Trust & Governance

Privacy Policy

Our commitment to transparency, minimal data collection, and uncompromising data protection for software professionals and enterprise teams.

Effective Date: September 2026 | Version 1.0

1. Core Privacy Philosophy

endoflife.tech exists to organize and deliver public software and hardware lifecycle intelligence. We believe developers, security engineers, and enterprise leaders deserve authoritative data without surveillance or commercial profiling. We do not sell, rent, or monetize your personal information to third parties.

2. Information We Collect

a. Anonymous Catalog Browsing: When searching the public catalog, browsing products, or verifying provenance, you do not need to create an account. We do not use third-party advertising cookies or cross-site tracking pixels.

b. Authenticated Workspace Accounts: When signing in to manage data sources or enterprise administration, we collect your work email address and authentication tokens via our secure authentication provider (Supabase Auth / Google OAuth).

c. Fleet Inventory & Risk Dashboard Data: When uploading CSV fleet inventory files to the Risk Dashboard, files are parsed directly inside your browser memory to evaluate lifecycle status against the catalog. We do not inspect, log, or harvest private internal network hostnames, IP addresses, or proprietary asset topologies.

d. Technical Telemetry: Like all web services, our global delivery network (Cloudflare edge) automatically logs basic operational metrics (HTTP status codes, coarse geographic region, browser user-agent) strictly to prevent denial-of-service attacks, maintain platform uptime, and optimize caching performance.

3. How We Use Information

  • To provide, operate, and maintain the lifecycle intelligence platform.
  • To authenticate authorized administrators and govern data ingestion pipelines.
  • To respond to user support inquiries, data corrections, and product requests.
  • To monitor system performance, uptime, and protect against security incidents or malicious traffic.

4. Data Security & Storage

We implement industry-standard cryptographic protocols to protect data in transit (TLS 1.3) and at rest (AES-256). All database infrastructure is hosted with SOC 2 Type II compliant providers. Role-based access control (RBAC) and row-level security (RLS) policies restrict database writes exclusively to authenticated administrators.

5. Third-Party Service Providers

We partner with reputable infrastructure providers to deliver reliable global service:

  • Supabase: Managed PostgreSQL database, authentication, and secure row-level access control.
  • Cloudflare / Lovable Cloud: Edge hosting, TLS termination, CDN caching, and DDoS mitigation.

6. Your Rights & Data Control

You retain full rights over any account data associated with endoflife.tech. You may request account deletion, data export, or correction at any time by contacting our maintainers via our Contact page.

7. Contact Information

If you have questions regarding this Privacy Policy or our operational security practices, please reach out via our Contact Form or connect with our maintainers directly.