PS UI TOOLKIT
ProductHow it worksPricingWhy teams use it
Sign inStart free

Privacy Policy

What we process, why, how long we keep it, who else sees it, and what you can ask us to do about it. This policy covers the PS UI TOOLKIT website and web application.

Last updated: 2026-08-02

On this page

  1. 1. Who is responsible
  2. 2. The short version
  3. 3. What we process
  4. 4. Why we process it, and on what legal basis
  5. 5. The AI assistant and where your project goes
  6. 6. Cookies and local storage
  7. 7. Who else processes your data
  8. 8. Where your data is
  9. 9. How long we keep things
  10. 10. Your rights
  11. 11. How to exercise them
  12. 12. How we protect it
  13. 13. Children
  14. 14. Complaints
  15. 15. Changes to this policy
  16. 16. Contact

1. Who is responsible

PS UI TOOLKIT decides how and why the personal data described here is processed. Under the GDPR that makes us the controller; under Türkiye's KVKK it makes us the data controller (veri sorumlusu).

We identify ourselves publicly by brand name and a single support address: info@psuitoolkit.com. Use it for anything in this policy — there is no separate privacy mailbox to remember.

If you use PS UI TOOLKIT for an organisation, the content you put into your workspace is that organisation's business data and we act on its instructions in respect of it. We remain the controller for account, security and billing data. If your organisation needs a data processing agreement, write to us and we will arrange one — we are not claiming to already have one on file.

2. The short version

No analytics, no advertising networks, no tracking of any kind. We do not sell or share your data with data brokers, and the AI feature stays off unless you turn it on. The single promotional email the product is capable of sending also ships switched off — section 4 names it.

  • Only strictly necessary cookies are used — the ones that keep you signed in. That is why there is no cookie banner: there is nothing optional to consent to.
  • Your data is stored on servers in Germany, inside the EU.
  • We never use your projects or packages to train a model. If you switch the AI assistant on, what the provider you chose then does with what it receives is governed by that provider's terms — we cannot audit it and we will not promise it on their behalf. Section 5 is explicit about this.
  • If you enable the AI assistant with your own provider key, your project content leaves our platform and goes to the provider you chose. Section 5 spells that out.
  • Account deletion and a full data export are not self-service buttons today. We do them by hand when you ask, and section 11 is honest about that rather than promising a button that does not exist.

3. What we process

Grouped by what it actually is, rather than by database table.

Account
Your email address (which is also your username), a hash of your password — never the password itself, whether the address is confirmed, two-factor status plus the TOTP secret and recovery codes if you enable it, lockout counters, the display name you gave at sign-up, and the date you registered.
Workspace
A workspace name and a URL-safe short name. If you did not enter a display name at sign-up, both are derived from the part of your email address before the @ — so 'ada.lovelace@example.com' produces a workspace called 'ada.lovelace'. We also store which users belong to which workspace and in what role.
Projects and package designs
Project names, the application name and version you are packaging, and the full manifest of every revision: file paths, commands, conditions, notification texts, script bodies — everything you typed. This is the core of the product and it is kept so you can come back to it.
Generated packages
For each build: the file name, size, SHA-256 checksum, who built it, the validation findings recorded at build time, and the ZIP file itself.
Company profile and logo
Your company name, your production defaults and the logo file you upload, so that the notifications shown by your packages carry your branding.
AI settings
Which provider and model you selected, and your provider API key encrypted with AES-256-GCM. The key is never stored in plain text, never written to a log, and never returned by any endpoint — the app can only tell you whether one is saved.
Support
The subject and free-text body of your tickets and replies, the category and status, and who wrote them. A copy is emailed to us so we see it. Please do not put anything into a ticket you would not put in an email.
Notifications
In-app announcements addressed to you, and whether you have read or dismissed them.
Audit trail
An append-only record of security-relevant actions: the workspace, the user, what was done, a JSON detail and a timestamp — package builds, AI calls, support activity, subscription changes. The database schema has a column for the client IP, but nothing in the product fills it, so it is empty.
Quota usage
Append-only counters recording which user consumed which quota and when, so plan limits can be enforced and shown back to you.
Email log
A record that an automated email was sent, so that it is sent exactly once: the workspace, the user, a template key such as 'trial-t2', a de-duplication key and a timestamp. It deliberately stores neither the address nor the message.
Subscription
Your plan, status, trial end date and — once payments are live — the pseudonymous customer and subscription identifiers issued by the payment provider. Payments are not live, so those last two fields are empty on every account that exists today. No card data ever reaches us.
Security logs and IP addresses
When a sign-in fails we log the email address that was tried together with the client IP, so credential-stuffing and brute-force attempts can be spotted. Failed two-factor and recovery attempts log the user id and the IP. Passwords are never logged. IP addresses are also held briefly in memory to enforce rate limits and are not written to the database for that purpose.

