# Privacy Policy

> What Talarius stores, why it stores it, and how that data is handled.

Effective August 28, 2026 · Last updated August 28, 2026

## Controller and data protection contact

vcraft Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422, is the controller for Talarius. Email [contact@talarius.io](mailto:contact@talarius.io) for privacy questions or requests.

## Information, sources, and required data

Talarius receives the following categories of information:

- Account and authentication details supplied by you or GitHub.
- Project, receiver, alert, heartbeat, delivery, and usage metadata created when you use Talarius.
- Device registration and delivery metadata from paired devices, Apple/APNs, and Google/Firebase/FCM.
- Stripe customer, checkout, transaction, refund, and dispute references.
- Security and abuse-control information, including IP-derived rate-limit state and hashed abuse-control subjects.
- Support messages and the minimum account or payment identifiers needed to help.

Authentication, project configuration, delivery metadata, and billing details are required to provide the related service. Do not include secrets, credentials, personal, confidential, regulated, or other sensitive information in notifications or free-form support content. A support request may include only the minimum account or payment identifiers Talarius explicitly requests.

## Purposes and legal bases

We process data to authenticate users, perform the service contract, deliver and meter alerts, secure Talarius, prevent abuse, provide support, reconcile payments, improve reliability, and meet tax and other legal obligations. Where the GDPR applies, these purposes rely on contract, legitimate interests in security and reliable operation, and legal obligations; consent is used only where specifically requested.

Talarius does not sell personal data and does not use it for third-party advertising, profiling, or automated decisions with legal or similarly significant effects.

## Retention and inactive accounts

Talarius persists service data only for as long as necessary for essential operations and legal obligations. Identifiable customer Usage metadata is kept for 13 calendar months. Revoked configuration is normally removed after 30 days. Daily business totals are retained for 25 months and may then be compacted into permanent monthly totals only after they pass a re-identification assessment and are anonymous. Accounts inactive for 24 months are scheduled for deletion after attempted warnings 30 days and 7 days beforehand. Failed or expired checkout attempts are retained for 13 months. Minimum pseudonymous financial records follow the applicable tax, refund, dispute, and legal-hold schedule.

## Deletion, backups, and phone history

Account deletion immediately blocks access and delivery, deletes operational identity and configuration, and commits retryable live-store cleanup that completes within 24 hours. Encrypted deployment backups expire within 35 days, and deletion is reapplied before restored service can become ready. Notification history on a paired phone remains until it is deleted locally. Talarius does not sync or remotely erase that history. On iOS, local history and credentials are excluded from iCloud backup where the platform supports that control. On Android, local history stored with Room, preferences stored with DataStore, and credentials protected with the system Keystore are excluded from backup or device transfer where the platform supports that control.

## Essential cookies

Talarius uses HTTP-only essential cookies only: Dashboard session — 30 days; GitHub OAuth state and CSRF protection — 10 minutes; Magic-link confirmation staging — at most 5 minutes or the link’s remaining life; Browser virtual-device session — 30 days. Talarius sets no advertising or analytics cookies.

## Providers and international transfers

Talarius uses service providers only for the purposes described in this policy:

- Hosting and encrypted backup providers for service operation and recovery.
- Cloudflare for network delivery, security, and abuse prevention.
- GitHub for optional account authentication.
- AhaSend for transactional email; open and click tracking is disabled.
- Apple/APNs and Google/Firebase/FCM for paired-phone notification delivery.
- Stripe for checkout, payment, refund, and dispute processing.
- The support mailbox for messages you choose to send.

These providers may process information in countries other than your own. Where applicable law requires it, a recognized transfer safeguard intended to provide comparable protection is used.

## Security

Talarius uses reasonable technical and organizational safeguards appropriate to the service, including access controls, scoped credentials, transport encryption, encrypted deployment backups, request limits, and security monitoring. No method of storage or transmission is completely secure.

## Your rights and complaints

Email contact@talarius.io to request access, portability, correction, restriction, objection, or deletion. We use fresh Talarius authentication or the minimum payment evidence necessary to verify a request and respond without undue delay, within 30 calendar days or earlier where applicable law requires. Some rights depend on the applicable law and financial or legal records may need to remain pseudonymously until their deadline. You may complain to Singapore’s Personal Data Protection Commission or the competent supervisory authority where you live. We will explain any refusal or delay and the available escalation route.

## Children

Talarius web accounts and purchases are for people who have reached the age of majority where they live. A phone used only as a paired receiver may be supervised by an adult account holder. Talarius is not directed to children and we do not knowingly collect personal information from a child through a web account.

## Changes to this policy

We may update this policy as Talarius or applicable law changes. We will post the revised policy here, update the date above, and provide reasonable advance notice of material changes when practicable. Continued use after a change takes effect is subject to the revised policy. You can stop using Talarius and [delete your account](https://talarius.io/app/account) if you do not accept a change.

## Canonical resources

- [Human-readable page](https://talarius.io/privacy)
- [Talarius documentation](https://talarius.io/docs/index.md)
- [llms.txt](https://talarius.io/llms.txt)
