Privacy policy
Effective date: January 2026
This notice explains what personal data Evora collects when you use our website, developer dashboard, licensing API, and SDK integrations (Evorion, EVORION_PROTECT, and SSCX). It covers developers who hold an Evora account and end users of applications that embed our SDK. Evora is a UK-based operation and processes personal data in accordance with the UK GDPR and the Data Protection Act 2018.
Introduction
Who we are
Evora provides licensing, session validation, hardware binding, and runtime protection tooling for software developers. In this notice, "Evora", "we", "us", and "our" refer to the operator of evora.plus. As the operator of the platform, we act as a data controller for account and telemetry data described below.
Who this notice covers
This notice applies to visitors of evora.plus, developers who register for an account or apply for access, and end users whose devices interact with an SDK-protected application through our authentication and licensing endpoints.
Developers as separate controllers
Developers who integrate Evorion into their own applications determine what end-user data flows through the SDK and remain independent controllers for their own product's data practices. Evora processes fingerprint, HWID, and session data on their behalf to deliver anti-abuse and licensing services.
What we collect
Account data
When you create an account at /signup or sign in at /signin, we collect your email address, chosen username, and a salted hash of your password. We do not store your password in plaintext. If you subscribe to a paid plan, our payment processor collects billing details on our behalf; we receive only the transaction reference, plan, and status.
Developer session telemetry
During sign-in and while your dashboard session is active, we record the IP address, user-agent string, CSRF token exchange, and timestamps of authentication events. This is used to secure your account, detect account sharing, and produce audit logs.
Browser fingerprint (developers only)
Our sign-in page runs a bounded fingerprint collector against the developer's browser. The signals are: a hashed canvas rendering, WebGL vendor/renderer strings and a hash of a fixed set of WebGL parameters, a hashed audio-processing sample, IANA timezone, screen dimensions and colour depth, browser platform string, browser languages, hardware concurrency count, and two heuristic flags ("incognito hint" and "weak platform"). We do not collect fonts, WebRTC data, battery status, plugin lists, or the raw user-agent as a fingerprint signal. Values are hashed on the client where possible; only the hashes and short vendor strings are transmitted.
Hardware identifiers (end users of SDK apps)
When an end user runs an application that integrates the Evorion SDK, the SDK may collect one or more hardware identifiers from the local machine to compute a HWID hash. Sources include the motherboard serial, disk serial, MAC address, CPU identifier, TPM public key, and SMBIOS metadata. The SDK sends only the derived HWID hash to Evora unless the integrating developer configures additional telemetry. The raw identifiers are not transmitted or stored by Evora.
License and session records
For each active license we retain the license key, plan tier, bound HWID hash, activation and expiry timestamps, revocation status, and a rolling log of session validations, session cookies issued, IP addresses seen, and integrity check results. This information is required to make license enforcement work.
Website analytics and logs
Our hosting and edge providers (see "Sharing") log basic request metadata for every request served by evora.plus: source IP, request path, response status, user-agent, and referrer. These logs are retained for a short period for security and debugging and are not linked to your account unless a security incident requires it.
Support communications
If you contact us over email or Discord, we retain the message contents and any identifiers you provide (email address, Discord handle, license key) for the purpose of responding to you and improving the product.
Why we collect it
Contract
Account data, license records, HWID hashes, and session validation are processed to perform the contract you enter into when you sign up or when you use software protected by an Evora-integrating developer. Without this data the platform cannot deliver licensing or session validation.
Legitimate interests
Developer fingerprints, IP logs, audit trails, and abuse-signal telemetry are processed on the basis of our legitimate interest in operating a secure platform, detecting account sharing and credential abuse, preventing fraud, and defending against automated attacks. We balance this against your privacy by minimising the signals collected, hashing them where practical, and limiting retention.
Legal obligation
Some data (financial records, tax invoices, and lawful-request preservation) is retained to meet UK legal and regulatory obligations.
Consent
Where we rely on your consent (for example, optional communications or non-essential cookies if we ever introduce them), you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.
How we use it
Operating the service
To authenticate developers, issue and validate license keys, bind licenses to hardware, keep dashboard sessions alive, and run the SSCX server-side execution and EVORION_PROTECT integrity paths that customers integrate into their products.
Security and abuse prevention
To detect account sharing across developer accounts, identify credential stuffing and brute-force attempts, block automated abuse of the licensing API, investigate reports of misuse, and maintain audit logs of privileged actions.
Product improvement
To debug incidents, understand which SDK versions and endpoints are in use, and improve the developer dashboard. We do not build advertising profiles and we do not use your data to train third-party machine-learning models.
Communications
To send you transactional and account-critical messages (security notices, billing, service incidents, changes to these terms). Marketing messages, if ever sent, are limited to existing customers and can be opted out of at any time.
Retention
Account and license data
Account data is kept for as long as your account is active and for a reasonable period after closure to handle disputes, chargebacks, and abuse investigations. License and HWID-hash records are kept while a license is active and for up to 24 months after expiry or revocation to support cross-license anti-abuse analysis.
Session, fingerprint and audit logs
Developer session records, fingerprint samples, and IP logs are retained for up to 12 months. Security-critical audit logs may be retained longer where necessary to investigate an incident or comply with a legal obligation.
Edge and request logs
Edge request logs held by our WAF and hosting providers are retained under those providers' standard retention windows, typically 30 to 90 days.
Deletion
When retention periods expire, records are deleted or irreversibly aggregated. Hashed values (HWID, canvas, audio) cannot be reversed to their source identifiers.
Your rights
Rights under the UK GDPR
You have the right to access the personal data we hold about you, to have inaccurate data corrected, to have data erased in defined circumstances, to restrict or object to processing based on legitimate interests, to receive a portable copy of data you provided, and to withdraw consent where processing is based on consent.
How to exercise your rights
To exercise any of these rights, email [email protected] from the address on file for your account. If you are an end user of a developer's product, please also contact that developer — they may hold copies of the same data outside our systems. We will respond within the timeframe required by the UK GDPR, normally within one month.
Complaints
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.
International transfers
Where your data is processed
Evora's infrastructure and sub-processors may store or process personal data outside the United Kingdom, including in the European Economic Area and the United States. Cloudflare's global edge, in particular, will process request metadata at the point of presence closest to the request source.
Transfer safeguards
Where personal data is transferred outside the UK to a country that has not received a UK adequacy decision, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate technical measures such as encryption in transit.
Security
How we protect data
Passwords are stored as salted hashes. Transport is encrypted with TLS. Session cookies are HTTP-only, secure, and same-site. The API sits behind CSRF protection, rate limiting, and Cloudflare's WAF and bot-management layer. Access to production data is restricted to a small operator group and gated by strong authentication.
Your role
No system is perfectly secure. Please use a unique, strong password, treat your license keys as sensitive material, and report anything unusual about your account or a suspected compromise as quickly as possible.
Children
Age
Evora is a business-to-developer service and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will delete it.
Changes
Updates to this notice
We may update this notice from time to time. Material changes will be signalled through the dashboard or via email to account holders at least 14 days before they take effect. The current version is always available at /privacy and is dated at the top of this page.
Contact
How to reach us
For privacy questions, subject-access requests, or to exercise any of the rights above, email [email protected]. For general support or informal contact, you can also reach us on Discord at https://discord.gg/HAQQMEhb2V.