Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how the operator of pancakeon.top ("Pancake," "we," or "us") processes personal data through the website, accounts, licensing, software, and support (the "Service"). It describes our data practices and does not ask you to waive your rights.
1. Controller and contact
The operator of Pancake acts as the controller for personal data processed directly by the Service. You can submit privacy requests through our official Discord server.
2. Data we collect
We collect only information reasonably necessary to operate, secure, and provide the Service:
- Account data. Email address, password hash, account identifier, username where used, role, account status, account creation and login times, license details, the legal version accepted and acceptance time, and optional account-security information.
- Technical and security data. Registration and recent login IP addresses, hashed hardware identifier, device binding and reset times, software version, release channel, authentication attempts, update or download requests, rate-limit data, and security events.
- Support data. Messages, attachments, account details, and proof of authorization that you choose to provide when asking for support, reporting misuse, or exercising a legal right.
3. How we receive data
We receive information from you, from your browser or Pancake software automatically, from our security infrastructure, and from support providers when needed to address a request.
4. Purposes and legal bases
Where data-protection law requires a legal basis, we process information on these grounds:
- Contract. To create accounts, authenticate users, bind licenses, deliver updates, and provide support.
- Legitimate interests. To protect the Service, prevent fraud, license sharing and misuse, diagnose issues, enforce our Terms, and establish or defend legal claims.
- Legal obligations. To comply with applicable requirements and respond to valid legal requests.
- Consent. For optional processing when we specifically ask for your consent. You may withdraw consent for future processing.
5. Information we require
Account credentials and essential technical and license data are needed to provide the relevant features. If you do not provide this information, we may not be able to create your account, authenticate the software, or provide support.
6. Cookies, sessions, and reCAPTCHA
Pancake sets an essential, secure first-party session cookie, which lasts up to seven days, to keep you signed in. Cloudflare may use cookies required for network security. We do not use first-party advertising cookies or sell browsing profiles.
Google reCAPTCHA helps prevent automated abuse on registration, login, and password-reset forms. Google may receive the CAPTCHA response, IP address, browser or device data, and may set security cookies. Google's handling of that information is described in the Google Privacy Policy. If essential cookies or reCAPTCHA are disabled, authentication features may not work.
7. Service providers and disclosures
We do not sell personal data. We disclose information only where reasonably necessary, including to:
- Cloudflare for network security, database, and file-storage infrastructure.
- Google for reCAPTCHA verification.
- Resend to send password-reset emails you request.
- Discord when you choose to contact our community or support there.
- Advisers, authorities, or other parties when required by law or reasonably needed to protect rights, safety, the Service, or legal claims.
- A successor in a merger, reorganization, financing, or transfer of the Service, in accordance with applicable privacy law.
8. International transfers
Our providers may process information in countries other than yours. If the law limits those transfers, we use a permitted transfer mechanism, such as an adequacy decision, contractual safeguards, or another lawful measure. Contact us for information about the safeguards that apply.
9. Retention
Session cookies last up to seven days, and password-reset links expire after five minutes. Rate-limit data is kept only for the relevant security period. We keep account, license, and security records while the account or license is active, and afterward only as reasonably needed for security, disputes, and legal requirements. When information is no longer needed, we delete or anonymize it, subject to backups and mandatory retention.
10. Security
Passwords and reset tokens are hashed, hardware identifiers are kept in hashed form, sessions are signed, and sensitive traffic is encrypted in transit. We use access controls and abuse-prevention measures appropriate to the Service. No system is completely secure, and we cannot guarantee absolute security.
11. Your rights
Depending on applicable law, you may request access to, correction or deletion of, restriction of, or portability of your data, or object to its processing. You may withdraw consent for future processing and may complain to a competent data-protection authority. These rights may be limited when we must retain information or need it to protect others or address legal claims. We may verify your identity before acting on a request.
12. Children
The Service is not intended for anyone under 18 or below the age of legal majority where they live, and we do not knowingly permit such users. If you believe a minor has provided personal data, contact us. We will review the matter and delete the data where appropriate.
13. Third-party services
Links and integrations may connect to independent third-party services. Their own privacy notices govern data processing they control, for which we are not responsible.
14. Changes to this Policy
We may update this Policy if our processing, providers, or legal requirements change. The latest version and its effective date will appear on this page. We will provide additional notice of material changes when required. Updates do not reduce rights you have under applicable law.