confish

Privacy Policy

Last updated: 10 July 2026

1. Introduction

confish (“Service”), available at https://confi.sh, is operated by Confish (“we”, “us”, or “our”). Confish is a trading name of Gega Nizharadze, a sole trader based in the United Kingdom.

This Privacy Policy explains how we collect, use, and protect your personal information. It should be read alongside our Terms & Conditions.

2. Information We Collect

Personal Data

When you create an account, we collect:

  • Name and email address
  • Authentication data (if you sign in via a social provider)
  • The timestamp of your most recent login and the IP address of your active session

Data You Store

The Service is designed to store data you upload through the dashboard or API - configuration values, log entries, feed items, and action payloads. These may include API keys, secrets, or other sensitive data. You are responsible for what you choose to store. We hold this data on your behalf solely to provide the Service and do not access it except where necessary for support, security, or legal obligations.

Usage and Server Logs

We automatically collect IP address, browser type, request paths, and device information for security, fraud prevention, and debugging purposes. Server-side application logs are retained by our hosting provider (Laravel Cloud) for up to 30 days and are then automatically purged.

Cookies

We use only essential cookies (session and CSRF tokens) for authentication and security. We do not use advertising, analytics, or third-party tracking cookies. Refusing essential cookies will prevent you from signing in.

3. How We Use Your Information

We use your information to:

  • Provide and operate the Service
  • Manage your account and process payments
  • Send transactional emails (verification codes, password resets, billing)
  • Detect, prevent, and address technical issues or abuse
  • Improve the Service

We do not sell your data, use it for advertising, or send marketing emails. We do not engage in automated decision-making or profiling that produces legal effects.

Legal basis for processing (UK GDPR Article 6)

  • Contract - providing the Service, managing your account, and processing payments (Article 6(1)(b)).
  • Legitimate interests - securing the Service, preventing fraud and abuse, debugging, and producing aggregate usage insights (Article 6(1)(f)).
  • Legal obligation - retaining billing and tax records for the periods required by HMRC (Article 6(1)(c)).

4. Data Retention

We retain personal data only as long as necessary to provide the Service:

  • Account data - for as long as your account is active
  • Server logs - up to 30 days
  • User-submitted log entries (Free plan) - up to 14 days or 500 entries per environment, whichever is smaller
  • User-submitted log entries (Pro plan) - up to 30 days or 5,000 entries per environment, whichever is smaller
  • Action history - up to 50 actions per environment
  • Feed items - until you delete or replace them, or until an optional TTL you set expires them

When you delete your account, all data is permanently removed after a 14-day grace period. During that period, you can sign in to cancel the deletion. After the grace period, no recovery is possible.

5. Data Sharing

We share data with third-party providers solely to operate the Service:

ProviderPurposeRegion
PaddlePayment processingUK
Laravel CloudApplication and database hostingEU
MailtrapTransactional email deliveryEU
SentryError tracking and performance monitoringEU
PostHogProduct analyticsEU
GitHubSocial authenticationUS

Where personal data is transferred outside the UK or EEA (currently to GitHub in the United States), we rely on the UK International Data Transfer Agreement and Standard Contractual Clauses to ensure an equivalent level of protection. We may also disclose data if required by law or to protect the rights, property, or safety of users or others.

6. Payments

We do not store payment card details. All payment information is handled by Paddle, who adheres to PCI-DSS standards.

7. Security

We use commercially reasonable measures to protect your data, including HTTPS, hashed passwords, and access controls. However, no method of transmission or storage is 100% secure.

8. Your Rights (UK GDPR)

You have the right to:

  • Access, correct, or delete your personal data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

Contact support@confi.sh to exercise these rights. We will respond within one month. You may also lodge a complaint with the ICO.

9. Children's Data

The Service is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us at support@confi.sh and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. We will update the date above. Continued use of the Service constitutes acceptance.

11. Contact

Questions? Contact us at support@confi.sh.