Privacy Policy
Last updated: 25 June 2025
1Who we are
Controller: Petru Rares Sincraian, Carrer Ample 31, 08270 Navarcles, Spain ("I", "me" or "pepy.tech").
For any privacy-related questions or to exercise your rights, email privacy@pepy.tech.
2What pepy.tech does
pepy.tech provides aggregated download analytics and usage insights for open-source Python packages.
3Personal data I collect
Category | Data elements | Purpose | Legal basis (GDPR) |
---|---|---|---|
Account data | Username, email address, hashed password, project opt-in preferences | Create and maintain your account; authenticate you | Contract Art 6 (1)(b) |
Communication data | Email address; email engagement metrics (open rate, bounces) | Send the monthly report you explicitly request | Consent Art 6 (1)(a) |
Usage logs | IP address, timestamp, requested URL, HTTP headers, user-agent | Prevent fraud, debug, generate aggregated stats | Legitimate interest Art 6 (1)(f) |
Cookies / local storage | Session ID, CSRF token, login status flag | Keep you signed in and secure the service | Contract Art 6 (1)(b) |
Analytics | Pseudonymous aggregate usage events collected by Cloudflare Analytics | Understand traffic and improve the site | Legitimate interest Art 6 (1)(f) |
Advertising | Contextual ad request data handled by Carbon Ads & EthicalAds (may include IP and user-agent) | Serve non-personalised ads that fund the service | Legitimate interest Art 6 (1)(f) |
pepy.tech does not use automated decision-making or profiling that produces legal or similarly significant effects.
4How I share data
I disclose personal data only to the service providers listed below, strictly for the purposes described.
Provider | Role | Location & safeguards |
---|---|---|
Cloudflare, Inc. | CDN, DDoS protection, DNS, Web Analytics | USA · EU-US Data Privacy Framework & SCCs |
DigitalOcean, LLC | Primary application hosting | USA · SCCs |
Hetzner Online GmbH | Database & object-storage servers | Germany |
Amazon Web Services, Inc. (AWS S3) | Off-site encrypted backups | USA · SCCs |
Carbon Ads | Contextual advertising network | USA · SCCs |
EthicalAds (Read the Docs, Inc.) | Contextual advertising network | USA · SCCs |
All providers are bound by data-processing agreements that limit use to my instructions and require appropriate security.
5International transfers
Where data leaves the EEA (e.g., to the USA), transfers rely on Standard Contractual Clauses (Art 46 GDPR) or the recipient's certification under the EU-US Data Privacy Framework.
6Data retention
- Account data – kept until you delete your account or 24 months after last login, whichever comes first.
- Email marketing consents – kept until you withdraw consent (unsubscribe).
- Server & access logs – deleted after 2 years.
- Back-ups – encrypted and rotated every 30 days; longest copy retained for 90 days.
I may keep limited data longer where required by law (e.g., security or tax obligations).
7Security measures
- All traffic is encrypted in transit
- Passwords are hashed and salted.
- Firewalls, two-factor authentication on admin access, and least-privilege roles.
- Continuous monitoring and automatic patch management.
8Your rights (EU/EEA & UK)
You can access, correct, delete, restrict or export your personal data and object to certain processing.
To exercise any right, email privacy@pepy.tech. You also have the right to lodge a complaint with your local supervisory authority (in Spain: AEPD).
9Cookies & similar technologies
I use only essential cookies:
- auth_session – keeps you logged in.
- access_token – keeps you logged in.
Cloudflare & ad partners may place their own first-party cookies strictly to provide aggregated analytics or frequency-capping; no cross-site tracking cookies are set.
Your browser settings allow you to delete or block cookies, but the site may not function correctly without them.
10Children's privacy
pepy.tech is not intended for children under 13. I do not knowingly collect personal data from children. If you believe a child has provided me personal data, please contact me so I can delete it.
11Changes to this policy
I may update this Privacy Policy from time to time. If changes are material, I will notify users in the app. The "last updated" date at the top reflects the latest revision.