Privacy

Privacy Policy

How we handle the source code you upload and the account data you create.

Last updated: June 11, 2026

1. What we receive

When you use PyVMProtect you submit two kinds of data:

In addition, like every web service, our servers automatically record technical logs (IP address, request timestamps, and request metadata) when you visit the site or call the API.

Providing an email address is required to create an account; without it we cannot provide the service. Everything else is provided only when you choose to use the corresponding feature.

2. Why we process your data

Everything we do with your data has a specific reason behind it:

None of this relies on your consent, so there is nothing to withdraw. If we ever add something that does rely on it, a newsletter for example, we will ask for it separately and you will be able to change your mind at any time.

3. How we store your source code

Your source code is treated as ephemeral build input, not as stored content.

Retention summary. Source code lives on our systems only for the duration of the build and long enough for you to download the protected output. It is not archived and not used to train any model. We do not create backups of your source code ourselves; our hosting provider's routine infrastructure backups may retain short-lived copies for up to 30 days before they roll off.

Personal data inside your uploads

Your source code may itself contain personal data, like names in comments or test data. That content stays your responsibility, and we handle it strictly on your behalf: we touch it only to perform the build you requested, under this policy and our Terms of Service, and we delete it as described above. Make sure you actually have the right to submit what you upload. The only thing we do with uploads on our own initiative is the abuse screening described in section 5.

4. Access

Access to the build infrastructure is restricted to operators of PyVMProtect acting under confidentiality obligations. We do not inspect customer source code as a matter of practice, and we do not share it with anyone except the service providers and circumstances described in this policy.

5. Malware and abuse

PyVMProtect is not a tool for malware authors. When automated or manual review identifies content that is plausibly malicious, abusive, or illegal, we reserve the right to:

This is the only scenario in which uploaded source code is kept beyond the normal build lifecycle. We disclose retained material only in response to requests that are valid and binding under European Union or French law.

Automated screening may flag or pause a build, but no account is terminated and no material is retained under this section without review by a human operator. If you believe a decision was made in error, contact privacy@pyvmprotect.com and a person will re-review it.

6. Account data and cookies

We store the minimum required to run your account: email, password hash, and build history metadata (timestamps, file sizes, target Python version). We do not sell this data. We use first-party cookies only for session management; these are strictly necessary cookies and require no consent banner.

7. Service providers and international transfers

We use a single service provider, who processes data on our behalf under a data-processing agreement:

We do not sell personal data and we do not share it with anyone else, except competent authorities where section 5 applies or where we are under a legal obligation to do so.

International transfers. All personal data is stored and processed within the European Union (France). We do not transfer personal data outside the EU. Web fonts and all page assets are served from our own domain, so visiting this site does not send your IP address to any third-party font or analytics service.

8. How long we keep data

9. Your rights

You can ask us at any time to see the personal data we hold about you, fix it, get a copy of it in a portable format, delete it, freeze its processing, or object to the processing we do for our own legitimate interests (including abuse screening). These rights apply to every user, wherever you are located. Just write to privacy@pyvmprotect.com. We will respond within one month; for complex requests this can stretch by up to two further months, and we will tell you if that happens. We may ask you to confirm control of your account email before acting on a request.

You can also complain to a data-protection authority. Ours is the French CNIL (Commission Nationale de l'Informatique et des Libertés), www.cnil.fr, though you can just as well go to the authority of your own EU member state.

Account deletion removes your login and build history within 30 days, after which copies in rolling host backups expire automatically (see section 8). One exception: material retained under section 5 while an abuse or law-enforcement matter is pending. Source code uploaded during your use of the service has already been deleted as described in section 3, so no separate deletion step is required for it.

10. Self-hosted option

For organisations that cannot send source code to a third party, we offer a self-hosted build of the compiler. In that configuration your code never leaves your own infrastructure : no uploads, no build servers, no data sharing. Contact sales to discuss this option.

11. Changes to this policy

If we change how we handle data, we will update this page and record the change date at the top. Material changes will be announced in-product before they take effect.

12. Controller and contact

PyVMProtect is operated as a personal project by an individual based in France, who is the data controller for all processing described in this policy. For privacy questions and any of the requests described in section 9, write to privacy@pyvmprotect.com. We do not have a Data Protection Officer; a service of this size is not required to appoint one, and the contact above handles all privacy matters.

The service is hosted by Alwaysdata SARL, 91 rue du Faubourg Saint-Honoré, 75008 Paris, France.