Privacy
Your project stays in your browser.
This notice explains what that means, what the licensing service does receive, and the choices you have.
Last updated: 8 September 2026
Who is responsible?
BidVariance is a personal project created, developed and maintained by Yunus Emre Vurgun in Istanbul, Türkiye. Contact details for privacy requests are available on the About page. This notice covers bidvariance.com; external services have their own notices.
Project inputs and results
The app stores saved projects in IndexedDB on your device. Calculations run in your browser, including its simulation worker. Project estimates, notes, risks and results are not uploaded to the BidVariance licensing service. Calculator baselines stay in the current tab and disappear when it closes or reloads. Downloads contain the assumptions and results you chose to export; you control where those files go and whom you share them with.
Local storage is not an encrypted vault or a cloud backup. Other people with access to your browser profile or device may access it. Export backups before clearing browser data or moving devices. Do not enter information you are not authorized to use.
License verification
When you activate or renew, the browser sends your license key to our server over HTTPS. The server sends that key and the configured product identifier to Gumroad for verification. Gumroad can return purchase information; the activation service uses the response to check the product and purchase status, and does not save the raw response or raw customer key in its license registry.
The registry stores a derived license identifier, the license tier, and first/last verification timestamps. A signed, HttpOnly cookie maintains the verified session for up to 30 days. If you explicitly choose “Keep this device activated,” the raw key is also saved in this browser's local storage for later re-verification. You can remove that saved copy through storage settings.
Website delivery, security and payments
Namecheap hosts the site and Cloudflare delivers and protects traffic. Requests necessarily expose technical information such as an IP address, requested URL, time, browser information and security signals to the infrastructure handling them. Hosting and CDN logs may retain that information under their service arrangements. The activation service also uses network-address records to limit repeated requests.
Gumroad handles checkout, payment processing, receipts and related purchase records. We do not receive card numbers through the BidVariance app. As the seller, the operator may access buyer and purchase details in Gumroad to deliver licenses, resolve support requests and meet legal obligations. See Gumroad's privacy policy, Cloudflare's privacy policy and Namecheap's privacy policy.
Why information is processed
License and purchase information supports delivery of the service you request. Technical records support security, troubleshooting and abuse prevention. Purchase records may also be needed for tax, accounting or other legal obligations. Optional local features are described on the cookies and storage page. Where applicable law requires a lawful basis, these purposes correspond to performing the purchase/service relationship, legitimate operational and security interests, legal obligations, or your consent for an optional choice.
Retention and international processing
Local projects and preferences remain until you delete them or the browser removes site data. The session cookie expires after 30 days or is cleared on successful deactivation. An optionally saved key remains until removed; calculator baselines do not persist across reloads. Offline copies can be removed through storage settings or by your browser.
License registry records have no automatic expiry in the current service. They are retained to support license access and verification, subject to applicable deletion requests and legal needs. Rate limiting uses a 10-minute active window; older database records are removed during subsequent checks, rather than by a guaranteed scheduled deletion. If the file-based fallback is used, files named with hashed network addresses may remain after inactivity. Infrastructure and Gumroad records follow their respective retention arrangements. Providers may process information outside your country; their notices describe their processing locations and transfer protections.
Your choices and requests
You can export or delete local projects in the app, remove an optionally saved key, disable offline storage, or deactivate this browser's session. Clearing all site data can permanently remove your local projects; back them up first. We cannot recover projects that existed only in your browser.
Depending on applicable law, you may have rights to access, correct, delete or restrict personal information, object to processing, obtain a portable copy, withdraw consent, or complain to a data protection authority. Use the privacy contact with enough information to identify the relevant interaction. Do not send card details, your full license key or project files unless a specific, necessary support step has been agreed. Gumroad requests may also need to be made directly to Gumroad.
Changes
We will update this page when the site's processing changes and identify the revision date. Material changes that require additional notice or consent will be handled as required by applicable law.