route.