Legal
Privacy policy
What we store about you, why we are allowed to, who else touches it, and how to get it back or get rid of it.
Last updated 31 July 2026
01Who is responsible
The data controller for everything described here is:
Ferdinand Holdings ApS
Sagasvej 2 A, 2. tv, 1861 Frederiksberg C, Denmark
CVR 46627741 · Anpartsselskab (ApS), registered in Denmark
Director: Frederik Ferdinand Duelund Madsen · support@libertyhud.com
We have not appointed a data protection officer. We are not required to. Data questions go to the same address as everything else: support@libertyhud.com.
02What we store
Your account
Your name, your email address, and your password. Stored only as a scrypt hash, never as text we could read. Plus the dates the account was created and last changed.
Signing in
Each session stores a session token, its expiry, and the IP address and browser user-agent it was created from. We keep those two so a suspicious sign-in can be recognised, not to build a profile of you.
Payments and your balance
A Stripe customer id, and the state of your subscription: plan, monthly or yearly, current period, trial end, whether it is set to cancel. For every top-up we record what you paid, in what currency, how much of it was tax, the country your payment address was in, and. Only if you gave one: the VAT number you claimed. Your balance is a ledger: one permanent line per top-up, refund, model call and sandbox second, carrying the model used, the token counts and the provider reference. Card numbers never reach us; Stripe handles those.
The desktop app
Authorising the app mints a long-lived token that is stored only as a SHA-256 hash, so a copy of our database yields no working credential. The same is true of the one-time code the browser hands back to the app.
For the two-machine limit we store one row per install: a SHA-256 hash of a random id the app generates locally, your machine hostname as a label (so the app can say which PC is holding a seat), the app version read from its user-agent, first and last seen times, and when the seat expires. The hostname is the only piece of that which is human-readable, and it is there to make the message useful rather than to identify you.
The app’s usage counters
A random session id per app start, your app version, the same hashed device id the two-machine limit already uses, the day an install checked in, when each session started and last reported and how many five-minute reports it sent (together, roughly how long the app ran), and per-feature counts (a number next to a feature name, nothing more). The app’s Account card has the switch that turns its reporting off. Apps before version 0.10.0 do not report these counters at all.
Camera paths
Freezetime camera paths sync to your account, not to your PC. That is the point of them, so a new machine remembers your shots. We store each path’s name, map, duration, keyframes, anchor and enabled flag. Deleting a path leaves a tombstone rather than removing the row, otherwise the next device to sync would upload it again as new.
The Studio
Everything you build: package files, their full commit history, uploaded assets and published releases. Also the conversation: your prompts, the agent’s replies, the tools it ran and the results. Because a run has to survive a page refresh, and because it is the record of what you were charged for. The history is append-only by design: restoring an older version writes a new commit rather than erasing the ones after it.
Email you send us
Support mail and whatever is in it, kept while it is useful for answering you.
Public page counts
One number per public page of this site per day: how many times it was loaded. No cookie, no identifier, nothing stored in your browser, and we cannot tell two visits apart, so this is a count of loads, not of you.
The statistics we keep, we keep ourselves. The app and this site count feature use and liveness into our own database on our own servers: which of the app’s features an account used and how many times, which days an install checked in, which step of the sign-up and checkout flow a visit reached, and how a subscription’s status changed over time. Those counters never contain game footage, chat, player data or anything you broadcast, and no third party receives them. There is still no advertising, no tracking pixels and no third-party cookies anywhere on this site, and public pages are counted only as a bare number of loads per page per day — no cookie, no identifier, nothing stored in your browser, and we cannot tell two visits apart. We do not sell or rent personal data, and we never will.
03Why we are allowed to
- To perform our contract with you (GDPR Art. 6(1)(b)): the account, the subscription, the app authorisation, camera path sync, the Studio and your balance. Without this data there is no product to deliver.
- Legal obligation (Art. 6(1)(c)): payment and accounting records, which Danish bookkeeping law requires us to keep whether you want us to or not.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure and paid for: sign-in IP and user-agent, the device lease, spending caps and abuse limits — and understanding whether the product earns its keep: per-account counts of which features are used and which days an install was seen. We read those in aggregate to decide what to build; nobody reviews an individual customer’s usage to make decisions about them, and the app has a switch to turn its reporting off. Our interest is a service that is not drained or broken by someone else; we think that is one you share.
We do not rely on consent for any of it, we do not use your data for automated decisions with legal effects, and we do not process special categories of data.
04Cookies
Two cookies, both strictly necessary. The first is the signed session cookie that keeps you signed in. The second holds a signed copy of that session for up to five minutes, so a page load can skip a database read. Neither is used for tracking or advertising, which is why there is no cookie banner: there is nothing to ask permission for.
Fonts are served from our own server rather than fetched from a font provider, so loading a page does not tell anyone else that you visited.
05Who else touches it
We keep the list short on purpose. These are the only companies that process your data on our behalf:
- Hetzner Online GmbH. The cloud servers in Nuremberg, Germany, that run this site, its database and its backups. Everything in section 02 lives here first.
- Stripe: payments, subscriptions, invoices and the billing portal. Stripe receives your name, email and billing address and handles your card details directly.
- Cloudflare: DNS and TLS for libertyhud.com, plus the mail routing and sending behind support@libertyhud.com, which is how any account email reaches you.
- OpenRouter: routes Studio prompts to the AI models that answer them. It sees your prompts and the package files the agent is working on. Only when you use the Studio.
- E2B: the cloud sandbox the Studio builds and renders your screens in. It sees the package files while a session is running. Only when you use the Studio.
Beyond those, we disclose data only when the law requires it, and we will tell you if that happens unless we are forbidden to.
06Data outside the EU
Our servers are in Germany. Stripe, Cloudflare, OpenRouter and E2B are United States companies, so using them means some of your data is processed outside the EU/EEA, under the transfer terms in each provider’s standard data processing agreement. If you would rather your prompts never left the EU, do not use the Studio; the rest of the product does not depend on it.
07How long we keep it
- Account, packages, camera paths and Studio history: while your account exists, and until you ask us to delete it.
- Sessions: they expire on their own, and signing out ends them.
- App tokens: until you or we revoke them. Device rows are kept after a seat is taken over rather than deleted, so support can explain why the app said your account was open elsewhere; we keep roughly the last twenty per account.
- Deleted camera paths: the tombstone stays, because a removed row would resurrect itself on the next sync. It holds the path id and its deletion time, nothing else.
- Usage statistics: the app's feature counters and the sign-up-flow counts for at most 13 months, day-level install liveness for at most 26 months, and subscription status history for as long as the subscription's own record. All of it is deleted with your account. Public page counts carry no person: a number of loads per page per day, with nothing about you in it to keep or delete.
- Payment and accounting records: five years from the end of the financial year they belong to, because Danish bookkeeping law says so. These survive account deletion. That part is not ours to choose.
08Your rights
Under the GDPR you can ask us to:
- give you a copy of what we hold about you, and tell you what we do with it
- correct anything that is wrong
- delete your account and its data, except the accounting records in section 07
- restrict or object to processing we base on legitimate interests
- hand your data over in a portable, machine-readable form
Ask at support@libertyhud.com from the address on the account. We answer within a month; if a request is complicated enough to need longer, we will say so before the month is up.
Being straight with you: there is no delete-my-account button in the product yet. Deletion is done by hand when you ask, normally within a few days, and we confirm when it is done.
If you think we have handled your data badly, tell us first. And if that gets you nowhere, you can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk.
09How it is protected
Traffic runs over HTTPS. Passwords are scrypt-hashed. The desktop app’s token, its one-time authorisation code and its device id are stored only as SHA-256 hashes, so reading the database gives an attacker nothing that still works. Secrets live in the deployment environment, never in our source code. Access to the production database is limited to the people who run the service.
If a breach ever puts your rights at risk, we will report it to Datatilsynet within 72 hours and tell you directly.
10Children
LibertyHUD is a production tool, not a service for children, and you must be 18 to buy a subscription. We do not knowingly collect data from anyone under 13. If a child has an account, write to us and we will remove it.
11Changes
When the product changes what it stores, this page changes with it, and the date at the top moves. If a change matters to you we will email you before it takes effect. The terms of service cover the rest of the agreement.
Questions about any of this? support@libertyhud.com