Privacy Policy
Last updated: September 24, 2026
The short version. Your browser profiles — cookies, logins, history, everything inside them — live on your computer. We never see them. If you turn on sync, we store a copy that is encrypted on your device before it is uploaded; your passphrase itself is never sent to us. So that forgetting a passphrase does not cost you your profiles, we also keep a sealed backup copy of your account's encryption key, used only to carry out a password reset you ask for. What we hold besides that is what any account needs: your email, your plan, which computers have signed in (known to us only by one-way hashes of their hardware), for free accounts a keyed hash of the internet connection they use, and usage counters. We do not sell data and we do not run advertising trackers.
1. Who We Are
LoginDeck is operated by Balmer Island Media Inc., a corporation registered in Ontario, Canada ("LoginDeck", "we", "us", or "our"). This Privacy Policy explains how we collect, use, share, and protect personal information when you use the LoginDeck desktop application, the LoginDeck account and sync service, and our website (collectively, "the Software"). For purposes of the EU/UK General Data Protection Regulation, Balmer Island Media Inc. is the "controller" of the personal data described here. For purposes of the California Consumer Privacy Act as amended ("CCPA/CPRA"), Balmer Island Media Inc. is the "business".
2. What Stays on Your Computer
LoginDeck is local-first. The following are stored only on your device and are never transmitted to our servers, unless you enable sync (Section 4):
- the contents of your browser profiles: cookies, session tokens, saved logins, local storage, history, bookmarks, extensions, and cached files;
- the proxy addresses and proxy credentials you configure;
- your fingerprint settings for each profile;
- your Flows and their run logs;
- application logs and diagnostics.
Web traffic from a profile goes from your computer to the website (directly or through the proxy you chose). We do not proxy, inspect, or log the traffic of your browser profiles.
3. Information We Collect
We collect the minimum information needed to operate an account and a paid plan:
- Account information: the email address you sign up with. We also store a salted hash derived from your passphrase to check that a sign-in is genuine; the passphrase itself never leaves your device and cannot be reconstructed from what we hold.
- A sealed copy of your encryption key (key escrow): so that we can offer password reset, we store your account's sync encryption key sealed under a master key held by our server. This is a copy of the key, never a copy of your passphrase. It is opened only to complete a password reset that you start and confirm by email, or to complete a "Continue with Google" sign-in on an account you have already set up. See Section 4.
- Billing information: processed and stored by our payment processor, which acts as merchant of record and is named at checkout. We receive your plan, order and subscription identifiers, and the email used at checkout. We do not receive or store full payment-card details.
- Plan and usage data: your plan and its expiry, the number and type of synced records (not their contents), AI-action counts for metering, and the names and self-assigned identifiers of computers that have signed in to your account (so you can see and evict them).
- Computer identifiers: to apply plan limits (the free plan is one account per person, and each plan covers a set number of computers) and to prevent abuse, the Software sends one-way hashes of your computer's hardware identifiers, such as its motherboard UUID and its BIOS, board and system-disk serial numbers (on a Mac, its platform UUID and serial number). We receive and keep only the hashes, never the identifiers themselves, and a hash cannot be turned back into the identifier. We also keep the internet address a new account was created from, to limit how many accounts one connection can create.
- Internet connection (free plan): so that one internet connection cannot run several free accounts, when a free account connects we keep a keyed hash of the connection's internet address (for IPv6, of its network prefix) and which account used it. The hash is made with a secret key that never leaves our server, so what we store is not a readable address. Paid accounts are not recorded this way.
- Team data: if you invite members to a workspace, their email addresses and the permissions you grant them.
- Diagnostic information you choose to send: when you report a problem, the operating system, app version, and any logs you attach.
- Server logs: our servers record the IP address, time, and endpoint of requests to them (sign-in, sync, update checks, AI requests) for security and operations, retained briefly as described in Section 8.
- Communications: the content of emails or support messages you send us.
4. Encrypted Sync
When you enable sync, profile settings, proxies, tags, folders, Flows, and — on plans that include it — a profile's cookies and local storage are encrypted on your device using keys derived from your passphrase, and only then uploaded. Our servers store ciphertext, a salt, and a copy of your vault key wrapped under your passphrase.
We also keep a second, sealed copy of that vault key (key escrow). It is encrypted under a master key held by our server, and it exists for one reason: so that a forgotten passphrase is a password-reset email rather than a permanently locked account. We use it only to complete a password reset that you start and confirm with a code emailed to your address, and to complete a "Continue with Google" sign-in on an account you have already set up. We do not use it to read, mine, or hand over your synced data, and your passphrase is never stored in any form that can be turned back into text.
You should understand the trade-off this creates, because we would rather state it than imply otherwise: because that sealed copy exists, our servers are technically capable of decrypting your synced data, and an attacker who obtained both our stored data and our master key could do the same. This is why sensitive sync content is limited to what the feature needs, and why we recommend you do not rely on sync as the only copy of anything you cannot afford to lose. Synced data is stored on our servers in Europe/North America and in Cloudflare R2 object storage (Section 6). Closing your account deletes your synced data, and its escrowed key, from our storage.
