Two different collectors
What we collect from you is what a subscription and a licence require. What you collect from your end users — customers who talk to you through a LINE support bot, say — is stored on your machine, and you are the controller of it. Notice and consent obligations for that data are yours.
What we collect
Administrator email, plan and billing cycle at activation or when requesting a free serial; the licence serial; a machine fingerprint (sss_id and the server-issued instance_id); a signature from your local private key; and heartbeat timestamps. Payments are handled by a payment provider — we do not store full card numbers.
What we do not collect
Database contents, SQL statements, knowledge base data, AI conversations and your customers' chat history never reach the licence server. It knows only whether a given machine has a valid subscription.
Data sent to third parties by features you enable
LLM providers receive the prompts you send, using the key you configured. The email gateway receives recipient addresses for verification and OTP mail. LINE and Telegram exchange messages with their APIs when support bots are on. Google Places and Routes receive your queries — and with "what's nearby" lookups, the precise coordinates your browser provides. All of these are optional; a feature you never enable makes no outbound calls.
Why we collect it
Subscription and licence validation, preventing serial cloning, billing and support correspondence, and necessary service notices.
Retention and recipients
Licence and billing records are kept for the life of the subscription and any period the law requires. Beyond necessary processors such as payment and email providers, we do not share them. Retention of anything on your own machine is under your control.
Your rights
You may request access to, a copy of, correction or supplementation of your personal data, or ask us to stop collecting, processing and using it and to delete it. Write to info@all2ultd.com.
Security
Licence traffic uses TLS, licence serials are short-lived JWTs, and machine identity is verified with Ed25519 signatures. Containers communicate over an internal Docker network and the knowledge database publishes no port.