Privacy Policy
1. Introduction
This Privacy Policy explains what personal data mockingpug ("mockingpug", "we", "us") collects, why we collect it, who processes it on our behalf and what rights you have. It covers this website (mockingpug.com), the mockingpug cloud editor (app.mockingpug.com) and the cloud features of the mockingpug CLI (sign-in, pull and push).
The open-source mockingpug npm package itself runs in your own project and does not send us any data unless you connect it to the cloud with mockingpug login.
2. Who We Are
The data controller is [Imię Nazwisko], [business name from CEIDG], [street, postal code, city], Poland, NIP [0000000000]. For anything related to this Policy or your data, contact us at [email protected].
3. Information We Collect
3.1 Information you give us
- Account data: email address, name and, if you sign in with GitHub or Google, your profile picture. If you sign up with a password, we store only a salted hash of it (scrypt), never the password itself.
- Project content: the schemas, tables, endpoints, dictionaries, notes and canvas layout you create, and the versions you publish.
- Collaboration data: email addresses of people you invite to a project, their access rights, and settings of the share links you create (including a hashed link password, if you set one).
- CLI and CI data: sign-in codes of the CLI, access tokens (stored hashed), and the name, framework and identifier of each app that pulls or pushes a project.
- Messages you send us.
3.2 Information collected automatically
- Product events tied to your account: for example, that you created a project, added a table, published a version, shared a link or pulled a schema into an app. We use them to measure activation and improve the product.
- Sign-up source: the campaign tags (UTM parameters) or referring page that brought you to mockingpug, stored with your account when you sign up.
- Anonymous visit counts: when you open a link with campaign tags, we count the visit together with the tags and the page — without any identifier of you.
- Technical data: your IP address and requests are processed to deliver the service and to protect it from abuse (rate limiting). IP addresses used for rate limiting are kept in memory only and are not stored.
- Analytics (with your consent only): on the cloud editor, page views, clicks and session recordings with masked inputs through PostHog.
3.3 Information from third parties
If you sign in with GitHub or Google, we receive your name, email address, profile picture and confirmation that the email address is verified. We do not receive access to your repositories or other data.
4. How We Use Your Information
- to create and run your account and projects, including real-time collaboration;
- to deliver your schemas to your apps through the CLI;
- to send transactional emails: email confirmation, password reset and security notices;
- to see whether our emails arrive and work: our emails contain a small tracking image that reports when an email is opened, and their links pass through
links.mockingpug.com, which records the click and forwards you to the page; - to understand which campaigns and pages bring new users, and how the product is used;
- to prevent abuse, fraud and security incidents;
- to comply with legal obligations.
We do not sell your personal data, do not use it for third-party advertising and do not send marketing emails without your consent.
5. Legal Basis for Processing (EEA and UK Users)
- Contract: account, projects, collaboration, CLI and transactional emails — to provide the service under our Terms of Service;
- Legitimate interests: product events, sign-up source, anonymous visit counts, email open and click statistics, security and abuse prevention — balanced against your rights;
- Consent: optional storage on your device for campaign attribution and product analytics (see Cookies). You can withdraw it at any time;
- Legal obligation: where the law requires us to keep or disclose data.
9. Data Retention
- account and project data — while your account exists;
- product events and sign-up source — while your account exists;
- email confirmation links — 24 hours; password reset links — 1 hour;
- CLI sign-in codes — 10 minutes; CLI tokens — until revoked or 90 days of inactivity;
- anonymous visit counts — kept in aggregate, they do not identify you;
- database backups — 14 days, after which deleted data is gone from them too.
10. Security
Traffic is encrypted with TLS. Passwords, link passwords and access tokens are stored only as hashes. Access to projects is checked on every request, sign-in and email endpoints are rate limited, and cross-site requests are blocked. No system is perfectly secure; if you find a vulnerability, please report it to [email protected].
11. Your Rights
Depending on where you live, you have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent at any time. To exercise these rights, including deleting your account, write to [email protected] from the email address of your account. We answer within 30 days.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority.
12. International Data Transfers
Your account and project data are stored on our server in Poland (EU). Some providers (Resend, GitHub, Google) process data in the United States. Where data is transferred outside the EEA or the UK, the transfer relies on the European Commission's adequacy decisions (including the EU–U.S. Data Privacy Framework) or Standard Contractual Clauses.
13. Children's Privacy
mockingpug is a tool for software developers and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
14. Changes to This Policy
We may update this Policy as the product changes. The effective date at the top shows the latest revision; for material changes we will notify you by email or in the cloud editor before they take effect.
15. Contact Us
[Imię Nazwisko], [business name from CEIDG], [street, postal code, city], Poland, NIP [0000000000]. Email: [email protected].