1. Overview
This Privacy Policy explains how NanoCDN (“we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Service at cdn.paulgeorge.dev and related APIs or integrations. It should be read together with our Terms of Service.
If you do not agree with this Policy, please do not use the Service. We may update this Policy from time to time; the “Last updated” date indicates the current version.
2. Data we collect
Account data. When you register or sign in we process identifiers such as name, email address, password hashes (if you use email/password), passkey public keys (if you register a passkey), profile image URL (if provided by an identity provider), and account flags needed for security (for example email verification or required password change).
Authentication data. If you use Google, GitHub, or another connected provider, we receive the profile information that provider shares with us (typically name, email, and avatar) as needed to create or link your account.
Content and project data. Assets you upload, project names and settings, visibility and security options, API key metadata (prefixes and labels—not raw secret values after creation), and related configuration.
Usage and technical data. Logs and metrics related to requests, delivery, errors, IP addresses, user agents, approximate location derived from IP where applicable, device/browser information, and diagnostic data needed to operate and secure the Service.
Communications. Content of emails we send you (such as verification or password reset messages) and any messages you send us about the Service.
3. How we use data
We use personal data to:
- Provide, operate, and maintain the Service
- Authenticate users and secure accounts
- Host, transform, cache, and deliver assets as you configure
- Enforce storage limits, rate limits, and acceptable use
- Send transactional email (verification, password reset, security notices)
- Monitor performance, debug issues, and prevent abuse or fraud
- Understand product usage through analytics (see below)
- Comply with legal obligations and enforce our Terms
We do not sell your personal data. We do not use your uploaded assets to train third-party machine-learning models.
4. Analytics
We may use privacy-focused product analytics (including a self-hosted or third-party OpenPanel deployment) to understand how the Service is used—for example page views and interaction events. Analytics configuration may collect client identifiers and usage events. You can limit some tracking through browser settings or extensions; core operational logs needed for security and delivery may still be collected.
5. Cookies and similar technologies
We use cookies and similar storage primarily for authentication and session management (keeping you signed in and protecting your account). We may also use storage required by analytics tooling when enabled. Essential cookies are necessary for the Service to function; disabling them may prevent sign-in or other features from working.
6. How we share data
We share personal data only as needed to run the Service, including with:
- Infrastructure providers — for example cloud object storage, hosting, databases, Redis/cache, and email delivery providers that process data on our instructions
- Identity providers — when you choose to sign in with Google, GitHub, or similar
- Analytics providers — as described above
- Authorities or advisors — when required by law, or to protect rights, safety, and the integrity of the Service
Public or signed asset URLs you create may make Your Content reachable by anyone who has the link (or a valid signature). You control those settings and are responsible for what you publish.
7. International transfers
We and our processors may store or process data in countries other than your own. Where required, we rely on appropriate safeguards (such as contractual protections) for cross-border transfers.
8. Retention
We retain account and project data for as long as your account is active and as needed to provide the Service. Uploaded assets remain until you delete them or your account is closed and cleanup completes. Logs and analytics data are kept for a limited period appropriate for security, operations, and product improvement, unless a longer period is required by law. Backup copies may persist for a short time after deletion.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including transport encryption, access controls, and hashed passwords for credential accounts. No method of transmission or storage is completely secure; you use the Service at your own risk and should use strong unique passwords and protect API keys.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights related to your NanoCDN account, contact us using the details below. We may need to verify your identity before fulfilling a request. You can also update certain profile information in the Service or delete assets and projects you control.
11. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
12. Contact
Privacy questions or requests: email us at contact@paulgeorge.dev.
See also our Terms of Service.