Privacy Policy

Last updated: March 7, 2026

Introduction

ENV Store ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our environment variable management service.

Information We Collect

Authentication Information

When you sign in using GitHub OAuth, we collect:

  • Your GitHub username and email address
  • Your GitHub profile information (name, avatar)
  • OAuth access tokens for authentication

Environment Variable Data

We store the environment variables you choose to save in our service. This data is:

  • Encrypted at rest using AES-256-GCM encryption
  • Only accessible by you through authenticated sessions
  • Never shared with third parties
  • Stored securely in our database infrastructure

Usage Information

We automatically collect certain information about your device and how you interact with our service, including:

  • IP address and browser type
  • Pages visited and features used
  • Timestamps of your interactions
  • Error logs and diagnostic data

How We Use Your Information

We use the collected information to:

  • Provide and maintain our service
  • Authenticate and authorize your access
  • Store and manage your environment variables securely
  • Improve and optimize our service performance
  • Respond to your inquiries and provide customer support
  • Monitor for security threats and prevent fraud

Data Security

We implement industry-standard security measures to protect your data:

  • AES-256-GCM encryption for all environment variables at rest
  • HTTPS/TLS encryption for data in transit
  • PBKDF2 key derivation with 100,000 iterations
  • Secure session management and authentication
  • Regular security audits and updates

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

Data Retention

We retain your personal information and environment variables for as long as your account is active or as needed to provide you services. You can delete your projects and associated environment variables at any time through the dashboard. Account deletion will permanently remove all your data from our systems.

Third-Party Services

We use the following third-party services:

  • GitHub OAuth - For authentication and authorization
  • MongoDB Atlas - For secure data storage
  • Vercel - For hosting and deployment

These services have their own privacy policies. We encourage you to review them.

Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete data
  • Delete your account and all associated data
  • Export your environment variables
  • Withdraw consent for data processing

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy, please contact us: