Privacy
Blackcode SA
Last reviewed 7 September 2026
What we collect, and what we do not.
This site
Analytics, once you accept.
We use Google Analytics 4 to count page views and see which pages people read, where they arrived from, and roughly where in the world they are. It is set up in consent mode: before you answer the banner, Google receives a request with no identifiers and writes nothing to your device. If you accept, it sets cookies and measures normally. If you decline, it stays in that first state, and the answer is remembered so you are not asked again.
Your choice is kept in your browser’s local storage under af.consent.v1. That is the one thing stored regardless, because it is what records your refusal. Clearing your site data resets it and the question comes back.
We never receive your name or email from analytics, and we do not run advertising, remarketing or cross-site tracking. IP addresses are anonymised before they reach the reports.
Leaving your browser
Two requests we should name.
The plugin pages show the current version of each plugin, which the page reads from a file on GitHub as you look at it. That means GitHub sees a request from your browser, and therefore your IP address, the same as visiting any page on github.com. We do not send them anything else.
Fonts are served from this domain, not from Google Fonts — they are compiled into the site at build time, so looking at a page makes no request to a font host.
There are no forms here. The waitlist and news buttons open a message in your own mail client addressed to bojan@blackcode.ch; nothing is submitted to us until you press send in your own software, and what you send is an ordinary email.
An account
Only what an account needs.
Signing in at app.kovati.dev creates a record holding your email address, the display name and photo your provider gives us if you sign in with Google or GitHub, the plugins on your account, and any orders. That is the whole of it. We never receive your password: Google and GitHub authenticate you, and email sign-in is handled by Firebase Authentication, which stores a hash we cannot read.
Connecting the hub on your computer records that a computer is connected, so the account can install what it holds. It does not read your projects, your files, or anything you make with the plugins.
The account runs on Google Firebase in the europe-west1 region. Payments, when they are switched on, are processed by Stripe, who receive what a payment needs; we never see or store card details.
Your say
Ask, and it is done.
Write to bojan@blackcode.ch to see what your account holds, correct it, or have it deleted. Deleting an account removes the record and the plugins on it; where we are obliged to keep an order for accounting, that is what is kept and nothing more.
You can withdraw analytics consent at any time by clearing this site’s data in your browser, which brings the banner back.
Blackcode SA is the controller, because the account's data sits in its cloud. That moves to MetaWorx LLC when the infrastructure does, and this page changes on the same day. If something here does not match what the software actually does, that is a bug worth reporting — the release notes say what changed and when.