CharisTools

Privacy Policy

Last updated 2026-08-28

1. Who this policy covers

This policy explains what CharisTools (“we”, “us”) collects when you create an account or use a CharisTools product — CharisPDF, CharisRemote, and any future product listed on this portal — through this portal, and what control you have over that data.

2. What we collect

  • Account data: the email address you sign up with. Your password is never stored or seen by us — it is managed entirely by Amazon Cognito, our authentication provider.
  • Content you submit: if you post a rating, comment, bug report, or feature request on this portal, we store that content and associate it with your account.
  • Consent record: the date and time you accepted this Privacy Policy, so we can demonstrate consent was given.

We do not use third-party analytics or advertising trackers on this portal today. If that changes, this policy will be updated first.

3. Why we collect it

  • To create and secure your account, and let you sign in.
  • To display content you choose to submit (reviews, comments, bug/feature requests) back on the portal.
  • To track approved bug reports and feature requests as work items: when we approve a bug report or feature request you submitted, its title and description (not your name or any other account identity) are copied into that product's own development issue tracker so it can be planned and worked on there.
  • To respond if you contact us for support.
  • To improve CharisTools products.

4. Where it's stored

Everything above is stored in our own AWS infrastructure — Amazon Cognito for account/authentication data, and Amazon DynamoDB for submitted content. We don't sell your data or share it with data brokers or advertisers. AWS acts as our infrastructure provider (a data processor), not an independent user of your data.

One exception: for products where we track work on GitHub, if a bug report or feature request you submitted is approved, its title and description are copied into that product's own GitHub issue tracker so our development team can plan and track the work. Only that text is copied — never your name, email, or any other account identity. From that point, that copy is also held by GitHub, under GitHub's own terms, as a second data processor for that specific content. As noted in section 5, our redaction check is best-effort and can't catch personal details written into plain prose, so please avoid including any in what you submit — this applies doubly to anything that may be copied to GitHub.

5. How long we keep it

We keep your account and submitted content for as long as your account is active. If you delete your account (see below), we delete your account record itself — your email address and login. Content you submitted (reviews, comments, bug reports, feature requests) stays on the portal, since it documents the product rather than you personally, but we sever its link to your account: it's re-attributed to “Anonymous” and no longer connected to your email in our systems.

Before anything you submit is stored, we run an automatic, best-effort check for things that look like an email address, phone number, payment card number, or government ID number, and replace them with a placeholder (e.g. [redacted-email]) before it's published. This is a backstop, not a guarantee: it can't catch a name or address written in plain prose. Please still avoid including personal details — yours or anyone else's — in anything you post; the submission form repeats this warning.

6. Your rights

You can, at any time:

  • See what email address and content are on your account.
  • Correct your account email through normal account settings.
  • Delete your account yourself, from your account's Dashboard — no need to email us to ask. You're locked out immediately; full deletion completes automatically shortly after. See the next section for exactly what this does and doesn't remove.
  • Contact us at privacy@charistools.example with any other privacy question or request.

7. Deleting your account

Signed-in users can delete their own account from the Dashboard's Account section. This happens in two steps, both automatic: your account is disabled immediately — you can't sign back in, on any device, from that moment — and then permanently deleted shortly after (typically within about 15 minutes), once an automated check confirms everything you posted has actually been anonymized. That short delay exists to verify the anonymization worked, not to give anyone a window to change their mind or to keep using the account.

It does not remove reviews, comments, bug reports, or feature requests you submitted: those stay on the portal so the product record they document isn't lost, but they're re-attributed to “Anonymous” and the link back to your account is severed. This cannot be undone and is not reversible by us after the fact.

8. Security

Data is encrypted in transit (HTTPS) and at rest, using AWS's built-in encryption for Cognito and DynamoDB. Access to the underlying AWS account is restricted to those operating CharisTools.

9. Children's privacy

CharisTools is not directed at children, and we do not knowingly collect data from children under 13.

10. Changes to this policy

If we change this policy, we'll update the date at the top of this page. Material changes will be communicated to account holders.

11. Contact

Questions about this policy or your data: privacy@charistools.example.