Privacy Policy
Last Updated: June 2026
At panic.design, we build tools for resilience, and that philosophy extends to your data. We adhere to a strict data-minimization architecture. This Privacy Policy outlines what we collect, why we need it, and how we protect it.
1. Data Collection & Authentication
- Third-Party OAuth: We use GitHub OAuth exclusively for registration and login. We retrieve only your baseline profile (Email, Name, Avatar) to establish your developer identity.
- Cookies: We utilize secure, HTTP-only cookies strictly for session management and identity authentication. We do not use tracking or advertising cookies.
- Bot Protection: To defend our control plane against automated abuse, we implement Cloudflare Turnstile. This service operates in a non-interactive mode and may collect ephemeral telemetry, including your IP address and browser fingerprint, solely for human-verification purposes. For more details, please review the Cloudflare Turnstile Privacy Policy.
- Anti-Abuse Telemetry: We collect necessary environmental metadata (e.g., request rates, geographic origin) to validate environment security and enforce our rate-limiting quotas.
2. Edge Passthrough & Upstream Disclosure
CRITICAL NOTICE: When you execute a RUN Cloud Injection directive, our Cloudflare Workers act as a proxy. To prevent our infrastructure from being utilized as an anonymous attack vector, we actively pass through the request.cf object to your specified Target Hostname. This means the target server will receive metadata including your approximate geographic coordinates (Longitude/Latitude) and IP reputation. This is a mandatory upstream anti-abuse mechanism.
3. Data Retention & Cryptographic Anonymization
We believe in the right to be forgotten. Upon account deletion:
- All active Edge Chaos Tokens (JWTs) are instantaneously revoked and blacklisted.
- Your Personally Identifiable Information (PII) — including your email, name, and avatar — is permanently scrubbed from our active databases.
- To preserve the integrity of our systemic audit logs, your records are retained but cryptographically anonymized, replaced entirely by unidentifiable random hashes.
4. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to request access to your data and request its deletion (which is executed via the cryptographic anonymization detailed above). We do not, and will never, sell your personal information.