Privacy Policy
Last updated 15 September 2026 · Terms of Service
What the Wall knows about you, why, who sees it and for how long — whether you are a developer with a workspace or someone who bought a tool. Short version: we hold what an account and a purchase need, we do not track or advertise, and each developer's buyers stay in that developer's own pool.
1. Who we are, and who you are to us
The Wall is run by Toolaby, the operator of toolaby.app and toolaby.com ("Toolaby", "we"). It runs accounts, licences and subscriptions for browser extensions that developers sell.
If you are a developer with a workspace, Toolaby decides why and how your data is processed: we are the controller.
If you bought a tool and signed in on a developer's address (something like their-name.toolaby.app), the developer is the controller of your account and purchase data and Toolaby processes it for them, under our terms. Questions about your purchase go to the developer first; their support address is at the bottom of every page of theirs. For the parts Toolaby decides on its own — keeping the service secure and free of abuse — Toolaby is the controller, and this policy tells you what those are.
2. What we collect from developers
Account
Your email address and, if you give it, your name. Sign-in is by one-time link, so there is no password to hold.
Workspace
Its name, website and support address (shown to your buyers); the id of the Stripe account you connect, never its bank or card details; a sending domain if you verify one.
Tools
Names, prices, plans, free limits, versions, checkout settings — what you configure.
Keys
A signing key per workspace, made by us and stored encrypted. Its public half is published so your extension can verify tokens.
Sessions
The address and browser each sign-in came from, for as long as the session lasts.
3. What we hold about buyers, for the developer
Account
Your email address and, if you gave it, your name — in a pool that belongs to that one developer. Signing in with one developer does not create anything with another.
Purchases
Stripe's references for what you bought (customer, checkout session, payment), the licence or subscription state, and when it started, renewed, ended or was refunded. Card details never reach us; Stripe holds them.
Devices
For each extension you connect: a random install id, the public half of a key the extension made on your device, which tool it is for, and when it was last seen. This is how a licence knows which devices use it.
Free use
How many free uses a device has taken of a tool that has a free tier.
Sessions
The address and browser each sign-in came from, while the session lasts.
4. What the extension sends
The client library we give developers, inside their extension, sends the Wall: the install id and the key described above, the tool's id and version, timestamps and single-use numbers that make each request unforgeable, and — once you have signed in from the extension — a token that proves the link between your account and that device. That is all it needs to answer "is this device entitled?" and "how many free uses are left?".
It does not send the pages you visit, what you type, or anything the extension does on a website. What the developer's own code does beyond the library is the developer's, described in their store listing and their privacy notice.
5. What is collected automatically
Request logs. Our hosting provider keeps short-lived logs of requests — address, path, time, browser — for operating the service. We use the address of a request to rate-limit sign-in and licence checks and to recognise abuse: the same device claiming to be many, a licence key tried from an unusual number of places.
Cookies. One session cookie when you sign in — scoped to the address you signed in on, so a developer's dashboard and a buyer's pages never share one — and a display preference kept in your browser. No analytics, no advertising, no third-party cookies, no tracking across sites.
6. What we use it for
- To run the service: sign you in, know what you are entitled to, unlock the tool on your devices, send the emails the account needs (a sign-in link, a licence, a receipt is Stripe's).
- To let developers see and support their buyers: who bought what, on how many devices, what needs attention.
- To keep the service secure and fair: rate limits, replay protection, abuse detection, revoking a licence that is refunded or shared beyond its limit.
- To meet legal obligations, and to answer you when you write to us.
Not to advertise, not to profile, not to sell. Under the GDPR our bases are the contract with you (or with the developer, for buyers), our legitimate interest in a secure service, and legal obligation.
8. Where it lives
In the European Union — Frankfurt and Stockholm, as listed above. The providers are companies that also operate outside the EU and are bound to us by data processing terms with the European Commission's standard contractual clauses. Stripe processes payments under its own arrangements.
9. How long we keep it
- Sessions end on their own; the sign-in link expires after five minutes and works once.
- Account, purchase, licence and device records: for as long as the account or the purchase exists, then as long as the developer's legal obligations require — a purchase record outlives the licence.
- Security and abuse records: no longer than twelve months.
- When you ask us to delete your data, we do so within thirty days, keeping only what the law requires — and, for a buyer, what the developer must keep for the sale.
10. Your rights
You can ask to see the data we hold about you, to correct it, to have it deleted, to receive a copy, and to object to or restrict its processing. Write to hello@toolaby.com and we answer within a month. If you are a buyer, your developer may answer, since the data is theirs to decide about; we help them do it. You can also complain to the data protection authority where you live.
11. Security
Everything travels over HTTPS. Signing keys are encrypted at rest and rotated when a developer asks. Every table is protected by row-level security, and each workspace's buyers are kept in their own pool. Card numbers never touch the Wall. If you find a weakness, tell us at hello@toolaby.com and we will act on it and thank you.
12. Children
The Wall is not directed at children under sixteen and we do not knowingly hold their data. If you believe a child has an account, write to us and we remove it.
13. Changes to this policy
When we change what we collect or why, we update this page and its date, and for changes that matter we email the address on your account before they take effect.
14. Contact
Toolaby · hello@toolaby.com