Privacy

This page describes what logicsrc.com does with data. It covers the marketing site and the credentials app; it does not restrict how you use the specification, schemas, or CLI, which run on your own machines and report nothing back to us.

Who is responsible

Profullstack, Inc. operates logicsrc.com and is responsible for the data described here. For any privacy question, or to ask us to delete something you sent us, email privacy@profullstack.com. Security reports go to security@profullstack.com (see security.txt).

There is no account required to read this site

Browsing the specification, docs, blog, and schema pages requires no account, no sign-in, and no cookie. We do not run advertising trackers, we do not sell or share data with data brokers, and we do not build advertising profiles.

Analytics

Page views are measured with CrawlProof, a privacy-friendly analytics service that records aggregate page traffic — pages visited, referrer, rough geography, and device class. It does not set advertising cookies and does not follow you across other sites. We use it to see which specs and docs people actually read.

The Hire Us form

If you submit a project through Hire Us, you send us two things: the contact address you type, and your description of the work. We use them only to evaluate and reply to your request, and to scope an engagement if it is a fit. We do not add the address to a marketing list. Ask us to delete a request and we will.

Payments and the CoinPay sign-in

Paid work is invoiced through CoinPay. If you connect a CoinPay account, we complete an OAuth sign-in and store the resulting session in a signed, HttpOnly, SameSite=Lax cookie so the site can show you as connected. That session holds your CoinPay identifier and the profile fields CoinPay returns (typically name and email). Clearing your cookies ends it.

Card numbers and cryptocurrency wallet credentials are entered on CoinPay, not here. We never receive them. CoinPay's handling of your payment data is governed by CoinPay's own privacy policy.

Credential Sharing: what we never receive

The LogicSRC credentials app exists to sync secrets between providers, so the boundary matters. Secret values are encrypted end-to-end on your device before they are stored. We hold ciphertext we cannot read. Audit records — who synced which key name, to which provider, when, and the resulting key fingerprint — are stored in readable form so that a sync is reviewable; key names and fingerprints are recorded, secret values are not.

The logicsrc CLI and TUI run locally. Running a spec validation, a schema check, or a credentials dry run sends nothing to us. Only commands that explicitly talk to a hosted endpoint — for example logicsrc login — make a network call.

Server logs

Like any web service, our hosting produces operational logs containing IP addresses, timestamps, request paths, and user-agent strings. They are used to keep the service running and to investigate abuse and outages, and they are not used to profile visitors.

Cookies

We set cookies only for functions you initiate: a short-lived state cookie during a CoinPay OAuth round trip, and the CoinPay session cookie described above. There are no advertising or cross-site tracking cookies. The site also registers a service worker for offline page caching; it stores pages in your own browser and sends us nothing.

Third parties we rely on

Our hosting provider, our database provider, CrawlProof for analytics, and CoinPay for payments process data on our behalf in order to run the service. We do not sell personal data, and we do not share it with anyone else except where we are legally required to.

Retention

Project requests are kept while an engagement is live and afterward only as long as we need them for tax and accounting records. Operational logs roll off on our provider's normal schedule. Analytics data is aggregate and is not tied back to you.

Your choices

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it — write to privacy@profullstack.com and we will act on it. Deleting an encrypted credential removes the ciphertext; the corresponding audit record is retained, because an audit trail that can be edited is not an audit trail.

Children

This is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

We will update this page as the hosted products grow. Material changes will be noted in the blog. See also our Terms.