Privacy Policy
This page explains what information Attriax collects, how we use it, how long we keep it, and the responsibilities that apply when you use Attriax in your own apps, sites, or campaigns.
Last updated: April 28, 2026
Throughout this document, "Attriax", "we", "us", or "our" refers to Timofiy Yuriyovych Pavlyshynets, Private Entrepreneur, registered in Ukraine, operating the Attriax platform. The registered address is provulok Pechunky 17, Khust, Zakarpattia Oblast, 90401, Ukraine.
1. Information We Collect
We collect account and workspace data such as your name, email address, display name, role, subscription plan, billing-account context, app memberships, and session metadata used to secure and operate the dashboard.
We also collect service and product data you create or configure in Attriax, including apps, links, dynamic links, Smart Pages, custom-domain settings, webhook endpoints, API key metadata, uploaded media, redirect destinations, preview content, and related operational logs.
Depending on which Attriax products you use, we may also process end-user and device-related data such as stable SDK-managed device identifiers, advertising identifiers where provided by the device (such as the Google Advertising ID or Apple IDFA), Android device identifiers, device model, brand, manufacturer, operating-system version, and screen and display attributes, external user identifiers or names you submit through identify calls, event names and event properties, click and page-view data, deep-link resolution data, install-referrer data, external referrer data, attribution metadata, IP address, user agent, language, timezone, app package identifiers, browser metadata, and anti-abuse or fraud-prevention signals.
2. How We Use Information
We use information to provide and improve Attriax, including authenticating users, serving branded app entry pages, resolving deep links, redirecting traffic, attributing installs or app opens, generating analytics, enforcing plan limits, provisioning and renewing custom-domain certificates, processing uploads, securing accounts, preventing abuse, investigating incidents, and offering customer support.
We also use information for internal operations such as capacity planning, debugging, reliability monitoring, communications about service issues, and enforcing our agreements and platform rules. We do not sell your personal information.
3. Customer Data You Send Through Attriax
If you use Attriax SDKs, links, Smart Pages, webhooks, or related APIs in your own apps, sites, or campaigns, you may send us end-user or business data that you control. That can include device IDs, external user IDs, app events, campaign context, deep-link payloads, install-referrer values, webhook payloads, and destination URLs.
In that context, you remain responsible for the data you choose to collect and send to Attriax, including obtaining any required notices, permissions, or consent from your end users and ensuring that your use of Attriax complies with applicable law, your own privacy disclosures, and any third-party platform requirements.
For account, workspace, support, and website operations data, Attriax generally acts as an independent controller. For customer-submitted end-user analytics and attribution data, Attriax generally acts as a processor or service provider on your instructions. Additional role and provider detail is available on our Data Processing and GDPR page.
4. Sharing and Processing
We share data only where needed to operate Attriax, comply with law, protect the platform, or follow your product instructions. This includes service providers that support hosting, storage, authentication, measurement, geolocation, DNS and TLS certificate operations, customer communications, and payment or billing workflows. In practice this may include Google Firebase for identity and, where enabled, optional website measurement alongside Attriax first-party analytics flows, plus licensed local datasets such as MaxMind GeoLite2 that are operated inside Attriax-managed services.
If you configure webhooks, we will transmit the event payloads you choose to the webhook endpoints you configure. Those endpoints are controlled by you or your vendors, and their processing is governed by their own terms and privacy practices.
We may also disclose information if required by law, legal process, or a good-faith belief that disclosure is needed to protect Attriax, our users, third parties, or the public.
Additional third-party software notices, license references, and provider links are available on our Open Source and Third-Party Notices page.
5. Cookies, Local Storage, and Measurement Technologies
Attriax uses cookies, local storage, session storage, and similar technologies to keep users signed in, remember preferences, support offline queueing for some SDK operations, improve reliability, and measure product usage.
Where customer SDK traffic is sent without a device identifier, Attriax may use a privacy-preserving, cookieless anonymous measure based on app ID, IP address, user agent, and a daily rotating salt to produce aggregate daily analytics. The daily salt rotation is deliberately designed to prevent a stable user profile from being built across days.
Our website or dashboard may also use first-party Attriax analytics and, where supported, Firebase Analytics, a third-party Google service that runs in consent mode with advertising storage disabled. You can read more in ourCookie Policy.
