OpenSyntaxx
Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains what OpenSyntaxx collects through the website, account system, subscription flows, analytics, and license services for iosy.
1. Who we are
OpenSyntaxx operates opensyntaxx.com, api.opensyntaxx.com, and the iosy product. The legal entity name, registration number, registered address, and governing jurisdiction are to be added once finalized.
Privacy questions and requests can be sent to support@codesyntaxx.com.
2. Local decompilation
iosy runs locally on your machine. OpenSyntaxx web services do not receive IPA files, generated Swift files, app binaries, app names, bundle identifiers, local project contents, or decompilation output.
The website is used for accounts, downloads, subscriptions, billing links, email verification, SSO, and license activation. The decompilation work stays on your workstation.
3. Information we collect
We collect the information needed to operate OpenSyntaxx accounts, subscriptions, and licensing:
- Account details such as name, email address, account ID, account creation time, and email status.
- Password hashes for password-based accounts. We do not store plaintext passwords.
- Legal consent records, including accepted Terms and Privacy Policy versions and timestamps.
- Session records used to keep you signed in.
- OAuth identity metadata when you use Google or Microsoft SSO.
- Dodo customer, subscription, checkout, invoice, payment status, and billing portal identifiers.
- CLI and license metadata such as machine ID, optional machine name, platform, app version, activation session ID, activation time, last validation time, and revoked session status.
- Short-lived CLI login request metadata, including device/user code hashes, status, expiry, polling metadata, and client key hashes.
- Security and rate-limit metadata, including hashed request keys and attempt counters.
4. Cookies and analytics
We use necessary cookies for sign-in, security, legal consent, and account operation. These cookies are required for the service to work.
We use Google Analytics to understand page traffic and basic site usage. In GDPR and privacy-regulated regions, Google Analytics loads only after you accept analytics cookies. Outside those regions, analytics may be enabled by default unless you change your cookie settings.
You can reject analytics in the cookie banner where consent is required, and you can reopen cookie settings from the Cookie settings button when available in your browser session.
5. How we use information
We use collected information to:
- Create, secure, and manage accounts.
- Send email verification codes, account notices, and service messages.
- Link Google or Microsoft SSO identities to OpenSyntaxx accounts.
- Create checkout sessions, sync subscription status, and show billing information.
- Activate, validate, revoke, and enforce iosy license access.
- Prevent abuse, rate-limit sensitive flows, troubleshoot errors, and protect the service.
- Measure website traffic and improve public pages when analytics is enabled.
- Comply with tax, payment, accounting, security, and legal obligations.
6. Service providers
We use third-party service providers to operate OpenSyntaxx:
- AWS services, including DynamoDB for application state and SES for email delivery.
- Dodo Payments for checkout, subscriptions, payment methods, taxes, invoices, billing history, and refunds where applicable.
- Google and Microsoft when you choose to sign in with SSO.
- Google Analytics for traffic measurement when analytics is enabled.
These providers process information according to their own terms and privacy notices, and only to the extent needed for the services they provide to OpenSyntaxx or to you.
7. Billing data
Payment card details are handled by Dodo Payments and its payment infrastructure. OpenSyntaxx stores billing identifiers, subscription status, plan information, renewal dates, cancellation state, and payment history summaries needed to show your account and enforce access.
Dodo Payments may send OpenSyntaxx webhook events and subscription snapshots so your OpenSyntaxx account reflects current paid, trial, past-due, cancelled, expired, or failed billing states.
8. Retention
We keep account, subscription, billing, consent, license, and security records for as long as needed to provide the service, maintain account history, resolve disputes, prevent abuse, comply with tax and accounting requirements, and meet legal obligations.
Short-lived verification and CLI login records expire or are pruned as part of normal service operation. If you ask us to delete your account, we will delete or anonymize information unless we need to keep it for legal, tax, billing, security, or legitimate operational reasons.
9. Security
We use technical and organizational measures designed to protect account, billing, license, and service metadata. No internet service can be guaranteed to be perfectly secure.
You are responsible for keeping your password, SSO account, local machine, generated files, and iosy activation tokens secure.
10. Your choices and rights
You can update account and billing information through your OpenSyntaxx account and the Dodo billing portal when available. You may contact us to request access, correction, deletion, export, or restriction of personal information.
Your rights depend on your location and applicable law. We may need to verify your identity before completing a request.
11. International processing
OpenSyntaxx and its service providers may process information in countries other than where you live. Where required, we rely on appropriate legal mechanisms for cross-border processing.
12. Children
OpenSyntaxx is not intended for children. You must be at least 18 years old, or the age of legal majority where you live, to create an account.
13. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will take reasonable steps to notify account holders. The latest version will be posted on this page.