delvunBack to the site
privacy

Privacy

Last updated: 16 September 2026

What Delvun stores, why, and how to get rid of it. The short version: an email address, what you did in the scenarios, and nothing else that identifies you.

The seller's registration details are added here before the first sale; until then Delvun sells nothing and takes no payments.

What we store

Three things, and each has a reason:

  • Your email address — it is the account, and it is where the sign-in link goes. If you asked to be notified when Step 1 opens, the address is also on that list.
  • What you did on the platform — which scenarios you opened, when sessions started and ended, check runs with their results and evidence, and attempts. This is the record the product exists to produce.
  • A keyed hash of your IP address, and nothing readable — it limits sign-in links and sandbox starts. The hash cannot be turned back into an address.

What we do not store

No passwords: sign-in is a one-time link. No payment details: when paid access opens, Paddle handles checkout and we never see a card number. No tracking across other websites, no advertising identifiers, no profiles sold to anyone.

Server logs carry a hashed address, never the email itself. What you type inside a sandbox stays in the sandbox and is destroyed with it; the checker records the result of checks, not your keystrokes.

Cookies

One cookie for the sign-in session, and one that remembers the interface language. Both are set by the site itself and neither is used for advertising.

Visits are counted with Plausible, which sets no cookies and stores no personal data — it produces page counts, not profiles. A few steps are counted the same way (opening a scenario, signing in, starting a sandbox, the first check run, the first pass), with the scenario's name as the only detail.

Who else touches it

The suppliers that make the service work, and nobody else:

  • Hetzner Online GmbH (Germany) — the servers and the database, including the off-site backup
  • Cloudflare — the network in front of the site
  • Resend — delivery of sign-in and notification emails
  • Plausible — privacy-friendly visit counts
  • Paddle — checkout, when paid access opens (they become the seller and their privacy policy applies to the payment)

How long

Sign-in links expire in fifteen minutes; sessions in thirty days. Rate-limit rows are deleted after twenty-four hours. Scenario records stay while the account exists, because they are the point of the account. Backups are kept for thirty days.

Your rights

Write to [email protected] and ask for a copy of what we hold, a correction, or deletion. We answer within thirty days. Deleting the account deletes the records with it; the notification list is a single line you can be removed from at any time.

The data controller is the operator of Delvun (registration details are published here before the first sale).