We do not ask for, and have no use for, your date of birth, postal address, phone number, or any special-category data. The underlying identity framework has a phone number column; the product never fills it.

4. Why we process it, and on what legal basis

GDPR Article 6 and KVKK Article 5 both require a lawful basis for every purpose. Ours are:

Performance of a contract — GDPR 6(1)(b) · KVKK 5/2-c
Creating and running your account and workspace, storing your projects, building and delivering packages, enforcing plan quotas, sending transactional email (address confirmation, password reset, trial reminders), providing support, and managing your subscription.
Legitimate interests — GDPR 6(1)(f) · KVKK 5/2-f
Keeping the service secure and available: rate limiting, account lockout, the security logs described above, the append-only audit trail, and preventing abuse of the platform. Our interest is running a service that is not taken over or abused; the data involved is kept minimal and, where we can, short-lived.
Legal obligation — GDPR 6(1)(c) · KVKK 5/2-a
Tax and accounting records for a purchase. Nothing is processed on this basis today, because there are no purchases: payments are not live and the product has no checkout. When they open, those records will be created and kept by the merchant of record that sells the subscription, and we will hold only the identifiers needed to match a subscription to a workspace.
Your explicit instruction — GDPR 6(1)(a) · KVKK 5/1
The AI assistant, and only that. It is off by default and sends nothing anywhere until you switch it on and enter your own provider key. Switching it off, or deleting the key, stops it immediately and does not affect anything that happened before.

We do not profile you and we make no automated decisions that produce legal effects for you.

One message deliberately sits outside those four bases, and we would rather name it than bury it. The product contains an optional reminder that can be sent once, seven days after a trial has ended, to an account that did not subscribe. It is promotional, not contractual, so none of the bases above would carry it. It therefore ships switched off, and it is off unless the operator turns it on. If it is ever turned on it goes out at most once per workspace — the send is recorded in the email log described above precisely so it cannot repeat — and a line to info@psuitoolkit.com is enough to have your workspace excluded from it.

5. The AI assistant and where your project goes

If you enable the AI assistant, the content of the project you are working on leaves our platform and is sent to the AI provider you selected, using your own API key.

The feature is bring-your-own-key and closed by default. Nothing is sent anywhere unless all three of these are true:

  • Your plan includes AI. Pro and Max do; Basic and the trial do not.
  • Someone with Admin or Owner rights in your workspace has switched AI on. The stored default is off.
  • You have saved your own API key for one of the supported providers.

When you then send a message to the assistant, the following goes to that provider over HTTPS:

  • The full manifest of the project you are working on — every path, command, condition, notification text and script body in it.
  • The message you typed and the text of any file you pasted into the conversation, up to a combined 64,000 characters.
  • Up to the last 40 turns of that conversation.
  • If you ask the assistant to start from a template: the built-in templates plus up to 10 of your own custom templates, in full.
  • In the detection assistant: the application name, publisher, version, architecture, install type, MSI product code and installer file name you entered.

The provider list is fixed in our code — OpenAI, Anthropic, Google Gemini, xAI, DeepSeek, Moonshot and NVIDIA. You cannot point the assistant at an arbitrary address, and redirects are refused so that your key cannot be forwarded to another host. Whatever a provider receives is governed by its own terms; that relationship is between you and them.

On our side the audit trail records only that a call happened, for which project, to which provider, whether a manifest came back and whether it was rejected. The prompt and the key are not recorded.

Suggestions are never applied automatically: they come back as a proposal, are dropped entirely if they fail our sanitiser, and take effect only when you accept them. To stop the feature, go to Settings → AI, switch it off and delete the stored key.

6. Cookies and local storage

We use strictly necessary cookies only — the ones without which you could not stay signed in. There are no analytics, advertising or tracking cookies, and no third-party pixels anywhere on the site.

