Powerduck logo Powerduck
  • Spec Editor
  • API Debug
  • MCP Server
  • API Docs
  • Licensing
  • FAQ
  • Open Source Libraries
    @powerduck/md-editorEmbeddable Markdown editor with math, mindmaps & code highlighting
    @powerduck/conf-patchTwo-layer config editor with OpenAPI validation & atomic writes
    @powerduck/openapi-cliCI-ready CLI for batch-testing OpenAPI across 6 protocols
    @powerduck/openapi-codegenGenerate runnable HTTP code from OpenAPI (21 languages)
    @powerduck/openapi-mcp-serverTurn OpenAPI specs into production MCP servers with Web UI
    @powerduck/openapi-requestOpenAPI 3.2 collection debugger with HTTP/SSE/WebSocket
    @powerduck/x-to-openapiConvert cURL commands & Postman collections to OpenAPI 3.2
Docs GitHub

Legal

Privacy Policy

How we collect, use, store, and protect your personal information when you use Powerduck and Powerduck Cloud.

Last updated: September 10, 2026

On this page

  1. Data Controller
  2. Overview
  3. Information We Collect
  4. How We Use Your Information
  5. Legal Basis for Processing
  6. Information Sharing
  7. Data Retention
  8. Security
  9. Your Rights
  10. International Data Transfers
  11. Cookies & Tracking
  12. Children's Privacy
  13. California Privacy Rights
  14. Changes to This Policy
  15. Contact

1. Data Controller

The data controller responsible for your personal information under this Privacy Policy is:

Powerduck Limited
Email: contact@neatico.com
Website: https://www.powerduck.com

For the purposes of the General Data Protection Regulation (GDPR) and applicable UK data protection laws, Powerduck Limited is the data controller of your personal information. We have not appointed a Data Protection Officer (DPO) as we are not required to do so under applicable law. However, all privacy inquiries should be directed to contact@neatico.com.

2. Overview

Powerduck ("we", "us", "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect when you use Powerduck (the open-source library) and Powerduck Cloud (the hosted service), how we use it, and the choices you have.

Important: The open-source editor itself does not collect any data. When you embed the editor in your own application, all content stays on your servers and devices. This policy primarily applies to Powerduck Cloud and our website.

This policy applies to all users of our website and services, including visitors, registered users, and organizations that access the Services on behalf of a business entity.

3. Information We Collect

3.1 Information You Provide

  • Account information: name, email address, and password when you create a Powerduck Cloud account.
  • Billing information: payment card details (processed by our payment provider Paddle, not stored on our servers), billing address, and tax identification numbers.
  • Content: markdown documents, files, and other data you upload or create through Powerduck Cloud.
  • Communications: messages you send to our support team or through feedback channels.
  • Profile information: optional information such as company name, job title, and avatar.

3.2 Information Collected Automatically

  • Log data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps.
  • Usage data: features used, document counts, and performance metrics to help us improve the service.
  • Device information: device type, screen resolution, and language settings.
  • Cookies and similar technologies: as described in our Cookie Notice.

3.3 Information from Third Parties

We may receive information about you from third parties, including:

  • Payment providers: Paddle may provide us with transaction information, billing address, and tax details.
  • Analytics providers: aggregated and anonymized usage data from analytics services.
  • Authentication providers: if you sign in using a third-party service, we may receive your name and email address from that provider.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide and maintain the Service: including creating accounts, processing transactions, and delivering features.
  • To process payments: including managing subscriptions, invoicing, and collecting applicable taxes.
  • To authenticate users and secure accounts: including verifying your identity and preventing unauthorized access.
  • To improve the Service: including analyzing usage patterns, fixing bugs, and developing new features.
  • To communicate with you: including sending service-related notifications, billing confirmations, security alerts, and support responses.
  • To personalize your experience: including remembering your preferences and settings.
  • To comply with legal obligations: including responding to legal requests and enforcing our Terms of Service.
  • To prevent fraud and abuse: including monitoring for suspicious activity and protecting our users and services.

We do not sell your personal information to third parties for commercial purposes. We do not use your personal information for targeted advertising.

5. Legal Basis for Processing (GDPR)

Under the GDPR, we rely on the following legal bases for processing your personal information:

  • Contractual necessity (Article 6(1)(b)): processing is necessary for the performance of our contract with you, including providing the Service, processing payments, and maintaining your account.
  • Legitimate interests (Article 6(1)(f)): processing is necessary for our legitimate interests, including improving the Service, ensuring security, preventing fraud, and communicating with you about updates.
  • Consent (Article 6(1)(a)): where we rely on your consent, such as for non-essential cookies and marketing communications. You may withdraw your consent at any time.
  • Legal obligation (Article 6(1)(c)): processing is necessary for compliance with a legal obligation, including tax reporting, accounting, and responding to legal requests.

6. Information Sharing

We may share your information with the following categories of recipients:

6.1 Service Providers

We share information with third-party service providers who help us operate the Service. These providers are contractually required to protect your data and may only process it on our behalf and in accordance with our instructions.

