Privacy Policy
Last updated: March 14, 2026
This Privacy Policy describes how Magic Monkei collects, uses, and protects your personal information when you use our service.
1. Information We Collect
We collect the following information when you create an account and use our service:
**Account information**: name, email address, phone number (optional), country, and profile picture. **Authentication data**: if you sign in via Google or Discord, we receive your public profile information from those services. **Payment information**: payment details are processed and stored by Stripe — we only store your Stripe customer ID, not your card details. **Usage data**: subscription status, billing history, and service access logs. **Technical data**: IP-based country detection (via Cloudflare) for currency localization.
2. How We Use Your Information
We use your information to: provide and maintain your account and subscription; process payments and manage billing; generate your Tinfoil shop credentials; send transactional emails (verification, password reset, subscription updates); localize pricing based on your region; operate our affiliate and referral program.
3. Third-Party Services
We share data with the following third-party services as necessary to operate Magic Monkei:
**Stripe**: payment processing and subscription management. **Google OAuth**: optional sign-in authentication. **Discord OAuth**: optional sign-in authentication. **Amazon Web Services (SES)**: sending transactional emails. **Cloudflare**: CDN, DDoS protection, and IP-based geolocation.
4. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, we will permanently remove your personal data from our systems. Some data may be retained in backups for a limited period or as required by law. Payment records processed by Stripe are retained according to Stripe's data retention policies.
5. Your Rights
You have the right to: access your personal data through your account Settings; update your profile information at any time; delete your account and all associated data from the Settings page; request a copy of your data by contacting us; withdraw consent for optional data processing.
6. Data Security
We implement appropriate technical measures to protect your personal data, including encrypted connections (HTTPS), secure password hashing, and access controls. However, no method of transmission over the internet is 100% secure.
7. Cookies
We use essential cookies to maintain your session and authentication state. We do not use third-party tracking or advertising cookies.
8. Children's Privacy
Our service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the service. We encourage you to review this page periodically.
10. Contact
If you have questions about this Privacy Policy, please contact us at [email protected].