AnimDeck - Software and Website Privacy Policy
Effective date: July 23, 2026
Controller / publisher: enter the publisher’s full legal name before public deployment.
Contact: enter a working privacy and support email address before public deployment.
This policy describes the prepared AnimDeck website, reporting form, automatic website diagnostics and optional software diagnostics. The text must match the features and third-party settings that are actually enabled.
Matsm Account
When an account is created, the website stores the following in Cloudflare D1:
- email address,
- profile name,
- a strong PBKDF2 SHA-256 password hash with a separate salt,
- account creation and last sign-in dates,
- active website and app sessions, device type/name and last activity time.
The raw password is never stored. Website sessions use an HttpOnly cookie. AnimDeck stores the session token locally using protection associated with the current Windows account. Users can change their profile name and password, sign out other devices and delete their account. Deleting the account removes profile and session data. Manual reports may remain without an account association when still required for support or security.
Google sign-in
When Google sign-in is selected, the website redirects the user to Google. Google returns an account identifier, verified email address, profile name and optional profile-picture URL. The Google identifier required to recognize the account is stored in Cloudflare D1. The Google access token is used only during sign-in and is not stored.
AnimDeck opens sign-in in the default browser. After completion, the browser sends a one-time code to the application through a local 127.0.0.1 address. The code expires quickly and can be used only once. The Google secret stays on Cloudflare and is never included in the desktop application.
Google processes sign-in data under its own policies. Users may continue to use a traditional email-and-password account.
Local software data
AnimDeck may store settings, language, window layout, projects, autosave and recovery data, collaboration history and information required for features enabled by the user. Local data remains until it is deleted, replaced or cleared. Projects saved in other folders must be removed separately.
Essential website server diagnostics
Cloudflare Pages Functions automatically record unhandled exceptions, server responses with 5xx status codes and exceptionally slow responses in a private Better Stack source. An event may contain:
- request method and path,
- response status and execution time,
- error message, exception type and a sanitized stack trace,
- basic Cloudflare environment data such as data center and country,
- the browser-identifying
User-Agentheader.
The project code does not add form contents, passwords, tokens, project files or a full IP address to the report. Cloudflare and Better Stack may still process normal connection data needed to deliver and protect their services under their own policies.
Optional browser diagnostics
With user consent, the website may load the Better Stack Error Tracking tag. Depending on settings in Better Stack, it may record JavaScript errors, rejected promises, performance information, page views and other diagnostic events. Features such as session replay, console logs or automatic events should be enabled deliberately and described here when used.
Without consent, the browser diagnostic tag and optional website analytics are not started. The choice is stored locally in the browser. A Do Not Track signal disables the website’s own analytics events.
Reporting form
When the /report form is submitted, its contents are stored in a private Cloudflare D1 database. Better Stack receives only a technical notification that a report was created, not the full report description. A report may include:
- category, title and description,
- optional reproduction steps,
- optional AnimDeck version,
- optional contact information,
- report ID, time and submission source.
The data is used to diagnose and handle the report and protect services. The contact field may be left empty. Do not include passwords, payment data, identity documents, private keys, room codes or confidential project content.
Optional software diagnostics
Automatic software crash reports are disabled by default. After voluntary enablement or manual submission, a report may contain:
- a random report ID and a random identifier for the current session,
- time, operation stage and problem category,
- exception type, error code, grouping fingerprint and sanitized stack trace,
- AnimDeck version and build identifier,
- operating system, architecture and .NET environment,
- process uptime, memory use, GC heap size and thread count,
- an optional contact nickname.
The report does not include project files or names, file paths, chat messages, room codes, passwords, tokens or imported asset content. Before sending, the code removes common local paths, email addresses and values marked as sensitive. Failed reports that have already been sanitized may be stored locally for a short time and retried on the next launch.
The app may also detect that the previous session did not close correctly. This signal is sent only when the user has enabled diagnostic reporting.
Optional software usage statistics
Usage statistics require separate consent and are disabled by default. When enabled, AnimDeck may send events to the publisher’s website for storage in Cloudflare D1, including:
- session start, periodic heartbeat and session end,
- app-ready state and periodic process health,
- a fresh random identifier valid only for one launch,
- app version, operating system and architecture,
- session duration, memory use, GC heap size and thread count,
- the name of a used feature from a restricted event catalog, such as project save or animation export.
The following are not sent: a persistent device identifier, project name, file name or path, project contents, chat, room codes or asset contents. When the user is signed in to Matsm Account, an optional statistic may be associated with the account identifier in D1. Consent can be disabled in settings, which stops future usage events.
Service status and monitoring
The website’s status link opens the publisher’s public Better Stack status page. It may show monitor state, availability history and public incident announcements. Private logs and reports are not disclosed there.
Better Stack may periodically request public website, download and API health endpoints to verify availability. A protected diagnostic-pipeline test requires a secret header and must not be exposed publicly.
Downloads and GitHub Releases
The main download button starts downloading the latest file from GitHub Releases, and the archive links directly to older release files. GitHub receives normal connection data related to the download under its own policy. With analytics consent, the website may record the download click, asset name and page path.
Recipients and retention
Data may be processed by infrastructure providers required to operate the service, especially:
- Cloudflare - website hosting, Functions, protection and traffic delivery,
- Better Stack - private technical logs, diagnostics, monitoring and public status page,
- Cloudflare D1 - accounts, sessions, manual reports and product statistics,
- GitHub - storage and download of public releases.
The publisher sets technical-log retention in Better Stack. Account, report and product-event retention is controlled in Cloudflare D1. Retention should be kept as short as reasonably needed, unnecessary contact data should be removed regularly and this policy should be updated whenever configuration changes.
AnimDeck does not sell personal data. Data is shared only as necessary to provide a selected feature, support, security, infrastructure or a legal obligation.
Legal bases and user rights
The exact legal basis depends on the purpose and the publisher’s circumstances. Optional diagnostics and statistics use a consent mechanism. Report handling may rely on action requested by the user or a legitimate interest in repairing and securing the software, depending on final deployment.
Depending on applicable law, users may have rights of access, correction, deletion, restriction, objection, withdrawal of consent and complaint to a competent data-protection authority. Withdrawing consent does not affect processing that occurred before withdrawal.
Children and sensitive information
Do not disclose sensitive or confidential data in forms, names, messages, searches or shared projects. A parent or guardian should supervise a minor’s use where required by law or appropriate for the user’s age.
Changes and contact
The date at the beginning identifies this version. Before public deployment, remove all placeholders and set the publisher’s real identity and contact details. For large-scale distribution, accounts, payments or children’s data, the document should be reviewed by a qualified lawyer.