Scroll
  • Home
  • Evorion
  • Features
  • Pricing
  • Reviews
  • Docs
  • Updates
Log inSign up

Privacy policy

Effective date: January 2026

This notice explains what personal data Evora collects when you use our website, developer dashboard, licensing API, and SDK integrations (Evorion, EVORION_PROTECT, and SSCX). It covers developers who hold an Evora account and end users of applications that embed our SDK. Evora is a UK-based operation and processes personal data in accordance with the UK GDPR and the Data Protection Act 2018.

  1. Introduction
  2. What we collect
  3. Why we collect it
  4. How we use it
  5. Sharing
  6. Retention
  7. Your rights
  8. International transfers
  9. Cookies and local storage
  10. Security
  11. Children
  12. Changes
  13. Contact

Introduction

1.1

Who we are

Evora provides licensing, session validation, hardware binding, and runtime protection tooling for software developers. In this notice, "Evora", "we", "us", and "our" refer to the operator of evora.plus. As the operator of the platform, we act as a data controller for account and telemetry data described below.

1.2

Who this notice covers

This notice applies to visitors of evora.plus, developers who register for an account or apply for access, and end users whose devices interact with an SDK-protected application through our authentication and licensing endpoints.

1.3

Developers as separate controllers

Developers who integrate Evorion into their own applications determine what end-user data flows through the SDK and remain independent controllers for their own product's data practices. Evora processes fingerprint, HWID, and session data on their behalf to deliver anti-abuse and licensing services.


What we collect

2.1

Account data

When you create an account at /signup or sign in at /signin, we collect your email address, chosen username, and a salted hash of your password. We do not store your password in plaintext. If you subscribe to a paid plan, our payment processor collects billing details on our behalf; we receive only the transaction reference, plan, and status.

2.2

Developer session telemetry

During sign-in and while your dashboard session is active, we record the IP address, user-agent string, CSRF token exchange, and timestamps of authentication events. This is used to secure your account, detect account sharing, and produce audit logs.

2.3

Browser fingerprint (developers only)

Our sign-in page runs a bounded fingerprint collector against the developer's browser. The signals are: a hashed canvas rendering, WebGL vendor/renderer strings and a hash of a fixed set of WebGL parameters, a hashed audio-processing sample, IANA timezone, screen dimensions and colour depth, browser platform string, browser languages, hardware concurrency count, and two heuristic flags ("incognito hint" and "weak platform"). We do not collect fonts, WebRTC data, battery status, plugin lists, or the raw user-agent as a fingerprint signal. Values are hashed on the client where possible; only the hashes and short vendor strings are transmitted.

2.4

Hardware identifiers (end users of SDK apps)

When an end user runs an application that integrates the Evorion SDK, the SDK may collect one or more hardware identifiers from the local machine to compute a HWID hash. Sources include the motherboard serial, disk serial, MAC address, CPU identifier, TPM public key, and SMBIOS metadata. The SDK sends only the derived HWID hash to Evora unless the integrating developer configures additional telemetry. The raw identifiers are not transmitted or stored by Evora.

2.5

License and session records

For each active license we retain the license key, plan tier, bound HWID hash, activation and expiry timestamps, revocation status, and a rolling log of session validations, session cookies issued, IP addresses seen, and integrity check results. This information is required to make license enforcement work.

2.6

Website analytics and logs

Our hosting and edge providers (see "Sharing") log basic request metadata for every request served by evora.plus: source IP, request path, response status, user-agent, and referrer. These logs are retained for a short period for security and debugging and are not linked to your account unless a security incident requires it.

2.7

Support communications

If you contact us over email or Discord, we retain the message contents and any identifiers you provide (email address, Discord handle, license key) for the purpose of responding to you and improving the product.


Why we collect it

3.1

Contract

Account data, license records, HWID hashes, and session validation are processed to perform the contract you enter into when you sign up or when you use software protected by an Evora-integrating developer. Without this data the platform cannot deliver licensing or session validation.

3.2

Legitimate interests

Developer fingerprints, IP logs, audit trails, and abuse-signal telemetry are processed on the basis of our legitimate interest in operating a secure platform, detecting account sharing and credential abuse, preventing fraud, and defending against automated attacks. We balance this against your privacy by minimising the signals collected, hashing them where practical, and limiting retention.

3.3

Legal obligation

Some data (financial records, tax invoices, and lawful-request preservation) is retained to meet UK legal and regulatory obligations.

3.4

Consent

Where we rely on your consent (for example, optional communications or non-essential cookies if we ever introduce them), you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.


How we use it

4.1

Operating the service

To authenticate developers, issue and validate license keys, bind licenses to hardware, keep dashboard sessions alive, and run the SSCX server-side execution and EVORION_PROTECT integrity paths that customers integrate into their products.

4.2

Security and abuse prevention

To detect account sharing across developer accounts, identify credential stuffing and brute-force attempts, block automated abuse of the licensing API, investigate reports of misuse, and maintain audit logs of privileged actions.

4.3

Product improvement

To debug incidents, understand which SDK versions and endpoints are in use, and improve the developer dashboard. We do not build advertising profiles and we do not use your data to train third-party machine-learning models.

