Privacy Policy

Last updated 15 September 2026 · Terms of Service

What the Wall knows about you, why, who sees it and for how long — whether you are a developer with a workspace or someone who bought a tool. Short version: we hold what an account and a purchase need, we do not track or advertise, and each developer's buyers stay in that developer's own pool.

1. Who we are, and who you are to us

The Wall is run by Toolaby, the operator of toolaby.app and toolaby.com ("Toolaby", "we"). It runs accounts, licences and subscriptions for browser extensions that developers sell.

If you are a developer with a workspace, Toolaby decides why and how your data is processed: we are the controller.

If you bought a tool and signed in on a developer's address (something like their-name.toolaby.app), the developer is the controller of your account and purchase data and Toolaby processes it for them, under our terms. Questions about your purchase go to the developer first; their support address is at the bottom of every page of theirs. For the parts Toolaby decides on its own — keeping the service secure and free of abuse — Toolaby is the controller, and this policy tells you what those are.

2. What we collect from developers

Account

Your email address and, if you give it, your name. Sign-in is by one-time link, so there is no password to hold.

Workspace

Its name, website and support address (shown to your buyers); the id of the Stripe account you connect, never its bank or card details; a sending domain if you verify one.

Tools

Names, prices, plans, free limits, versions, checkout settings — what you configure.

Keys

A signing key per workspace, made by us and stored encrypted. Its public half is published so your extension can verify tokens.

Sessions

The address and browser each sign-in came from, for as long as the session lasts.

3. What we hold about buyers, for the developer

Account

Your email address and, if you gave it, your name — in a pool that belongs to that one developer. Signing in with one developer does not create anything with another.

Purchases

Stripe's references for what you bought (customer, checkout session, payment), the licence or subscription state, and when it started, renewed, ended or was refunded. Card details never reach us; Stripe holds them.

Devices

For each extension you connect: a random install id, the public half of a key the extension made on your device, which tool it is for, and when it was last seen. This is how a licence knows which devices use it.

Free use

How many free uses a device has taken of a tool that has a free tier.

Sessions

The address and browser each sign-in came from, while the session lasts.

4. What the extension sends

The client library we give developers, inside their extension, sends the Wall: the install id and the key described above, the tool's id and version, timestamps and single-use numbers that make each request unforgeable, and — once you have signed in from the extension — a token that proves the link between your account and that device. That is all it needs to answer "is this device entitled?" and "how many free uses are left?".

It does not send the pages you visit, what you type, or anything the extension does on a website. What the developer's own code does beyond the library is the developer's, described in their store listing and their privacy notice.

5. What is collected automatically

Request logs. Our hosting provider keeps short-lived logs of requests — address, path, time, browser — for operating the service. We use the address of a request to rate-limit sign-in and licence checks and to recognise abuse: the same device claiming to be many, a licence key tried from an unusual number of places.

Cookies. One session cookie when you sign in — scoped to the address you signed in on, so a developer's dashboard and a buyer's pages never share one — and a display preference kept in your browser. No analytics, no advertising, no third-party cookies, no tracking across sites.

6. What we use it for

  • To run the service: sign you in, know what you are entitled to, unlock the tool on your devices, send the emails the account needs (a sign-in link, a licence, a receipt is Stripe's).
  • To let developers see and support their buyers: who bought what, on how many devices, what needs attention.
  • To keep the service secure and fair: rate limits, replay protection, abuse detection, revoking a licence that is refunded or shared beyond its limit.
  • To meet legal obligations, and to answer you when you write to us.

Not to advertise, not to profile, not to sell. Under the GDPR our bases are the contract with you (or with the developer, for buyers), our legitimate interest in a secure service, and legal obligation.

7. Who sees it

The developer you bought from sees your email, your purchases and your devices for their tool, in their dashboard. No other developer does.

Stripe handles payment on the developer's account; what Stripe holds is under Stripe's privacy policy.

The providers that run the Wall, processing on our instructions and nothing else:

Vercel

Hosting and the code that answers every request. Frankfurt.

Supabase

The database. Frankfurt.

Amazon Web Services

Email delivery (SES). Stockholm.

Upstash

Rate limits and replay protection. Frankfurt.

Beyond these: a buyer's own developer, a lawful request we are obliged to answer, or a successor if Toolaby is ever transferred — with this policy still applying.

8. Where it lives

In the European Union — Frankfurt and Stockholm, as listed above. The providers are companies that also operate outside the EU and are bound to us by data processing terms with the European Commission's standard contractual clauses. Stripe processes payments under its own arrangements.

9. How long we keep it

  • Sessions end on their own; the sign-in link expires after five minutes and works once.
  • Account, purchase, licence and device records: for as long as the account or the purchase exists, then as long as the developer's legal obligations require — a purchase record outlives the licence.
  • Security and abuse records: no longer than twelve months.
  • When you ask us to delete your data, we do so within thirty days, keeping only what the law requires — and, for a buyer, what the developer must keep for the sale.

10. Your rights

You can ask to see the data we hold about you, to correct it, to have it deleted, to receive a copy, and to object to or restrict its processing. Write to hello@toolaby.com and we answer within a month. If you are a buyer, your developer may answer, since the data is theirs to decide about; we help them do it. You can also complain to the data protection authority where you live.

11. Security

Everything travels over HTTPS. Signing keys are encrypted at rest and rotated when a developer asks. Every table is protected by row-level security, and each workspace's buyers are kept in their own pool. Card numbers never touch the Wall. If you find a weakness, tell us at hello@toolaby.com and we will act on it and thank you.

12. Children

The Wall is not directed at children under sixteen and we do not knowingly hold their data. If you believe a child has an account, write to us and we remove it.

13. Changes to this policy

When we change what we collect or why, we update this page and its date, and for changes that matter we email the address on your account before they take effect.

14. Contact