Privacy Policy
Version 2026-09-10-paddle-2
Controller and purposes
The Talos supplier identified below is the controller for the licensing data it holds. Paddle separately processes purchase and payment data under its privacy policy. We process your email, selected plan, consent text, acceptance time and policy versions to conclude and perform your contract and retain evidence of the purchase. Payment and accounting records are also processed to meet applicable legal obligations; security and diagnostic processing serves the legitimate interest of operating and protecting the service.
Payments and licenses
Paddle is the merchant of record for new purchases and processes payment details through Paddle Checkout. Paddle provides payment receipts and invoices and handles applicable sales tax for those purchases. Paddle buyer terms (https://www.paddle.com/legal/checkout-buyer-terms) and privacy policy (https://www.paddle.com/legal/privacy) apply to its services. This license server does not receive full card numbers or CVC. It stores order, Paddle transaction, event, customer and subscription identifiers (and historical Stripe references) where present, paid amount, currency, email, license key, status, activation allowance and creation/expiry times. Confirmation email content and delivery status are retained to deliver and recover your license.
Activation and technical data
Talos sends its license key and a persistent host identifier to activate, verify and deactivate a license; activation also includes the host name. The server stores activation, last-seen and deactivation times. This identifies the computer running Talos, not the attached Android phone. Website and API connections expose an IP address to hosting and network providers; IPs are used in memory for rate limiting and are not stored by this service. We keep no website access logs. The server records operational diagnostic entries such as rejected checkout attempts, payment provider errors and release publications; these hold error codes, trace identifiers and configuration details rather than visitor identities, browsing history or request contents. A cumulative download counter is kept per release and does not identify who downloaded. Logs written by the Talos desktop application, including task definitions and run history, stay on your own computer and are not transmitted to us. Categories of recipients are Paddle for payments, the hosting provider operating the server and the email provider delivering your confirmation; the seller names the current providers on request.
Android screens and AI providers
ADB interaction happens between your Talos host and your authorized Android device. The reviewed licensing endpoints do not accept Android screenshots, screen text or task history. However, the desktop application sends task context, UI observations and screenshots used for decisions directly to Anthropic Claude or your configured custom HTTP AI endpoint. These can contain personal or sensitive information displayed on the device. Choose an appropriate provider and avoid exposing data you lack permission to process. Task definitions and run history are stored on your host. Self-hosting does not mean AI processing is offline.
Cookies, analytics and crash reports
The website uses an essential HttpOnly order-access cookie for up to 30 days so that only the browser that started Checkout can retrieve its license. It stores a theme preference locally and administration uses browser session storage for its access key. No advertising analytics or third-party crash-reporting SDK was found in the reviewed website or desktop source. Paddle and the hosting/CDN may process technical data for their services. No analytics, advertising or third-party tracking cookies are set and no tracking pixels are embedded; the essential order-access cookie described above is the only cookie this site sets. The theme preference and the administration key are held in browser local and session storage and are never sent to us. Paddle Checkout sets its own cookies under its own policy. Where a recipient processes personal data outside the European Economic Area, the seller relies on the transfer safeguards published by that provider; contact the seller for current details.
Retention and your rights
We keep each category of data only for as long as it is needed for the purpose it was collected for, and delete or irreversibly anonymise it once that need ends. Contract records, meaning your order, licence key, plan, amount, currency, email and the consent text with its acceptance time, are kept while your licence runs and afterwards for as long as claims connected with the purchase can still be brought or defended under the applicable limitation periods. Accounting records are kept for the period required by Polish tax and accounting law. Activation records are kept while the licence is active and for a limited period afterwards, to handle renewals and disputes about activation slots. Confirmation email content and delivery status are kept for as long as they are needed to evidence delivery of your licence. Operational diagnostic entries are kept only for as long as they remain useful for running and securing the service. You can ask us to delete data that we are no longer required to keep. Subject to applicable law you can request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Contact the seller using the address below. You may complain to your competent data-protection supervisory authority. Required purchase and activation data is necessary to provide the license; without it we cannot complete those services. This service does not make automated decisions about you producing legal or similarly significant effects.
Seller and contact
Maciej Bielecki
ul. Wiejska 36, 77-400 Nowa Święta
7671710821