Privacy Policy
Last updated: 5 October 2026
The short version
- We collect only what we need to sell you a license, run your optional account, and stop keys being shared.
- Card details go straight to Stripe. We never see them.
- Your license key is stored only as a one-way hash, plus an encrypted copy if you use an account.
- Your password never reaches our servers. We only store a scrambled value that can't be turned back into it.
- No ads, no tracking cookies, no analytics, and we never sell your data.
1. Who is responsible
Marcus Lennander and Melker Ljungkvist, Sweden, who run FriendClient (Friendclient.co) together, are jointly responsible (joint data controllers) for the personal data described here. Contact: friendclient.support@gmail.com.
2. What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Email address, plan, purchase time, and Stripe customer, payment and subscription IDs | To deliver and manage your license, send your key, and handle support, refunds and disputes | Contract; legal obligation (bookkeeping) |
| If you make an account: your email, a scrambled version of your password (your real password never leaves your browser), and if you log in with Discord or Google, the account ID and email they share with us | To log you in, show your keys and let you manage your subscription | Contract |
| Login sessions: a random token (we store only its hash) and when it was created and expires | To keep you logged in and let you log out | Contract; legitimate interests (security) |
| The display name you choose at checkout (optional) | Shown inside FriendClient as the name your license belongs to | Contract |
| Your license key | To check that FriendClient is licensed. We store a one-way hash, plus an encrypted copy so it can be shown back to you: for 7 days after a guest purchase (then deleted), or for as long as the key belongs to your account. | Contract |
| Device data when FriendClient checks your key: a hashed hardware identifier (never your raw hardware details), the client version, and when the device first and last checked in | To enforce the device limit and stop keys being shared | Contract; legitimate interests (preventing abuse) |
| A log of license events (created, activated, renewed, revoked) | Support, security and resolving disputes | Legitimate interests |
| IP address and basic request data | Processed by Cloudflare to deliver the site, limit abuse and block attacks. We don't store IP addresses in our database. | Legitimate interests (security) |
| Messages you send us | To answer you | Legitimate interests |
Payment details (such as your card number) are collected directly by Stripe on its checkout page. We never see or store them.
3. Cookies and tracking
We only use strictly necessary cookies: one that keeps you logged in (for up to 30 days, removed when you log out), and a short-lived one (10 minutes) while you log in with Discord or Google. We don't use analytics, advertising or tracking tools. Stripe's checkout pages and Cloudflare may use strictly necessary cookies for security and fraud prevention.
4. Who we share data with
We never sell your data. We use these service providers, who process data for us under data processing agreements:
- Stripe: payments, fraud prevention and the subscription portal. For some payment data, Stripe is also an independent controller (Stripe's privacy policy).
- Cloudflare: website hosting, database and security (Cloudflare's privacy policy).
- Discord and Google: only if you choose to log in with them. They tell us your account ID and email, and their own privacy policies apply to your use of their login.
- Our email provider: sends your license key and password-reset emails, if email delivery is turned on.
We may also disclose data where the law requires it, or to protect our rights in a dispute.
5. Transfers outside the EU/EEA
Some of these providers process data outside the EU/EEA, for example in the United States. Those transfers rely on recognised safeguards such as the EU–US Data Privacy Framework or the EU Standard Contractual Clauses.
6. How long we keep data
- Orders: for as long as your license exists, then for as long as accounting law requires.
- Your account: until you ask us to delete it. Login sessions expire after 30 days and password-reset links after 1 hour.
- Encrypted copy of your key: deleted 7 days after a guest purchase; kept while it belongs to your account.
- Device records: while your key exists; removed when your devices are reset.
- Support messages: as long as needed to help you, then deleted.
7. Your rights
You have the right to access, correct or delete your personal data, to restrict or object to how we use it, and to receive it in a portable format. Email friendclient.support@gmail.com to use these rights. If we delete the data your license depends on, your key will stop working.
You can also complain to the data protection authority where you live. In Sweden that is IMY (Integritetsskyddsmyndigheten).
8. Children
FriendClient isn't aimed at children under 13. If you're under 18, a parent or guardian should make or approve the purchase.
9. Security
Everything is served over HTTPS. License keys are stored only as hashes, temporary key copies are encrypted, and our admin tools are protected by access control. No system is perfectly secure, but we'll tell you and the authorities as the law requires if a breach affects your data.
10. Changes
If we change this policy, we'll update the date at the top of this page. For important changes, we'll tell existing customers.