1. Our principle: local-first
Restorm is built local-first. Your working data โ requests, collections, environment variables, scenarios, response history โ stays stored on your device. Unless you explicitly enable a feature that requires it, this data is never sent to us, and we cannot read it.
In particular, the API keys, access tokens, certificates, secrets, environment variables, and other credentials you save in Restorm stay stored locally, unless you explicitly choose to send them to a third-party service.
2. Data controller
MonsieurDev, a French simplified joint-stock company with a single shareholder (SASU) with capital of โฌ1,000, registered with the Bordeaux Trade and Companies Register under number 941 528 259, whose registered office is located at 6, Sente des Morutiers, Rรฉsidence Edรฉal, Apt D21, 33300 Bordeaux, France. Contact for any question about your data: [email protected].
3. Data processed and purposes
- Account (name, email address, authentication credentials) โ to create and secure your account. Legal basis: performance of a contract.
- Subscription and billing (order information, purchase history) โ to manage your subscription. Payment is processed by our reseller Paddle; we never store any card data. Legal basis: performance of a contract and legal obligation (accounting).
- Technical logs from the licensing service (IP address, connection date and time, application version, license identifier) โ for security and proper operation. Legal basis: legitimate interest.
We do not collect the content of API requests, responses, collections, variables, or scenarios you create in Restorm.
To verify that an active license is valid, the application may periodically communicate with our licensing service, sending only the technical information necessary for that verification.
4. Artificial intelligence
When you use a third-party AI provider configured in Restorm, the data sent to that provider is processed in accordance with that provider's own privacy policy. Neither Restorm nor its publisher has access to the content of those exchanges.
5. Security
We implement technical and organizational measures designed to protect the personal data we process against unauthorized access, loss, disclosure, or alteration.
6. Processors and recipients
We rely on providers acting as processors:
- Supabase โ account and license database (hosted in the European Union);
- Paddle โ payment and billing (Merchant of Record);
- WorkOS โ authentication and account management;
- Cloudflare โ site hosting and delivery (CDN).
This list may change; this policy is updated accordingly. We never sell your personal data.
7. Transfers outside the European Union
Some providers may process data outside the EU. Where this happens, such transfers are covered by appropriate safeguards (European Commission standard contractual clauses or an equivalent mechanism).
8. Retention period
Account data is kept for as long as your account is active, then deleted or anonymized within a maximum of 90 days after the account is deleted, unless a legal obligation requires otherwise. Billing data is kept for the period required by legal and accounting obligations.
9. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object to, and port your data. You can exercise these rights at [email protected]; you're also welcome to contact us before filing any complaint so we can address your request. You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
10. Cookies
We use no advertising cookies, no profiling cookies, and no user-behavior analytics tools. Only cookies or storage strictly necessary for the service to function may be used.
11. Contact
For any question about this policy: [email protected].