EnvX is built with a zero-knowledge, developer-first philosophy. We do not track, profile, or sell your data, and we cannot read your secrets.
Effective Date: September 24, 2026•Zero-Cookie Policy•Back to Home
Zero-Knowledge Architectural Guarantee:
Your environment variables, API keys, passwords, and project files are encrypted locally on your device with AES-256 GCM. The decryption key never leaves your machine. EnvX servers cannot decrypt, inspect, or log your credentials under any circumstances.
1. Information We Collect
We intentionally minimize data collection to the absolute technical minimum necessary to provide account services and license management:
Account Information: When you register, we collect your email address and an encrypted cryptographic password hash.
Billing & Payment Data: Payment transactions are handled directly by Stripe. EnvX does not receive or store your credit card numbers or banking credentials. We receive only a tokenized Stripe Customer ID.
Machine License Fingerprint: To activate Pro licenses across your devices, the desktop binary sends a one-way SHA-256 hash derived from your motherboard/CPU hardware signature.
2. Information We NEVER Collect
Plaintext Secrets or Keys: Values stored in your .env or Hive vault are strictly local or client-side encrypted before any optional cloud backup.
Filesystem Paths & Source Code: We do not scan, upload, or index your local repositories or source code files.
Keystroke or Telemetry Logs: We do not record keystrokes, OSD search queries, or workflow recordings.
Cross-Site Advertising Cookies: We do not deploy marketing trackers, Google Analytics, Facebook Pixels, or data broker beacons.
3. Third-Party Sub-Processors
We rely on trusted, compliant infrastructure providers that meet SOC 2, ISO 27001, and GDPR standards:
Stripe Inc. (USA / EU): Payment gateway and invoice management.
Cloudflare (Global): DDoS protection and edge caching for static assets.
4. Your Rights (GDPR, CCPA & Global)
Regardless of your country of residence, EnvX extends the highest privacy protections to all developers:
Right to Access & Portability: You may request a machine-readable export of all account profile data stored on our servers.
Right to Erasure ("Right to Be Forgotten"): You can delete your account from your dashboard or by emailing privacy@envx.grod.ovh. All associated database records and active license keys will be permanently purged within 48 hours.
5. Contact Our Data Protection Officer
If you have questions, concerns, or requests regarding your personal data, reach out directly to privacy@envx.grod.ovh.