StateLens StateLens

Documentation Privacy

Privacy

What this website keeps about you, who else holds a part of it, and what you can do about it, written as the site actually works. The site is run by Luca Briguglia, and support@statelens.dev is where to ask anything this page does not answer. The terms the tool is used under are the licence; this page is about the website and the hosted demo, not about what the tool reads in your own stores, which never leaves your own host.

On this page

What an account holds

An account is an email address and a password, kept as a hash that cannot be turned back into the password, or the identity Google asserts when you sign in with Google, which is your name and address there and never your Google password. With it the site keeps whether the address has been confirmed, and whatever you add on the account's own pages, such as two-factor authentication.

A purchase is recorded against the account that made it: Paddle's transaction and subscription ids, the edition and the term bought, the amount and currency, and the period it covers. That is what the account's Purchases page shows. The payment itself — the card, the invoice, the tax — is held by Paddle, the merchant of record, under its own policy; the site never sees a card number.

The pull token that pulls the tool's image is named after the account's id on the registry, and its password is handed to you once and kept nowhere.

Back to top

What goes out as email

The site sends email through Postmark: the link that confirms an address, the link that resets a password, the licence certificate for a purchase, and the messages written in the support and contact forms, which go to support@statelens.dev with the name and address you gave, so that they can be answered. Postmark keeps a copy of what it sent for a short while, under its own policy, and no other third party receives email on the site's behalf.

Back to top

Cookies and the browser

The site sets a cookie that keeps you signed in, a cookie that protects the forms against being posted from elsewhere, and a short-lived cookie that carries something from one page to the next, such as a password you have just made. The light-or-dark choice is kept in your browser's own storage and is never sent. There are no analytics, no advertising and no tracking. The pricing page loads Paddle's checkout script, so that a purchase can be made there; what that script keeps is under Paddle's policy.

Back to top

Where it is and for how long

Everything the site keeps is in a database of its own in Microsoft Azure's UK South region, which only the site reaches. An account and what hangs off it are kept until the account is deleted. The platform's logs, which hold the addresses requests came from and what the application wrote about them, are kept for thirty days and then gone.

Back to top

What you can do

The account's Personal data page, among its own pages, downloads everything the site holds about the account as a file, and deletes the account outright, purchases and all; Paddle keeps its own record of a sale for as long as the law asks of a merchant. For anything else — a question, a correction, a copy, an objection — write to support@statelens.dev.

Back to top

The hosted demo

demo.statelens.dev is an instance of the tool over made-up sample data, open by invitation. Signing in to it goes through the owner's Microsoft Entra tenant, which holds the identities it admits; the demo keeps a sign-in cookie, and its log says who uploaded or removed what, so that a change to a shared instance can be traced.

Back to top

Changes

Changes to this page are made here, with their date. First written on 5 October 2026.

Back to top