Privacy
This page describes what weaponeer.io actually stores today. It is a first draft, not legal advice.
Who runs it
Operator: weaponeer.io. Privacy requests: admin@weaponeer.io.
What is stored
An account holds your name, email, a password hash, session tokens (and the IP address and user-agent recorded with each session), role (user or admin), whether Workbench access is on, and a trial expiry timestamp if you redeemed a code. Setups store a name plus the JSON snapshot of the workbench state (payloads, surrogate, scene, catalogue edits). Emails the app tries to send are logged (address, subject, template, status) so delivery can be debugged.
Who sees it
Your setups are scoped to your account. Admins on this install can open the system page, which shows whether integrations are configured and the email log — not API keys.
Processors
Better Auth runs sign-in on this app. When Polar keys are set, Polar receives your name and email on sign-up so checkout can attach later; this app does not store Polar identifiers. Polar also handles checkout. Resend sends mail when a key is set. Until those keys exist, nothing leaves this machine for those jobs.
Cookies
The session cookie is essential to staying signed in. There is no analytics, advertising, or embedded third-party script to consent to, so there is no banner. A disclaimer acknowledgment is stored in this browser (localStorage) so the workbench does not ask again; it is not sent to the server.
Deletion
Settings → Delete account requires your current password, then asks Better Auth to remove the user and revoke sessions. Setups cascade with the user row. Email log rows addressed to that account are deleted with it.