4.4

Communications

To send you transactional and account-critical messages (security notices, billing, service incidents, changes to these terms). Marketing messages, if ever sent, are limited to existing customers and can be opted out of at any time.


Sharing

5.1

We do not sell personal data

Evora does not sell your personal data or that of your end users, and we do not share it with data brokers or advertising networks.

5.2

Sub-processors

We share limited data with a small set of infrastructure providers that act as processors on our behalf: our hosting and database providers (to store account, license, and session records), Cloudflare (as our edge, WAF, and DDoS protection layer — which processes IPs, request metadata, and bot-management signals), our email delivery provider (for transactional email), and our payment processor (for billing). Each is bound by a written data-processing agreement.

5.3

Developer customers

If you are an end user of a product that embeds Evorion, the developer of that product receives the HWID hash, license status, and session validation results necessary to operate their integration. The developer is a separate controller for that data and their own privacy notice applies to what they do with it inside their product.

5.4

Legal and safety disclosures

We may disclose data where required by UK law, a valid legal request, or where we believe in good faith that disclosure is necessary to protect rights, prevent fraud or ongoing abuse, or defend Evora and its users. Where lawful, we will notify affected users.

5.5

Business transfers

If Evora is involved in a merger, acquisition, or asset sale, personal data may be transferred subject to standard confidentiality protections and continued application of a privacy notice at least as protective as this one.


Retention

6.1

Account and license data

Account data is kept for as long as your account is active and for a reasonable period after closure to handle disputes, chargebacks, and abuse investigations. License and HWID-hash records are kept while a license is active and for up to 24 months after expiry or revocation to support cross-license anti-abuse analysis.

6.2

Session, fingerprint and audit logs

Developer session records, fingerprint samples, and IP logs are retained for up to 12 months. Security-critical audit logs may be retained longer where necessary to investigate an incident or comply with a legal obligation.

6.3

Edge and request logs

Edge request logs held by our WAF and hosting providers are retained under those providers' standard retention windows, typically 30 to 90 days.

6.4

Deletion

When retention periods expire, records are deleted or irreversibly aggregated. Hashed values (HWID, canvas, audio) cannot be reversed to their source identifiers.


Your rights

7.1

Rights under the UK GDPR

You have the right to access the personal data we hold about you, to have inaccurate data corrected, to have data erased in defined circumstances, to restrict or object to processing based on legitimate interests, to receive a portable copy of data you provided, and to withdraw consent where processing is based on consent.

7.2

How to exercise your rights

To exercise any of these rights, email [email protected] from the address on file for your account. If you are an end user of a developer's product, please also contact that developer — they may hold copies of the same data outside our systems. We will respond within the timeframe required by the UK GDPR, normally within one month.

7.3

Complaints

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.


International transfers

8.1

Where your data is processed

Evora's infrastructure and sub-processors may store or process personal data outside the United Kingdom, including in the European Economic Area and the United States. Cloudflare's global edge, in particular, will process request metadata at the point of presence closest to the request source.

8.2

Transfer safeguards

Where personal data is transferred outside the UK to a country that has not received a UK adequacy decision, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate technical measures such as encryption in transit.


Cookies and local storage

9.1

What we set

We use cookies and equivalent browser storage only where necessary for the service to work. The primary cookie is evora_sid, an HTTP-only, secure, same-site session cookie used to keep you signed in to the developer dashboard. We also set short-lived CSRF tokens for form submissions and may set cookies used by Cloudflare's bot management (for example, __cf_bm) as part of the edge protection layer.

9.2

No advertising or cross-site tracking cookies

We do not use cookies for advertising, cross-site tracking, or behavioural profiling. We do not embed third-party analytics that build such profiles.

9.3

Managing cookies

You can block or clear cookies through your browser settings. Blocking evora_sid will sign you out of the dashboard and prevent parts of the service that require authentication from working.


Security

10.1

How we protect data

Passwords are stored as salted hashes. Transport is encrypted with TLS. Session cookies are HTTP-only, secure, and same-site. The API sits behind CSRF protection, rate limiting, and Cloudflare's WAF and bot-management layer. Access to production data is restricted to a small operator group and gated by strong authentication.

10.2

Your role

No system is perfectly secure. Please use a unique, strong password, treat your license keys as sensitive material, and report anything unusual about your account or a suspected compromise as quickly as possible.


Children

11.1

Age

Evora is a business-to-developer service and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will delete it.


Changes

12.1

Updates to this notice

We may update this notice from time to time. Material changes will be signalled through the dashboard or via email to account holders at least 14 days before they take effect. The current version is always available at /privacy and is dated at the top of this page.


Contact

13.1

How to reach us

For privacy questions, subject-access requests, or to exercise any of the rights above, email [email protected]. For general support or informal contact, you can also reach us on Discord at https://discord.gg/HAQQMEhb2V.

Evora

Authentication, licensing, and runtime protection for Windows applications.

Product
  • Evorion SDK
  • Features
  • Pricing
  • Evorion
  • Updates
  • Reviews
Developers
  • Documentation
  • API reference
  • Integrations
  • Why Evorion
Resources
  • Aim module
  • Reseller program
  • Discord
Account
  • Sign in
  • Create account
Legal
  • Terms
© 2026 Evora. All rights reserved.