CentralizeMe

Privacy Policy

Last updated: See what changed

Nestor-reviewed for soft launch, current as of the date above. Professional legal review remains pending, particularly for GDPR/international-transfer compliance and controller disclosures, before paid launch.

Contents

Data we collect

In short: account information, project metadata, encrypted secrets you store, and basic product analytics.

CentralizeMe collects the information needed to provide and secure the service. The categories we handle include:

  • Account information, such as your email address, identity-provider details, and subscription status.
  • Project metadata, such as project names, configuration metadata, and access relationships.
  • Encrypted secrets that you choose to store in the service. CentralizeMe does not use these secrets for advertising.
  • Subscription and billing administration information. Paddle handles payment details as its merchant-of-record service requires.
  • Basic product analytics about feature use and reliability so we can understand and improve the service.

Please do not store information in CentralizeMe that you are not authorized to provide or that the service does not need. We may also receive information you send when you contact us about privacy or support.

Why we process it

In short: to run the service. We do not sell data.

We process information to authenticate accounts, operate CentralizeMe, store and monitor project configuration, provide support, secure the service, and maintain its reliability.

  • Provide account access and the project-secrets features you request.
  • Process subscriptions, payments, and related account administration.
  • Detect abuse, investigate security events, troubleshoot failures, and improve product usability.
  • Communicate with you about the service, support requests, and material policy changes.

CentralizeMe does not sell personal data. We use information for the purposes described here and share it with service providers only as needed to operate the service, comply with law, or protect people and the service.

Processors and subprocessors

In short: WorkOS (login), Paddle (payments), AWS (hosting and data storage), and PostHog (analytics).

We use processors and subprocessors to provide specific parts of CentralizeMe. Their own compliance and privacy materials are linked here for due diligence:

  • WorkOS provides login and identity services. Its security page links to its trust and compliance resources.
  • Paddle processes subscription payments and provides merchant-of-record services. Its SOC 2 compliance page describes its security and compliance program.
  • Amazon Web Services (AWS) hosts our infrastructure and stores data as our cloud hosting provider. Its compliance page describes its certifications and compliance programs.
  • PostHog provides basic product analytics through its trust portal.

We remain responsible for choosing processors appropriate for the service and will update this section if the processor set materially changes.

Where data lives

In short: Production data is hosted with AWS in the US East (N. Virginia) region (us-east-1).

CentralizeMe's production infrastructure and data are hosted with Amazon Web Services (AWS) in the US East (N. Virginia) region (us-east-1).

If we change hosting providers, add region options, or make other changes affecting where data is processed or stored, we will update this section before the change takes effect.

How long we keep it

In short: While your account is active, plus up to 30 days for backups after deletion.

We keep account and project information while your account is active so that we can provide the service. When you request deletion, we begin removing your account and project data promptly.

Backups that already existed at the time of deletion are automatically deleted within 30 days, consistent with our standard backup retention window. We do not keep a separate long-term archive beyond that window except where required by law, to prevent fraud, or to resolve an active dispute.

Deletion and your rights

In short: delete your account and your data goes with it.

You can request deletion of your CentralizeMe account and data by contacting privacy@centralizeme.com. We will use reasonable steps to verify the request, then delete the account and the data associated with it in accordance with the retention process described above.

Depending on the law that applies to you, you may also have rights to access, correct, restrict, or object to certain processing, and to receive a copy of information you provided. Contact us to exercise a right or ask a question; we will explain any verification, exception, or response timeline that applies.

The direct summary above refers to your active account and service data. A minimal record may need to remain for a limited period where required by law, to prevent fraud, or to resolve a dispute; the final period for those operational records remains pending confirmation.

Contact

In short: privacy@centralizeme.com.

For privacy questions, requests, or concerns, email privacy@centralizeme.com. Please include enough context for us to understand your request, but do not send secrets or other sensitive material in an email.

This Privacy Policy is a soft-launch draft reviewed by Nestor. Professional legal review remains pending for GDPR/international-transfer compliance and final wording before paid launch.

For the purposes of this Privacy Policy, the data controller is Nestor Mata, operating as an individual (sole proprietor) from Ancón, Panama City, Panama, until CentralizeMe is formally incorporated.

Changes

August 9, 2026: Privacy Policy content authored for soft launch.