Privacy Policy
This policy explains how Laxmana Technologies Private Limited, established in Kathmandu, Nepal ("OnlyUtils", "we", "us") handles personal data on the OnlyUtils platform — the developer console, HTTP APIs, and hosted utility services (authentication, media, email). It is written for the developers who are our customers. If you are an end user of an application built on OnlyUtils, the developer of that application controls your data; see Section 7.
1. Two roles, two kinds of data
We act as a controller for data about you as our customer (your account, organization, configuration, billing when introduced). We act as a processor for data your application sends through the Services on behalf of your end users — we process it only to provide the Services and on your instructions.
2. Data we collect as controller
| Category | What | Source |
|---|---|---|
| Account | Email address, name, and identity-provider subject ID | Google or GitHub sign-in |
| Organization | Org name, member list, roles, invitations | You and your team |
| Service configuration | Enabled services, provider settings, connected mailbox address; SMTP credentials are encrypted with AWS KMS and are never written to logs | You |
| Usage and logs | IP address, request IDs, timestamps, API endpoints called, error and latency telemetry | Automatic (CloudWatch, X-Ray) |
| Session | Authentication cookies/tokens for the console; optional browser-push subscriptions for operator notifications | Automatic / opt-in |
Sign-in data from Google and GitHub. When you sign in with Google or GitHub we receive only basic profile information: your name, email address, and provider account identifier. We use it solely to create, operate, and secure your OnlyUtils account — never for advertising — and we do not share it except with the infrastructure subprocessors listed in Section 5. OnlyUtils' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Data we process on your behalf
Depending on which services you enable: end-user authentication records (your users' sign-in identifiers and tokens), media files you or your users upload, and the content and recipient addresses of email you send through the platform. This is your Customer Content under the Terms of Use; we host, transmit, and process it solely to provide the Services, and we do not sell it or use it to train machine-learning models.
4. How we use data
To provide, secure, and operate the Services; to authenticate you; to send transactional email (invitations, service notices); to monitor performance and debug incidents; to enforce our Terms and prevent abuse; and to comply with law. We do not run third-party advertising or tracking on the platform.
5. Sharing and subprocessors
We share data only with the infrastructure providers needed to run the platform: Amazon Web Services (hosting, storage, and email delivery via SES) and Cloudflare (DNS and content delivery). Sign-in is performed directly with Google or GitHub under their own policies. We may disclose data where required by law, and in a merger or acquisition subject to this policy. We do not sell personal data.
6. Security and retention
Data is encrypted in transit (TLS) and at rest; high-sensitivity secrets (such as connected mailbox credentials) are envelope-encrypted with AWS KMS. Access is restricted on a least-privilege basis. We retain account and organization data while your account is active and delete or anonymize it within a reasonable period after deletion; operational logs are retained on a rolling basis for security and debugging. For email we send, delivery telemetry (bounces and spam complaints) is recorded in suppression lists so that addresses which bounce, complain, or opt out are not mailed again. Report vulnerabilities to ops@onlyutils.com.
7. End users of applications built on OnlyUtils
If your data reached us through someone else's application, that developer is the controller: their privacy policy applies, and requests to access or delete your data should go to them. We support our customers in honoring such requests and forward any we receive directly.
8. Your rights
Depending on where you live (including under GDPR and similar laws), you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Contact ops@onlyutils.com and we will respond within the timeframe required by applicable law. You may also lodge a complaint with your supervisory authority.
9. International transfers
The platform is hosted on AWS; data may be processed in regions outside your own. Where required, we rely on appropriate safeguards for such transfers (such as standard contractual clauses once formalized — see Section 11).
10. Children
The platform is a developer tool and is not directed to children under 16. Do not use the Services to knowingly collect children's data without complying with applicable law (e.g., COPPA) in your own application.
11. Data controller
The data controller of record is Laxmana Technologies Private Limited, Kathmandu, Nepal. For data we process on behalf of developer customers (Section 3), we act on the customer's documented instructions as described in this policy and the Terms of Use; a standalone data-processing addendum is available on request at ops@onlyutils.com and will be published before general availability.
12. Changes and contact
We may update this policy; material changes will be announced by email or console notice at least 14 days in advance. Questions: ops@onlyutils.com.