Privacy Policy
Last updated: July 2026
This describes what Javer Studios collects when you use Javer Webhost or Javer Game Host, and why. We try to collect only what the service actually needs to run.
What we collect
| Data | Why |
|---|---|
| Email address | Account identification, login, sending verification/security emails |
| Password (hashed, never plaintext) | Login authentication |
| IP address + timestamp on login attempts | Security — detecting abuse, account lockout after repeated failures |
| Two-factor auth secret, if you enable it | Login security |
| Google account ID/email, if you link Google sign-in | Alternate login method |
| GitHub access token, if you connect GitHub | Listing your repos and pulling code for auto-deploy — scoped to your own repos only |
| Stripe customer/subscription ID | Billing — we never receive or store your actual card number; Stripe handles that |
| Whatever you deploy (code, files, environment variables) | That's the product — running your app/server |
Third parties we use
We rely on a small number of specific providers to run the service, and share only what each one needs:
- Stripe — payment processing. Handles your card details directly; we never see them.
- Resend — sends transactional email (email verification, login codes, security notifications). Receives your email address and the message content.
- Cloudflare — CDN, DDoS protection, and the tunnel that routes traffic to our servers. Sees traffic metadata as part of normal request routing, same as any site behind Cloudflare.
- Google / GitHub — only if you choose to link them for sign-in or repo access.
We don't sell your data, and we don't share it with anyone beyond what's listed here and what's needed to operate the service or comply with the law.
Where your data lives
Our infrastructure is dedicated hardware we operate ourselves in Tokyo, Japan — not a shared cloud provider. Backups are kept for disaster-recovery purposes on infrastructure we control.
Your controls
- Change your password or enable/disable two-factor authentication anytime from Settings.
- Disconnect Google or GitHub anytime from Settings — this revokes our access to that account.
- Cancel a paid subscription anytime from the Billing page.
- Request account deletion by emailing [email protected] — we'll remove your account and associated data, except where we're required to retain billing records for legal/tax purposes.
Cookies
The panel uses cookies strictly for keeping you logged in (session refresh token and a CSRF protection token) — not for tracking or advertising.
Changes
We may update this policy as the product evolves. Material changes will be posted here with an updated date.
Contact
Questions about this policy or your data: [email protected].