Legal

Privacy Policy

Last updated: August 6, 2026 · Effective: August 6, 2026

Plain-English Summary

  • We only collect what we need to run the service — account info, payment data, download logs.
  • We never sell your data. Not ever. Not to anyone.
  • Payments are processed by Alipay and PayPal. Your card number and payment account password never pass through our servers.
  • You can email us at any time to export or delete your account data; we act on it within 30 days.
  • We only use essential cookies — no ad trackers.

This Privacy Policy describes how GPLlib ("we") collects, uses, and shares information about you when you use our website gpllib.com and related services. By using the service, you agree to the collection and use of information in accordance with this policy.

GPLlib operates as an independent service. This policy applies to all users, regardless of location.

Information We Collect

Account Information

When you create an account, we collect your Name, Email Address, and a hashed password. If you sign in with a third-party account (QQ, Google, GitHub), we store the unique user identifier, nickname, and avatar URL that platform returns, along with the authorization tokens needed to maintain the link. You can unlink at any time under "Settings → Connected accounts"; unlinking deletes the corresponding record.

Payment Information

Billing is processed by Alipay (CNY) and PayPal (USD). We store only the order number, amount, currency, payment method, and the transaction reference the payment provider returns, for reconciliation and invoicing. We never view, transmit, or store your full card number, CVV, bank account, or payment account password — those are handled entirely on the payment provider's own pages and servers.

Download and Usage Logs

We log every package download tied to your account: timestamp, package and version, download method, IP address, and the region that IP resolves to. These logs power your download history and are used to enforce download quotas and prevent abuse. Logs are kept for 24 months.

Technical and Device Data

When you access the service, we automatically collect:

  • IP address (retained for 90 days for abuse prevention)
  • Browser type and version (user agent string)
  • Referring URLs and pages visited
  • Date and time of requests

Support Communications

If you contact our support team, we keep a record of the conversation. It's used to resolve your issue and improve the service. We never use support conversations for marketing purposes.

Data Collected by the Connector Plugin

GPLlib Connector (our optional WordPress plugin) sends a site token to our servers to authenticate requests, and records the domain of the site you linked, the IP address it was registered from, the number of managed packages, and the time of the last check-in — used for authorization and quota accounting. It does not read or upload your site's content, database, or user information.

Data Type Why We Collect It Retention Period
Email AddressAccount identity, notificationsUntil account deletion
Orders and transaction referencesBilling, reconciliation, invoicingAs long as the law requires
Third-party sign-in authorization dataMaintaining the account linkUntil unlinked or account deleted
Download logs (incl. IP and region)History, quotas, abuse prevention24 months
Sign-in IP and regionSecurity and anomaly detectionUntil account deletion
Email delivery logs (incl. message body)Delivery troubleshooting and dispute evidencePurged automatically after 90 days by default
Support messagesIssue resolution3 years

How We Use Your Information

We use the information we collect to:

  • Deliver the service — Authenticate your account, process downloads, and sync the Connector plugin.
  • Billing and invoicing — Complete payments, issue receipts, and record how long your plan runs.
  • Transactional emails — Send receipts, password resets, update alerts for packages you follow, and critical service notices. We don't send marketing emails unless you explicitly opt in.
  • Service improvement — Aggregate usage data helps us prioritize which packages to add and where the product is slow.
  • Security and fraud prevention — Detect unusual access patterns, block credential stuffing, and investigate abuse reports.
  • Legal compliance — Retain billing records as required by applicable law.

We never use your data to train machine learning models, sell advertising, build behavioral profiles, or share it with data brokers.

Sharing & Third Parties

We only share data with third parties in the following cases:

Service Providers

We work with a small number of vendors who process data under our supervision and a data processing agreement:

  • Alipay, PayPal — Payment processing
  • Email service providers — Transactional email delivery (receipts, verification codes, notifications)
  • Cloudflare — Bot verification, CDN and DDoS protection, package object storage and download delivery
  • Cloud server and CDN providers — Website and database hosting

These providers only access the data required to do their job. They're contractually prohibited from using it for any other purpose.

Our service runs on rented cloud servers and object storage. Personal data is stored only on the primary servers we control; the edge nodes used for content delivery carry nothing but the public package catalog — no account or order data.

What We Never Do

  • We never sell personal data to any third party.
  • We never share data with ad networks.
  • We never give plugin developers or brands in the catalog access to your data.

Cookie

We use the bare minimum of cookies. All cookies are first-party (set by gpllib.com, not third-party scripts).

CookiePurposeDuration
wordpress_logged_in_*Authentication — keeps you signed in (set by WordPress core)Session; longer if you check "Remember me"
gpl_langRemembers the interface language you chose1 year
gpl_gh_oauthCross-site request protection token during GitHub sign-inA few minutes; expires as soon as sign-in completes

When bot verification is enabled, Cloudflare Turnstile sets its own cookie to identify automated requests. Beyond that, we use no analytics cookies, advertising pixels, or third-party tracking scripts. If we ever add optional analytics, it will be opt-in only.

Data Retention

We retain your personal data only as long as needed for the purposes above. When you delete your account, we delete your personal data within 30 days, except where the law requires retention (billing records are kept for 7 years under tax regulations).

Download logs are permanently deleted after 24 months. Email delivery logs are purged automatically by a scheduled job after 90 days by default. Anonymized aggregate download statistics (with no personal identifiers) may be kept indefinitely for product improvement.

Security

We take reasonable technical and organizational measures to protect your data:

  • All traffic is encrypted with TLS 1.3.
  • Passwords are hashed with bcrypt (cost factor 12). We never store plaintext passwords.
  • Connector site tokens are stored as hashes; we cannot recover the plaintext.
  • Your account license key is visible in your dashboard — do not share it. If you suspect it has leaked, contact us to have it reset.
  • Database access is limited to application servers; there are no public endpoints.
  • Servers are isolated on a private network with firewall rules restricting outbound traffic.

No system is perfectly secure. If you find a security issue, please report it responsibly to [email protected] rather than disclosing it publicly. We respond to all security reports within 48 hours.

Your Rights

Regardless of where you live, you have the following rights over your personal data:

  • Access and export — Email us and we will provide a copy of your account data in a machine-readable format.
  • Correction — You can change your display name yourself under "Settings → Profile"; email us for anything else.
  • Deletion — Email us to request deletion of your account and associated personal data, except billing records the law requires us to keep.
  • Unlink third-party accounts — Unlink at any time under "Settings → Connected accounts"; unlinking deletes the corresponding authorization record.
  • Opt Out of Email — Turn off non-essential email at any time under "Settings → Notifications"; messages related to account security cannot be disabled.

To exercise any right that self-service tools in your account can't handle, email [email protected]. We respond within 30 days. Reasonable requests are free.

Children's Privacy

GPLlib is a professional developer tool and is not directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact [email protected] and we will delete the account and associated data immediately.

Policy Changes

We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. For material changes — especially ones that expand how we use your data — we'll notify all active subscribers by email at least 14 days before the change takes effect, giving you time to close your account if you disagree.

Continuing to use the service after a policy change constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights:

We aim to respond to all privacy-related inquiries within 5 business days.