Last updated 24 July 2026
Privacy Policy
1. Who we are
This Privacy Policy explains how the operator of Cerise (“we”, “us”) handles personal data when you use cerise.lol, accounts, payments, the license APIs, and the Cerise client. It works together with our Terms of Service.
2. Data we collect
- Account. Email, hashed password, name fields, optional username and avatar, role, account status (for example active or suspended), member number, timestamps.
- Sessions and auth. Session tokens, approximate IP, user agent, expiry times. Credential and provider rows needed for sign-in.
- Licenses and seats. License keys and plan metadata, status (including revoked or suspended), expiry and cancel times, seat limits, HWID hashes, optional device fingerprint components, seat labels, bind times.
- Activation and security logs. Event type, outcome, reason, IP, user agent, HWID hash, optional detail payloads for activate, session, link, heartbeat, deactivate, and related denials.
- Bans. Scope and value (for example HWID), reason, creator metadata, timestamps.
- Cloud configs. Named presets and settings blobs you save from the client.
- Billing references. Creem customer id, subscription id, product id, order id, checkout id, and plan/source fields. We do not store full card numbers on Cerise servers. Creem processes payments as Merchant of Record under its own privacy terms.
- Technical data. Request metadata used for rate limits, abuse detection, debugging, and hosting logs.
3. Why we use data
- Provide accounts, sessions, and the website.
- Sell and deliver access, bind seats, verify signed license grants, and run the client protocol.
- Enforce the Terms: suspend accounts, revoke licenses, ban HWIDs, rate-limit abuse, investigate fraud and chargebacks.
- Process payments and reconcile Creem webhooks.
- Provide support and fix product issues you report.
- Secure the Service and improve reliability.
- Meet legal obligations where they apply.
Where GDPR or similar laws apply, we rely on performance of a contract (providing the Service you request), legitimate interests (security, fraud prevention, enforcement, product improvement), and legal obligation when required. We do not sell your personal data.
4. Enforcement and automated checks
Seat limits, replay protection, ban lists, account status, and rate limits may automatically deny activation or other API calls. Staff may also manually suspend accounts, revoke licenses, or ban hardware. Those actions use the data above and may permanently affect your ability to use Cerise.
5. Who we share with
- Creem for checkout, subscriptions, invoices, tax handling, and payment disputes.
- Hosting, database, and infrastructure providers that run cerise.lol and store data under our instruction.
- Professional advisors or authorities when required by law or to protect our rights and users.
We do not sell personal data to advertisers. We do not run third-party ad trackers on core product pages for that purpose.
6. International transfers
Servers and vendors may process data in the EU or other countries. Where required, we use appropriate safeguards offered by those providers for cross-border processing.
7. Retention
We keep account and product data while your account exists and as long as needed to provide the Service, resolve disputes, prevent fraud, and meet legal duties. Activation logs, ban records, and related security data may be kept longer when needed for enforcement (including after an account is closed) so that suspended users or banned hardware cannot simply re-register around a block.
Billing records may also remain with Creem under its retention rules.
8. Your choices and rights
You can update certain profile fields in Settings and end sessions by signing out. You may contact us to request access, correction, or deletion of account data we control, subject to law.
We may refuse or limit deletion or anonymization where we must keep data for security, fraud prevention, license enforcement, legal claims, or accounting. Deleting an account does not automatically create a refund right under the Terms.
If you are in the EEA/UK or another region with similar rights, you may also have rights to object, restrict processing, or complain to a supervisory authority. Contact us first so we can try to resolve the issue.
9. Cookies and similar tech
We use cookies and similar storage required for authentication, security, and basic site function. Disabling cookies may break sign-in.
10. Security
We use HTTPS, hashed passwords, signed license envelopes, access controls on admin tools, and operational practices aimed at protecting data. No system is perfectly secure. Protect your password and devices.
11. Children
Cerise is not directed at children under 16. If you believe a child created an account, contact us and we will remove it where appropriate.
12. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after a change means you accept the updated policy.
13. Contact
Privacy questions: Discord. Also see the Terms of Service.