Silent Install HQ

Privacy Policy

Last updated: 2026-06-19

1. Overview

Silent Install HQ ("we", "us") operates app.silentinstallhq.com (the "Platform"). This policy explains what data we collect when you use the Platform, how we use it, and your rights regarding it. We have designed the Platform to collect as little personal data as possible.

2. What We Collect

Installer submissions

When you upload an installer binary, we compute and store a SHA-256 hash of the file along with derived metadata: product name, version, publisher, silent install switches, detection rules, file size, and architecture. The binary itself is deleted from our servers immediately after analysis completes. If the installer cannot be identified by our detection engine, the binary may be retained in secure storage for up to 7 days to enable administrator review, after which it is permanently deleted.

API key accounts

If you sign up for an API key, we collect and store your email address to issue your key, send transactional emails (key delivery, magic login links, payment receipts), and associate your account with usage records. Your email is never sold or shared with third parties for marketing.

Submission identifiers

Each submission is associated with a pseudonymous identifier derived from your API key or session token. We never store your raw API key or any directly identifying information alongside submission records.

API key usage

We record the date and request count per key for rate limiting and quota enforcement. We store a SHA-256 hash of your key — the raw key is never stored after issuance.

Payment information

Pro subscriptions are processed by Stripe. We do not store credit card numbers or full payment details. We store a Stripe customer ID and subscription ID to manage your billing relationship and link webhook events to your account.

IP addresses

IP addresses are used to enforce rate limits on unauthenticated requests. They are processed in memory and are not written to persistent storage in the normal operating path. Server infrastructure (Railway) may retain standard access logs independently.

What we do not collect

  • No passwords — authentication uses one-time magic links sent to your email
  • No names, phone numbers, or physical addresses
  • No cross-session tracking or behavioral profiling
  • No installer binaries retained beyond the analysis window, except unrecognized installers held for up to 7 days for admin review

3. How We Use It

  • To analyze submitted installers and populate the knowledge graph
  • To enforce per-key and per-IP rate limits
  • To attribute submissions pseudonymously for quota tracking
  • To issue API keys and send transactional emails (key delivery, magic login links, billing notifications)
  • To process Pro subscription payments via Stripe
  • To operate and improve the Platform

We do not sell data, share it with advertisers, or use it for any purpose unrelated to operating the Platform.

4. Data Retention

Installer binaries are deleted immediately after analysis. Exception: if an installer cannot be identified by our detection engine, the binary is retained in secure storage for up to 7 days for administrator review, then permanently deleted. Derived metadata (hashes, switches, detection rules) is retained indefinitely as part of the knowledge graph — it is the core product.

API key usage records are retained for 90 days for billing and quota purposes, then deleted. Pseudonymous submission identifiers are retained with the metadata record but cannot be reverse-mapped to an individual without the original API key.

Email addresses associated with API key accounts are retained for as long as the account is active. If you request account deletion, your email and associated account data will be removed within 30 days.

5. Third-Party Services

The Platform uses the following third-party services that may process data on our behalf:

  • Railway — application hosting. Standard server access logs may be retained per Railway's own policy.
  • Supabase — managed PostgreSQL database hosting. Installer metadata and API key account data (including email addresses) are stored here.
  • Stripe — payment processing for Pro subscriptions. Your email address and payment information are transmitted to Stripe to create a billing relationship. Stripe's privacy policy governs their handling of that data.
  • Resend — transactional email delivery. Your email address is transmitted to Resend solely to deliver emails you have requested (key delivery, magic links, billing notifications).
  • Google Fonts / Tailwind CDN — loaded by the browser when you visit the Platform. These services may log your IP address per their own privacy policies.

We do not transmit installer binaries or submission metadata to any third-party service except as described above.

6. Cookies

The Platform does not set tracking or analytics cookies. API key account holders who access the dashboard are issued a short-lived session cookie (sihq_session) that expires after 1 hour. This cookie contains only a signed, opaque token — no personal data is embedded in it. It is used solely to keep you logged in to the dashboard.

No cookies are set for visitors who do not have an API key account.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or request deletion of personal data we hold about you. For API key account holders, this includes your email address, usage records, and associated Stripe billing data.

To exercise any rights or ask questions about your data, contact us at legal@silentinstallhq.com.

8. Security

API keys are hashed before storage and never retrievable after issuance. Connections to the Platform use TLS. Access to the database is restricted to the application layer. We do not guarantee absolute security but take reasonable measures appropriate to the sensitivity of the data we hold.

9. Changes

We may update this policy from time to time. Material changes will be noted by updating the "Last updated" date above. Continued use of the Platform after changes are posted constitutes acceptance.

10. Contact

Privacy questions or data requests: legal@silentinstallhq.com