Privacy Policy
Last updated: May 14, 2026
1. Who We Are
This Privacy Policy applies to Edo's Framework ("we", "us", or "our"). It explains what data we collect, how we use it, and your rights regarding it. If you have questions, contact us at edinmuhic@edosframework.com.
2. Data We Collect
- Google account data — your name, email address, and Google account ID, collected when you sign in via Google OAuth.
- Subscription data — your subscription status (trial / active / lapsed), billing dates, and Paddle customer/subscription IDs.
- License keys — if you activate via a license key, we store which key was used and when.
- Authentication tokens — JWT access tokens and refresh tokens used to keep you logged in. Stored locally on your device and in our database.
- Framework files — when you use the Cloud Sync feature, your Edo's Framework project files (plain-text markdown) are uploaded to our servers so they can be restored on any machine you log in to.
- Integration credentials — if you connect third-party services (Anthropic API key, Railway token, Gmail address and App Password), those values are stored on our servers in encrypted form and synced to your devices. See Section 4 for how we protect this data.
We do not collect any source code you write, Claude AI conversation content, or any project data beyond the framework files you explicitly choose to sync.
3. How We Use Your Data
- To authenticate your identity and maintain your session
- To verify your subscription status and unlock paid features
- To sync your framework files and integration credentials across your devices
- To process billing via Paddle (your card details go directly to Paddle — we never see them)
- To send transactional emails related to your account (e.g. subscription confirmation)
We do not sell, rent, or share your data with any third party for marketing or advertising purposes.
4. How We Protect Your Data
Security is a core part of how we store sensitive information:
- Integration credentials are encrypted at rest — API keys, tokens, and email credentials are encrypted using AES-256 with a unique randomly generated IV per value before being written to our database. The encryption key is never stored alongside the data.
- All data in transit is encrypted — communication between your device and our servers uses HTTPS/TLS.
- Access is token-gated — credentials can only be retrieved by an authenticated request from the account that stored them.
- You stay in control — you can disconnect any integration at any time from your dashboard, which permanently deletes the stored credential from our servers.
5. Third-Party Services
We use the following third-party services:
- Google OAuth — for sign-in. Google's privacy policy applies to data processed by Google.
- Paddle — for billing and subscription management. Paddle acts as the Merchant of Record and processes your payment data under their own privacy policy.
- Railway — our backend and database hosting provider. Data is stored on Railway-provisioned infrastructure in the EU region.
- Anthropic / Railway / Google — if you connect these services via Integrations, your credentials are stored by us (encrypted) and used solely to configure the extension on your behalf. We do not make API calls to these services on your behalf.
6. Data Retention
We retain your account and subscription data for as long as your account exists. Synced framework files and integration credentials are retained until you delete them or request account deletion. If you request account deletion, we will delete all your personal data within 30 days, except where retention is required by law (e.g. billing records).
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data
- Disconnect any integration at any time, which removes the stored credential immediately
- Withdraw consent for data processing (this may require account termination)
To exercise any of these rights, email us at edinmuhic@edosframework.com.
8. Cookies and Local Storage
The website stores your access token and subscription status in browser local storage to maintain your session. The VS Code extension stores your authentication token locally using VS Code's extension storage API. We do not use advertising or tracking cookies.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or via a notice in the extension. The date at the top of this page always reflects the most recent update.