OnlyUtils

Privacy Policy

Effective date: 2 August 2026

This policy explains how Laxmana Technologies Private Limited, established in Kathmandu, Nepal ("OnlyUtils", "we", "us") handles personal data on the OnlyUtils platform — the developer console, HTTP APIs, and hosted utility services (authentication, media, email). It is written for the developers who are our customers. If you are an end user of an application built on OnlyUtils, the developer of that application controls your data; see Section 7.

1. Two roles, two kinds of data

We act as a controller for data about you as our customer (your account, organization, configuration, billing when introduced). We act as a processor for data your application sends through the Services on behalf of your end users — we process it only to provide the Services and on your instructions.

2. Data we collect as controller

CategoryWhatSource
AccountEmail address, name, and identity-provider subject IDGoogle or GitHub sign-in
OrganizationOrg name, member list, roles, invitationsYou and your team
Service configurationEnabled services, provider settings, connected mailbox address; SMTP credentials are encrypted with AWS KMS and are never written to logsYou
Usage and logsIP address, request IDs, timestamps, API endpoints called, error and latency telemetryAutomatic (CloudWatch, X-Ray)
SessionAuthentication cookies/tokens for the console; optional browser-push subscriptions for operator notificationsAutomatic / opt-in

Sign-in data from Google and GitHub. When you sign in with Google or GitHub we receive only basic profile information: your name, email address, and provider account identifier. We use it solely to create, operate, and secure your OnlyUtils account — never for advertising — and we do not share it except with the infrastructure subprocessors listed in Section 5. OnlyUtils' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. Data we process on your behalf

Depending on which services you enable: end-user authentication records (your users' sign-in identifiers and tokens), media files you or your users upload, and the content and recipient addresses of email you send through the platform. This is your Customer Content under the Terms of Use; we host, transmit, and process it solely to provide the Services, and we do not sell it or use it to train machine-learning models.

4. How we use data

To provide, secure, and operate the Services; to authenticate you; to send transactional email (invitations, service notices); to monitor performance and debug incidents; to enforce our Terms and prevent abuse; and to comply with law. We do not run third-party advertising or tracking on the platform.

5. Sharing and subprocessors

We share data only with the infrastructure providers needed to run the platform: Amazon Web Services (hosting, storage, and email delivery via SES) and Cloudflare (DNS and content delivery). Sign-in is performed directly with Google or GitHub under their own policies. We may disclose data where required by law, and in a merger or acquisition subject to this policy. We do not sell personal data.

6. Security and retention

Data is encrypted in transit (TLS) and at rest; high-sensitivity secrets (such as connected mailbox credentials) are envelope-encrypted with AWS KMS. Access is restricted on a least-privilege basis. We retain account and organization data while your account is active and delete or anonymize it within a reasonable period after deletion; operational logs are retained on a rolling basis for security and debugging. For email we send, delivery telemetry (bounces and spam complaints) is recorded in suppression lists so that addresses which bounce, complain, or opt out are not mailed again. Report vulnerabilities to ops@onlyutils.com.

7. End users of applications built on OnlyUtils

If your data reached us through someone else's application, that developer is the controller: their privacy policy applies, and requests to access or delete your data should go to them. We support our customers in honoring such requests and forward any we receive directly.

8. Your rights

Depending on where you live (including under GDPR and similar laws), you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Contact ops@onlyutils.com and we will respond within the timeframe required by applicable law. You may also lodge a complaint with your supervisory authority.

9. International transfers

The platform is hosted on AWS; data may be processed in regions outside your own. Where required, we rely on appropriate safeguards for such transfers (such as standard contractual clauses once formalized — see Section 11).

10. Children

The platform is a developer tool and is not directed to children under 16. Do not use the Services to knowingly collect children's data without complying with applicable law (e.g., COPPA) in your own application.

11. Data controller

The data controller of record is Laxmana Technologies Private Limited, Kathmandu, Nepal. For data we process on behalf of developer customers (Section 3), we act on the customer's documented instructions as described in this policy and the Terms of Use; a standalone data-processing addendum is available on request at ops@onlyutils.com and will be published before general availability.

12. Changes and contact

We may update this policy; material changes will be announced by email or console notice at least 14 days in advance. Questions: ops@onlyutils.com.