1. Controller, operator, and contact
DWL Accounts is operated by Alpinix LLC. Privacy requests should be sent to privacy
2. Scope and data sources
This Privacy Policy applies to DWL Accounts account creation, sign-in, recovery, profile settings, passkeys, email preferences, security events, support, app connections, purchase records supplied by supported products, billing support, and data requests. Connected apps may publish separate privacy notices for product-specific content, healthcare-adjacent workflows, paid features, analytics, or regulated processing.
Information may come from you, your browser or device, authentication providers such as Google, connected apps, service providers, payment processors, tax processors, email providers, support messages, security logs, cookies, audit logs, and fraud-prevention workflows.
3. Information we use and retain
| Information | How we use it | Retention and sharing |
|---|---|---|
| Account details: name, email, photo, account ID, verification status, and preferences | Create and maintain your account, provide requested features, and contact you. Legal bases include our contract, legitimate interests, and consent where required. | Kept while your account is active, with limited retention afterward where needed for legal, security, or dispute purposes. Shared with service providers and, when you connect, the relevant app. |
| Sign-in and passkey information: protected credentials, provider account identifiers, passkey names and device information, and sign-in records | Verify access, recover accounts, and prevent unauthorized use. Legal bases include our contract, security interests, and legal obligations. | Kept as needed for account access and security. Temporary sign-in information expires; removing a passkey removes its account registration, subject to backup and audit retention. Processed by our hosting, storage, and selected sign-in providers. |
| App connections: the app, connection status, account role, and connection dates | Connect your account to the apps you choose and check access. Legal bases include our contract and legitimate interests. | Kept while connected, with limited security and legal records retained afterward. Shared with the relevant app and service providers. |
| Purchase and subscription records, when supplied by a supported product: email, order, plan, amount, receipt, payment-method description, status, and billing dates | Send receipts and subscription messages, provide support, and maintain transaction records. Legal bases include our contract, legal obligations, and legitimate interests. | Kept as needed for the transaction, accounting, disputes, and legal duties. Processed by relevant product, email, hosting, and storage providers. Payment collection is handled by the product and its payment provider. |
| Device and security information: browser details, network information, timestamps, account activity, and abuse signals | Protect accounts, investigate problems, and keep the service reliable. Legal bases include security interests and legal obligations. | Kept for operational and security purposes; investigation or legal needs may require longer retention. Processed by hosting and security providers. |
| Support, privacy requests, and agreement records: your messages, relevant account information, accepted policy versions, and request history | Respond to requests, verify authority, document agreements, and resolve disputes. Legal bases include our contract, legitimate interests, consent where required, and legal obligations. | Kept as needed for the request and related legal or security obligations. Shared with personnel and providers handling it. |
| Cookies, local preferences, and diagnostic information | Maintain sign-in, remember settings, and understand service errors. Legal bases include our contract and security interests, with consent where required. | See Cookies below. Service providers may retain operational logs; information that no longer identifies you may be retained for aggregate reliability and security analysis. |
4. Payment processing and purchase privacy
DWL Accounts does not provide a public checkout or collect payment card details in its account settings. A supported product may send purchase or subscription records to DWL Accounts so we can send receipts, subscription updates, or provide support.
Those records may include your account email, product or plan, amount, order reference, purchase date, payment-method description, receipt or billing link, subscription status, and next billing date. Payment providers handle the payment itself under their own privacy notices. Use the product's checkout and billing information for its payment practices.
5. Connected-app sharing and unlinking
When you sign in to a connected app, DWL Accounts shares your account ID, name, email address, and profile photo, if provided. It also checks your account and app connection to decide whether sign-in is allowed.
Profile photos have a publicly accessible image address. Anyone with that address can view the image, so do not use a photo that contains sensitive information.
You can review connections and disconnect an app in Apps. Disconnecting removes that app's DWL account connection. It does not erase records the app already holds, cancel a subscription, or necessarily end a session that the app manages independently. Use the app's controls or contact us about product-specific records.