5. Features That Contact Our Servers or Third Parties
- Update checks: the app periodically asks our update server for the latest version. That request carries your app version and, like any web request, your IP address.
- IP quality check: when you check a proxy, the app makes a request through that proxy to our server so we can report the proxy's public address, location, and reputation back to you. We see the proxy's exit address, not your home address, and we keep a short log of these checks for abuse prevention.
- AI Flows: when a Flow step uses AI, the page content or screenshot that step is looking at is sent through our server to our AI model provider (currently Anthropic) to produce the next action. We do not use this content to train models, and our provider does not train on it under our agreement. We keep a count of actions for metering, not the content.
- Imports from other tools: importing profiles from another profile manager happens entirely on your computer.
6. Data Sharing and Sub-processors
We do not sell your personal information. We share data only with the following categories of providers, and only as needed to operate LoginDeck:
- Payment processor (named at checkout) — checkout, billing, tax compliance, and fraud prevention.
- Hosting and storage providers (currently Hostinger for our servers and Cloudflare for object storage, DNS, and email routing) — for account data, encrypted sync data, logs, and backups.
- AI model provider (currently Anthropic) — for AI Flow steps, as described in Section 5.
- Email provider (currently Resend) — transactional and, if you opt in, product emails.
- Legal authorities — if required by a valid legal process (subpoena, court order, or similar), or to protect the rights, property, or safety of LoginDeck, our users, or the public.
7. How We Use Your Information; Lawful Basis
- To provide, operate, and maintain the Software and your account.
- To process payments and enforce plan limits.
- To send transactional emails (receipts, account and security notices, important service updates).
- To send product announcements, only if you opt in; you can opt out at any time.
- To respond to support requests and improve the product.
- To detect, prevent, and investigate fraud, abuse, and security incidents, including use that violates our Terms of Service.
- To comply with legal obligations.
Where the GDPR applies, we rely on: (a) performance of a contract for account creation, billing, sync, and providing the Software; (b) our legitimate interests in operating, securing, and improving the Software and preventing abuse, where not overridden by your rights; (c) your consent for product emails, which you may withdraw at any time; and (d) compliance with legal obligations. We do not use your data to train AI models and we do not sell or rent personal information.
8. Data Retention and Security
Encrypted sync data is stored encrypted at rest and in transit (TLS). Account data is stored on secured servers. No security measure is perfect, and we cannot guarantee that personal data will never be subject to unauthorized access. Sync data is never stored in the clear, so access to our storage alone yields ciphertext; as explained in Section 4, an attacker who also obtained our escrow master key could decrypt it. The master key is held separately from backups and object storage for that reason.
Typical retention periods, subject to extension where required by law or to establish, exercise, or defend legal claims:
- Account and encrypted sync data: for the life of your account. Closing your account deletes it; residual copies in backups are overwritten within 30 days.
- Billing records: 7 years (Canadian and US tax retention norms), held by our payment processor and in our records.
- Server and security logs, IP-check logs: up to 30 days.
- Computer identifier hashes: kept with the account that first used that computer, and deleted with that account. The internet address a new account was created from: 30 days. The internet-connection hash of a free account: 7 days after that account last connected from it, and sooner if the account is deleted or moves to a paid plan.
- Support correspondence: up to 3 years from the last interaction.
- Unsubscribe lists: indefinitely, to honour your opt-out.
9. International Transfers
Our servers and providers are located in Canada, the United States, and the European Union. By using the Software you consent to the transfer of your information to these jurisdictions, which may have different data-protection laws than your country of residence. Where required, we rely on standard contractual clauses or equivalent safeguards with our providers.
10. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent. You can delete your synced data and close your account from inside the Software at any time, and export any profile your plan has open. For anything else, email support@logindeck.com from the address on your account. We will respond within 30 days (extendable where permitted by law for complex requests) and will not discriminate against you for exercising your rights.
EU/UK residents also have the right to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your local data-protection authority). California residents have the right to know what personal information we collect and how it is used and shared, to delete it (subject to exceptions), to correct it, and to opt out of any "sale" or "sharing"; we do not sell or share personal information for cross-context behavioural advertising. An authorized agent may submit a request on your behalf with proof of authorization.
Synced data is stored encrypted, and reading, correcting, or exporting its contents is done by you inside the Software, where the data is already decrypted for you. We do not decrypt it on your behalf for access requests, because the Software gives you a faster and more complete route to the same result. We can delete it, and we will. If a profile is locked because your plan no longer covers it, you can still get a copy of your personal data in it: email support@logindeck.com from the address on your account, and we will make that profile available for you to export.
11. Cookies and Website
Our website does not use advertising or analytics cookies. It loads fonts from Google Fonts, which receives your IP address as part of serving them. The desktop application does not set tracking cookies. Our website does not respond to "Do Not Track" signals because no industry standard exists, but we do not track you across sites in any case.
12. Children
The Software is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If a change is material, we will notify you by email or in-app notice before it takes effect. The date at the top shows the current version.
14. Contact
support@logindeck.com
Balmer Island Media Inc., 1020 Shaw Drive #1607, Mississauga, Ontario, Canada L5G 3Z5.