CookieWhat it doesLifetime
psui_authKeeps you signed in. Encrypted, HttpOnly so JavaScript cannot read it, SameSite=Lax, and HTTPS-only in production.7 days, refreshed on each request
ASP.NET Identity framework cookiesUsed only in two-factor sign-in: the short-lived cookie between password and code, and the optional 'remember this device' cookie. Their names come from the framework.The sign-in flow, or the remembered-device period
df_active_tenantWould select which workspace is active. The product only reads it; nothing in the app writes it today, so it does not appear in your browser.Not set today

Because every cookie we use is strictly necessary to deliver a service you asked for, there is no consent banner to click through. If we ever add an optional cookie, we will ask first.

Separately, the app keeps a few preferences in your browser's local storage. These are not cookies, they are never sent to our servers, and they stay in your browser:

  • df_theme — light or dark theme.
  • df_lang — interface language.
  • df_last_project, df_last_page:… and df_ws_cols — the project and page you last had open and your editor column widths, so you can pick up where you left off.
  • Flags recording that you have already seen a product tour or an onboarding hint.

Clearing your browser's site data removes all of them, at the cost of your theme and language preference.

7. Who else processes your data

The full list of subprocessors lives on its own page, with what each one receives and whether it is involved at all times or only when you switch a feature on.

See the subprocessor list →

There are no advertising networks, analytics vendors, content delivery networks or external font services in that list, because the product uses none.

8. Where your data is

The application, the database and the files you upload or generate are hosted at Hetzner Online GmbH, on servers in Falkenstein, Germany — inside the EU. The service runs as a single deployment, so nothing is copied to another region for routine operation.

Data leaves that environment only in these cases:

  • AI, and only if you enable it: your project content goes to the provider you selected, in whichever country that provider operates. You start that transfer and you choose the recipient.
  • Transactional email: the recipient address, the subject and the message body go to our email provider, Resend.
  • Payments, once they are live: your email address, your workspace identifier and the plan you chose would go to the payment provider to create the checkout. Today this transfer does not happen at all — there is no checkout, and no provider has been chosen to receive it.

Hosting itself involves no such transfer: the servers are in Germany. Where a transfer outside the EU or outside Türkiye is involved — email delivery, and payments once they are live — it relies on the transfer mechanism the relevant provider offers. We will name the specific mechanism here once we have checked it against each provider's current terms; the payment provider is not even chosen yet. We would rather leave this sentence unfinished than claim a safeguard we have not verified.

9. How long we keep things

Concrete periods where the product enforces one, and a straight answer where it does not.

Generated packages — download window
30 days from the build. After that the download link stops working and returns 'not found'.
Session
The sign-in cookie lasts 7 days and is refreshed while you use the app. A password reset or an account lock invalidates live sessions within 5 minutes.
Account, workspace, projects, templates, profiles and logos
Kept while your account exists, and after that until you ask us to delete them. There is no automatic erasure job today.
Audit trail, quota usage and email log
Append-only by design: the application has no permission to change or delete them, which is exactly what makes them trustworthy as a security record. They are kept while the account exists and are removed as part of a manual deletion request.
Support tickets and replies
Kept with the workspace, and removed as part of a deletion request. A copy also exists in our support mailbox.
Security logs — failed sign-in address and IP
Written to the application log rather than the database. What lands there: when a sign-in fails we record the email address that was tried and the client IP address. That is personal data, so we say it in plain words instead of hiding it behind 'security logs'. There is no fixed retention period, and we are not going to invent one to make this box look tidy. The logs rotate by SIZE, not by age: the container runtime keeps at most 3 files of 10 MB per container — roughly 30 MB — and deletes the oldest file when that fills up. How many days that covers therefore depends on traffic: a quiet week survives longer than a busy one. If you need to know whether a particular entry still exists, ask us and we will look.
Rate-limiting IP addresses
Held in memory only, for the length of the limit window, and never written to the database.
Database backups
Two layers, both in Germany, in the same region as the production server. First, a nightly database backup written to the production server's own disk at /var/backups/psuitoolkit, in a directory only the deployment user can open (700 on the directory, 600 on the files); those dumps are kept for 14 days and anything older is deleted automatically. Second, a daily Hetzner snapshot of the whole server disk, held on Hetzner's side on a rolling 7-day window. The honest limit of that arrangement: the first layer sits on the SAME machine as the service, so if the server is lost outright only the snapshots remain. We are not going to describe this as a geographically separate backup, because it is not one. Data you asked us to delete can survive in a backup until the relevant window expires; it is never restored into the live service.

Being straight with you: the product currently runs no scheduled job that erases expired packages or old records. The 30-day figure closes the download link, it does not wipe the file. Actual erasure happens when you ask us, manually, across the whole account.