6. Service providers and processors
| Provider | Purpose |
|---|---|
| Vercel | Hosts DWL Accounts and processes request and operational logs. |
| Supabase | Stores account details, sign-in records, profile photos, app connections, preferences, and related records. |
| Resend | Delivers account, security, support-related, purchase or subscription, and optional update emails. |
| Google, when you choose Google sign-in | Provides the account information needed to sign you in. |
| Cloudflare, where used for the domain | Provides domain routing and security services and may process related network information. |
7. Your privacy rights
Depending on where you live and how the law applies, you may request access, correction, deletion, export, portability, objection, restriction, withdrawal of consent, appeal, non-discrimination, limitation of sensitive information, or authorized-agent handling. We may verify your identity and authority and may deny or limit requests where permitted by law, including for security, fraud prevention, legal obligations, taxes, payment disputes, chargebacks, audit logs, backups, trade secrets, privileged information, or another person's rights.
EU, UK, Swiss, or other international users may have rights to lodge a complaint with a supervisory authority. DWL Accounts is operated from the United States. Contact the privacy address above for questions about international processing or exercising your rights.
9. Cookies and similar technologies
DWL Accounts uses essential cookies and similar storage for authentication, session protection, sign-out state, CSRF protection, required preferences, and account security. Refusing essential cookies may prevent sign-in, account security, or connected-app access from working.
| Cookie or technology | Purpose | Typical duration |
|---|---|---|
authjs.*, __Secure-authjs.*, and __Host-authjs.* | Maintain sign-in and protect account access | Sign-in session: up to seven days; temporary security cookies expire sooner |
dwl_manual_sign_out | Fresh reauthentication after manual sign-out | Up to 90 days unless changed or cleared |
dwl_last_sign_in_method | Remember your last successful sign-in method on this browser, without storing account details | Up to 90 days unless changed or cleared |
dwl_privacy_choices and browser preference storage | Remember your privacy choices on this browser | Cookie: up to one year; browser storage: until changed or cleared |
| Analytics, advertising, retargeting, or session replay cookies | Not currently used by DWL Accounts unless separately disclosed | Not applicable |
10. Security and breach notice
We use encrypted connections, protected sign-in credentials, passkeys, access restrictions, and account activity records to help protect your information. No service can guarantee complete security. We investigate suspected incidents and notify affected people, authorities, or service providers where required by law or applicable provider rules.
11. Health, sensitive data, and AI training
DWL Accounts itself is an identity and account portal. Do not send health information, government IDs, payment details, credentials, private keys, or other sensitive information through general support unless necessary for the request. Healthcare-adjacent connected apps must provide product-specific privacy notices before collecting health information. DWL Accounts does not claim HIPAA compliance unless a separate reviewed implementation and agreement state so.
Account data, support data, connected-app linkage data, payment metadata, and uploaded content are not used to train AI models unless that use is clearly disclosed and consented to in a product-specific notice or another valid legal basis applies.
12. Access and retention
Access to account data is limited to authorized personnel and service providers with a legitimate need. Account profiles, authentication records, passkeys, support messages, connected-app records, purchase records, payment metadata, tax records, backups, and security logs are retained only as needed for the purposes described in this Policy, then deleted or de-identified unless security, fraud prevention, payment disputes, chargebacks, tax, accounting, legal, backup, audit, or dispute needs require longer retention. Backups and provider logs are not deleted instantly everywhere.
13. International transfers
DWL Accounts is operated from the United States. Information may be processed in the United States and other locations where service providers, payment processors, connected apps, or support providers operate. Where required, appropriate safeguards are used for international transfers, such as adequacy decisions, standard contractual clauses, provider transfer frameworks, or other legally recognized mechanisms.
14. Children
DWL Accounts is not directed to children under 13 and does not knowingly collect personal information from children under 13. A parent or guardian may contact privacy
15. Automated decisions and fraud controls
DWL Accounts may use automated or rule-based controls for authentication, rate limits, fraud prevention, payment-risk signals, spam prevention, security alerts, app access checks, and abuse detection. These controls are used to protect the Service and users. DWL Accounts does not currently make solely automated decisions that produce legal or similarly significant effects on users unless a product-specific notice states otherwise.
16. Changes to this policy
Material changes may receive email, in-app, checkout, or Portal notice and may require renewed acknowledgement, consent, or preference choices where appropriate. The version, effective date, and last-updated date at the top identify the current policy.