6. Data Retention and Deletion
Analytics and client event data are retained according to the active subscription plan unless a stricter legal, security, or contractual requirement applies. At the time of writing, the standard plan windows are 30 days for Free, 60 days for Indie, 90 days for Startup, and 365 days for Growth. Enterprise retention may be longer, unlimited, or contractually customized.
Account, billing, operational security, and abuse-prevention records may be retained longer where necessary to provide the service, meet legal obligations, enforce agreements, or resolve disputes. When data is no longer needed, we delete, age out, or anonymize it.
7. Deleted Account, App, and Link Data
When you delete an account, app, or link, the record is moved into a private, access-restricted archive table instead of being immediately destroyed. We keep this archive only so a verified administrator can recover from accidental deletions and so we can investigate abuse reports.
Archived records are read-only recovery records. They are not part of normal product queries or reporting and are kept only for recovery, abuse review, dispute handling, or other limited operational and legal needs.
Default retention windows after deletion are 30 days for user accounts and 7 days for apps and links. Once the window passes, the archived record is permanently and automatically removed by a daily background job. You can contact support@attriax.com to request immediate purging of an archived record where the law requires it.
8. Security and International Transfers
We use reasonable administrative, technical, and organizational measures to protect information processed through Attriax. No service can guarantee absolute security, and you are responsible for maintaining the confidentiality of your own credentials, API keys, and team access.
Attriax is operated from Ukraine, and our service providers may process information in other countries, including inside and outside the European Economic Area. Where personal data of EU/EEA users is transferred internationally and a safeguard is required, we rely on the data-transfer mechanisms our providers make available — for example, the EU Standard Contractual Clauses (SCCs) included in their data processing terms — together with additional measures where appropriate. We do not rely on an adequacy decision for Ukraine, as none currently applies. If your organization needs a signed DPA or additional transfer documentation before rollout, contact us before sending regulated customer data through Attriax.
9. Your Rights and Choices
Depending on your region, you may have rights to access, update, export, restrict, object to, or delete certain personal data, and to data portability. Where we rely on legitimate interests, you have the right to object to that processing; where we rely on consent (for example, optional website analytics), you can withdraw it at any time — withdrawal is as easy as giving it, through Cookie settings in the footer, and does not affect processing carried out before withdrawal. If you are in the EU/EEA, you also have the right to lodge a complaint with a data protection supervisory authority — generally the one in the country where you live or work, or where the issue arose; because Attriax is operated from Ukraine, you may also contact the Ukrainian data protection authority. Signed-in users can use the Privacy Center and app Privacy tools for product-handled export, deletion, and SDK anonymization workflows. For other privacy questions, contact support@attriax.com.
Where the GDPR applies, Attriax relies on the following legal bases: performance of a contract to create and operate your account and workspaces and to provide the features you request (Art. 6(1)(b)); legitimate interests to secure the platform, prevent fraud and abuse, maintain reliability, and run first-party product measurement, balanced against your rights (Art. 6(1)(f)); compliance with legal obligations such as billing, tax, and accounting records and responding to lawful requests (Art. 6(1)(c)); and consent for optional website analytics and similar non-essential technologies where the law requires it (Art. 6(1)(a)). We do not carry out solely automated decision-making that produces legal or similarly significant effects about you (Art. 22), and we do not seek to process special categories of personal data (Art. 9) — please do not send such data through the platform.
If you are an Attriax customer sending your own end-user data into the platform, you are responsible for handling end-user rights requests relating to the data you control, unless applicable law requires otherwise.
10. Children and Minimum Age
Attriax is a business-to-business product intended for developers, businesses, and other professional users. It is not directed to children, and we do not knowingly collect personal data directly from children under the age of 16 through our own website or accounts.
If you use Attriax to process data about your own end users, including any who may be children, you are responsible for the lawful basis and, where required, for obtaining verifiable parental consent under Article 8 of the GDPR or equivalent local law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where the change is material, take reasonable steps to notify you, for example by email or an in-product notice.
Your continued use of Attriax after an update takes effect means you acknowledge the updated policy. Where the law requires consent for a specific change, we will ask for it separately.
12. Open Source and Third-Party Notices
Attriax uses third-party software libraries, SDKs, infrastructure components, and external service providers. The main notices, license families, and upstream references for those integrations are published on our Open Source and Third-Party Notices page.
13. Contact
For privacy questions, contact us at support@attriax.com.