  • Payment processors: Paddle (billing, invoicing, tax collection, refund processing).
  • Hosting providers: cloud infrastructure providers who host our servers and data.
  • Analytics services: privacy-friendly analytics providers who help us understand usage patterns.
  • Email service providers: providers who help us send transactional and support emails.
  • Customer support tools: providers who help us manage support tickets and communications.

6.2 Legal Authorities

We may disclose your information when required by law, court order, or government request, or when we believe in good faith that disclosure is necessary to:

  • Comply with applicable laws, regulations, or legal process.
  • Protect our rights, property, or safety, or that of our users or the public.
  • Detect, prevent, or address fraud, security, or technical issues.
  • Enforce our Terms of Service or other agreements.

6.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Category of Data Retention Period
Account information For the duration of your account, plus 30 days after deletion
Billing and transaction records 7 years (as required by tax and accounting laws)
Content (documents, files) For the duration of your account, plus 30 days after deletion
Log and usage data 12 months (anonymized after 90 days)
Support communications 3 years after the last communication
Marketing communications Until you opt out or unsubscribe

When we no longer need your personal information, we will securely delete or anonymize it in accordance with applicable law.

8. Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or later.
  • Encryption at rest: sensitive data is encrypted using industry-standard encryption algorithms.
  • Access controls: access to personal information is restricted to authorized personnel who need it to perform their duties.
  • Regular security audits: we conduct regular security assessments and penetration testing.
  • Data minimization: we collect only the information necessary to provide the Service.
  • Secure payment processing: payment card data is processed by Paddle and never stored on our servers.

Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

9. Your Rights (GDPR)

If you are a resident of the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR and UK GDPR:

  • Right of access (Article 15): you have the right to obtain a copy of the personal information we hold about you.
  • Right to rectification (Article 16): you have the right to request correction of inaccurate or incomplete personal information.
  • Right to erasure (Article 17): you have the right to request deletion of your personal information, where we no longer have a legitimate reason to process it.
  • Right to restriction of processing (Article 18): you have the right to request restriction of processing in certain circumstances.
  • Right to data portability (Article 20): you have the right to receive your personal information in a structured, commonly used, and machine-readable format, or to request transfer to another controller.
  • Right to object (Article 21): you have the right to object to processing based on our legitimate interests or for direct marketing purposes.
  • Right to withdraw consent (Article 7(3)): where we rely on your consent, you have the right to withdraw it at any time.
  • Right to lodge a complaint (Article 77): you have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, please contact us at contact@neatico.com. We will respond to your request within 30 days. There is no fee for exercising your rights, unless your request is excessive, repetitive, or manifestly unfounded, in which case we may charge a reasonable fee.

10. International Data Transfers

Your personal information may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that differ from, and in some cases may be less protective than, the laws of your country.

When we transfer personal information from the EEA or UK to countries that have not been deemed adequate by the European Commission or UK Secretary of State, we use appropriate safeguards to ensure an adequate level of protection, including:

  • Standard Contractual Clauses (SCCs): we use the European Commission's Standard Contractual Clauses for transfers to third countries.
  • Data Processing Agreements (DPAs): we enter into DPAs with our service providers that include appropriate data protection safeguards.
  • Encryption and security measures: we implement technical measures to protect personal information during transfer and storage.

For more information about international data transfers or to obtain a copy of the relevant safeguards, please contact us at contact@neatico.com.

11. Cookies & Tracking

We use cookies and similar technologies to collect information about how you interact with our website and services. For detailed information about the cookies we use, their purposes, and how to control them, please see our Cookie Notice.

You can control cookies through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, and set preferences for certain websites. Please note that disabling essential cookies may affect the functionality of our website.

12. Children's Privacy

Our Service is not intended for children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information as soon as possible.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at contact@neatico.com.

13. California Privacy Rights (CCPA/CPRA)

If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know: you have the right to request information about the personal information we collect, use, and disclose about you.
  • Right to delete: you have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to opt out of sale: we do not sell your personal information. If we were to do so in the future, you would have the right to opt out.
  • Right to correct: you have the right to request correction of inaccurate personal information.
  • Right to limit use: you have the right to limit the use of sensitive personal information.
  • Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.

To exercise any of these rights, please contact us at contact@neatico.com. We will verify your identity before responding to your request.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date at the top of this page. For significant changes, we may also send you an email notification or display a prominent notice on our website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.

15. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Powerduck Limited
Email: contact@neatico.com
Website: https://www.powerduck.com

We will respond to all privacy inquiries within 30 days. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.

Powerduck logo Powerduck

Building developer tools for the modern API workflow. Open source, production-ready, and community-driven.

Product
  • Features
  • Open Source
  • MD Editor
  • OpenAPI CLI
Documentation
  • Getting Started
  • API Reference
  • OpenAPI Parser
  • MD Editor
  • CLI Tools
  • FAQ
Resources
  • GitHub
  • npm Packages
  • Contact
Legal
  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Cookie Notice
© 2026 POWERDUCK LIMITED. All rights reserved.
Terms Privacy Cookies