10. Your rights

Under the GDPR and under KVKK you have — in substance the same under both — the right to:

  • Know whether we process personal data about you, and get a copy of it.
  • Have inaccurate data corrected and incomplete data completed.
  • Have your data erased once there is no longer a valid reason for us to hold it.
  • Restrict processing, or object to processing we base on our legitimate interests.
  • Receive the data you gave us in a structured, machine-readable format, and have it transmitted to another provider where that is technically feasible.
  • Withdraw consent at any time — in practice, switching the AI assistant off — without affecting processing that already happened.
  • Not be subject to a decision based solely on automated processing. We make none.
  • Ask us to notify third parties of a correction or erasure and, under KVKK, to claim compensation for damage caused by unlawful processing.

Exercising any of this is free, and we will not treat your account differently because you did.

11. How to exercise them

Some of it you can do yourself, right now, inside the app:

  • See your data — your account and workspace details, plan and quota usage, projects, templates, profiles, packages, support tickets and notifications are all visible in the app.
  • Export a project as its manifest file, and download any package as a ZIP within the 30-day window.
  • Change your password from Account → Security.
  • Stop AI processing from Settings → AI: switch it off and delete the key.
  • Cancel your subscription from Account → Subscription.

Deleting your account and getting a complete export of everything we hold are not self-service today — there is no button, and we will not pretend otherwise. We do both by hand when you ask, and being manual is never a reason for us to refuse or delay.

For everything else — erasure, a full export, correcting your display name or email address, restriction or objection — write to info@psuitoolkit.com from the address on your account, or open a support ticket while signed in. Writing from the account address is how we check it is you; if we still cannot be sure, we will ask one more question rather than act on a guess.

We answer within 30 days, the deadline both the GDPR and KVKK set. If a request is unusually complex we will tell you before that deadline rather than after it.

12. How we protect it

These measures are implemented in the product today, not planned:

  • Workspace isolation is enforced by the database itself through PostgreSQL row-level security, and mirrored a second time in the application layer. The database account the web app connects with cannot bypass those policies.
  • Passwords are stored only as hashes. Sign-in is protected by mandatory address confirmation, account lockout, and optional TOTP two-factor authentication with recovery codes — and turning two-factor off requires your password.
  • The session cookie is encrypted, HttpOnly and HTTPS-only in production, and sessions are re-validated every 5 minutes against a security stamp, so a password reset or a lock takes effect almost immediately.
  • Your AI provider key is encrypted at rest with AES-256-GCM. The plain key is never stored, logged or returned.
  • Audit, usage and email logs are append-only at the database level: the application has no permission to alter or delete them.
  • Uploaded and generated files are stored under unguessable, workspace-prefixed keys, with checks that reject path traversal and cross-workspace access at the file layer as well.
  • Traffic is served over HTTPS with HSTS. The site sets a strict content security policy that blocks connections to other origins, the API refuses framing and content sniffing, and rate limits apply per IP, per user and per workspace.

What we do not claim: we hold no ISO 27001, SOC 2 or PCI certification, we offer no uptime guarantee, and we will not describe our encryption with marketing adjectives. Card data has never reached our systems — not because of a safeguard we built, but because payments are not live and the product has no checkout at all. When paid plans open, cards will be entered on the merchant of record's own pages and card data will still never pass through us.

13. Children

PS UI TOOLKIT is a tool for IT administrators and is not directed at children. Please do not create an account if you are under 18. If you believe a child has given us personal data, write to info@psuitoolkit.com and we will delete it.

14. Complaints

Please raise it with us first at info@psuitoolkit.com — most things are faster to fix directly. You also have the right to go to a regulator:

  • In Türkiye: the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr).
  • In the EU or EEA: the supervisory authority of the country where you live or work, or where the issue occurred.

15. Changes to this policy

We publish any change on this page and update the date at the top. If a change materially affects how we use your data, we will tell you by email or in-app notice before it takes effect.

16. Contact

Privacy questions, requests, or a data processing agreement for your organisation: info@psuitoolkit.com.

Back to top

PS UI TOOLKIT

Enterprise software packaging, from the browser — forged for SCCM and Intune.

Product

OverviewHow it worksPricing

Company

AboutContactSecurity

Get started

Sign inStart freePricing

Legal

Terms of ServicePrivacy PolicyRefundsSubprocessors
© 2026 PS UI TOOLKIT. All rights reserved.