Privacy Policy
Last updated: October 2, 2026
1. Introduction
AfterPack ("we", "our", or "us") is the controller of the personal data described here. AfterPack is operated by its founder as an independent business. This policy explains what we collect when you visit afterpack.dev, create an account, or use the AfterPack obfuscation service, what we do with it, and who else processes it. Where this policy summarises how the product handles your code, the detailed version is in our data handling documentation, linked below.
For a data processing agreement or a vendor security questionnaire, email us.
2. Information We Collect
We collect information in the following ways:
Information You Provide
- Your email address, when you create an account, sign in with a magic link, or sign in with Google.
- Account content you create: workspace and project names, team invitations, and API key labels.
- Billing details you enter at checkout. Payments run through Creem, our merchant of record; your card details go to Creem and never reach AfterPack.
- Anything you send us: support email, feedback, and answers to optional surveys.
- What you type into the in-site assistant ("Ask AfterPack") and its answers, the page you asked from, and your language — linked to your account when you're signed in. Don't paste secrets into it.
Information Collected Automatically
- Product analytics events — pages viewed, features used — and anonymized, aggregated behavioral analytics data, collected without cookies and without identifying you across visits.
- Device and browser information: browser type and version, operating system, screen size, and language.
- Your IP address, used to rate-limit abuse and to derive an approximate country. We do not use it to build a profile of you.
- Service logs from cloud builds: timestamps, status codes, build identifiers, file counts, byte totals, and diagnostic codes — never file contents, identifier names, or constant values.
- For the in-site assistant, a version of your IP address that is hashed and changes every day, used only to limit how many messages an anonymous visitor can send.
3. Your Source Code
Your code is the thing we are most careful with:
- Local builds: AfterPack runs on your machine. Your source never leaves it: we cannot read it, store it, or transmit it, because it is never sent.
- Cloud builds: A Pro build sends source to our cloud, where it is encrypted in transit, obfuscated in memory inside a sandboxed isolate, and discarded at the end of the request. Server logs record build identifiers, file counts, byte totals, and diagnostic codes, never file contents.
- Protection Maps: A cloud build stores one artifact, the Protection Map — an annotated copy of your source — for up to one year or the most recent 500 builds per project, whichever runs out first. It is readable only by members of the workspace that owns the project, and an admin can switch it off per project at any time; maps already stored then age out on their existing schedule. Deleting a project or workspace removes its maps immediately.
- Telemetry: The client reports a diagnostic only when a build fails: the diagnostic's stable code and severity, engine and runtime versions, the detected framework, bucketed file counts and durations, and a random install identifier that rotates every 30 days. It carries no source, no file names or paths, no diagnostic message text, and is not linked to your account. A build that succeeds sends nothing. Set AFTERPACK_telemetry_enabled=false to turn it off.
- No training: Your code is never used to train AI models, and never for any purpose other than performing the obfuscation you asked for.
The full tables — what a log line records, what telemetry carries, what a stored map contains, and which sub-processors a build touches — are in our data handling documentation.
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, and administrative messages
- Respond to your comments, questions, and support requests
- Monitor and analyze trends, usage, and activities to improve user experience
- Detect, prevent, and address technical issues or fraud
5. Cookies and Analytics
AfterPack sets three cookies. All of them are functional; none is used for advertising, and none follows you to another site.
- afterpack_session: The sign-in session. It is set only after you sign in, is httpOnly and secure so page scripts cannot read it, and is cleared when you sign out.
- afterpack_impersonation: Set only when an AfterPack administrator has been granted access to act inside an account, for example to investigate a support request. It exists so the action is recorded as impersonation rather than as you.
- NEXT_LOCALE: Remembers the language you picked so the site opens in it next time.
That is the entire list. Because none of them is used for advertising or cross-site tracking, the site shows no cookie banner. You can delete them in your browser at any time; deleting afterpack_session simply signs you out. We also use your browser's local storage, not cookies, to remember the assistant's conversation id and the last workspace you viewed in the dashboard.
Analytics, without cookies
We use PostHog to count page views and see which features get used. We collect anonymized and aggregated behavioral analytics data to improve our product. PostHog is configured to run cookie-free:
- It stores nothing on your device. Analytics state lives in memory for the current page session and is gone when you close the tab — no cookies, no local storage.
- It does not identify you. We create no person profile and do not link visits, so two visits from the same browser are two unrelated sessions.
- It honours Do Not Track. If your browser sends that signal, analytics do not run at all.
- Events are sent to a path on afterpack.dev rather than to a third-party domain, and are stored by PostHog in the European Union.
6. Sub-processors
We keep the list of companies that process data on our behalf short, and we name all of them:
- Cloudflare — hosting, edge compute, object storage, and the account database. It runs the website and the API, and it is where a stored Protection Map sits.
- Creem — merchant of record for every AfterPack purchase: payment, tax, invoices, and the billing portal. Creem never receives your source code.
- Google — sign-in only, when you choose to sign in with a Google account. Google receives nothing beyond that sign-in.
- PostHog — product analytics, as described above, hosted in the European Union.
- Resend — transactional email: magic-link sign-in, account and API key notices, and the monthly statement.
- Anthropic — powers the in-site assistant ("Ask AfterPack"), through Cloudflare AI Gateway. It receives what you type into the assistant and the documentation pages it reads to answer, never your source code.
Each is bound by a contract that permits it to use your data only to provide the service we engaged it for, and some process data outside your country under standard contractual clauses. We do not sell personal data and we do not share it for advertising. A Data Processing Agreement is available on request; the sub-processors a build touches are listed in our data handling documentation.
7. Data Retention
We keep personal data only for as long as it is doing something. Account data lives until you delete your account, after which we delete or anonymise it within 30 days. Protection Maps expire after one year or 500 builds per project, whichever comes first. Analytics events are held by PostHog for the retention period configured on our project and are not tied to an identity. Billing records — invoices and tax data — are kept by Creem and by us for as long as tax and accounting law requires, typically up to ten years, which is why deleting your account does not erase your invoices. Assistant transcripts are deleted after 90 days; anonymised topic tags are kept.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct information that is inaccurate or incomplete
- Request deletion of your personal data
- Object to or restrict how we process it
- Receive your data in a portable, machine-readable format
- Withdraw consent where processing rests on consent
- Complain to your local data protection authority
To exercise any of these, write to us at the address below and we will answer within 30 days. You can also delete your account yourself, at any time, from the dashboard.
9. Security
We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
11. Contact
If you have any questions about this Privacy Policy or our data practices, please contact us at support@afterpack.dev.