Legal

Privacy Policy

Last updated: April 23, 2026 · Effective date: April 23, 2026

1. Scope

This Privacy Policy (the “Policy”) explains how FP System LLC, a Delaware limited liability company (“iStealth”, “we”, “us”, or “our”), collects, uses, shares, and protects information about individuals in connection with the iStealth launcher, browser, website at fpsystem.us, and related services (together, the “Service”).

This Policy applies to customers, trial users, team members, workers, website visitors, and prospective customers who interact with us. It is read together with our Terms of Service and Acceptable Use Policy.

Where we refer to “you”, we mean the person whose data we process. Where required by data-protection law (GDPR / UK GDPR / CCPA / CPRA / state comprehensive privacy laws), we act as the controller for your personal information.

2. Who we are

3. Information we collect

3.1 Account information

  • Email address
  • Password (stored as a salted hash; never in plaintext)
  • First and last name
  • Date of birth (used to confirm you are 18+)
  • Country, state, city, street, and ZIP / postal code
  • Email-verified status and verification timestamp
  • Last login timestamp and the IP address seen at that login
  • Session tokens (opaque random strings, revocable)

3.2 Device and license information

  • Hardware serial number of the Mac on which you activate a license. We store a SHA-256 hash of the serial plus a fixed salt, not the raw serial. This is your HWID.
  • License key and plan.
  • Launcher version installed.
  • Runtime version currently active.

3.3 Payment information

  • Plan chosen, amount in USD, cryptocurrency chosen, and the amount in that cryptocurrency.
  • The deposit address we generated for your order and the blockchain transaction hash(es) we observe confirming payment.
  • Timestamp of confirmed payment.
  • We never receive or store your private keys or wallet credentials. Payments are routed through our non-custodial processor (CryptAPI); deposit funds flow directly from your wallet to our merchant wallet on confirmation.

3.4 Profile data (you configure; we store encrypted)

  • Profile names, icons, templates, proxy strings you enter, geolocation coordinates you configure, camera images you upload, password-vault entries you save. All of this stays under your control.
  • Browser session data (cookies, localStorage, IndexedDB, cache, browsing history) is pushed encrypted to our server when you stop a profile and pulled back when you next launch it. We cannot read the contents — the encryption key is derived on your device from your license key, profile id, and HWID using HKDF-SHA256, and never transmitted.

3.5 Operational logs

  • Server-side HTTP request logs: timestamp, endpoint, IP address, user agent, HTTP response code. Retained short-term for security and abuse investigation.
  • Launcher heartbeat events: license key, timestamp, launcher version, runtime version. Used to count active installations and detect tampering.
  • Audit log of sensitive actions (license activate, password reset, team invite accepted, payment received). Retained longer for fraud and dispute resolution.

3.6 Support correspondence

If you email us for support, we store your message, attachments, and the reply thread to improve support quality and for our records.

3.7 What we do NOT collect

  • Contents of your browsing sessions. Cookies, localStorage, and history are encrypted on your device with a key we cannot derive. We see ciphertext blobs only.
  • Your saved passwords. The password vault is end-to-end encrypted with the same keying scheme. We can't read it.
  • Your cryptocurrency wallet private keys. They never reach our servers.
  • Marketing trackers on our website. No Google Analytics, no Facebook Pixel, no third-party advertising cookies, no browser fingerprinting.
  • Telemetry from your Mac outside the launcher. We do not monitor other apps, network traffic not initiated by the launcher, files, or device activity.

4. How we collect it

  • Directly from you when you create an account, enter information in forms, upload a camera image, save passwords, or contact support.
  • Automatically from your device (HWID, IP, launcher version, runtime version) when the launcher or website communicates with our API.
  • From our payment processor (CryptAPI) when they notify us of confirmed cryptocurrency payments attributed to a deposit address we generated for your order.

5. How we use it

  • Account management. Register and maintain your account, verify your email, reset passwords, let you sign in.
  • License delivery. Issue license keys, bind them to a HWID, validate on each launch, serve runtime decryption keys.
  • Billing. Generate deposit addresses, confirm payments, issue receipts, handle renewals and upgrades.
  • Product operation. Sync your encrypted profile blobs across Macs you sign in on, deliver updates, enforce plan limits.
  • Security and abuse prevention. Detect stolen licenses, credential stuffing, DMG tampering, AUP violations. Enforce rate limits.
  • Legal compliance. Respond to lawful requests from law enforcement and regulators, comply with sanctions and export-control law, fulfill record-keeping obligations.
  • Communication. Send transactional email (OTP codes, receipts, password-reset links, service announcements). We do not send marketing email unless you explicitly opt in.
  • Support. Respond to your inquiries and investigate issues you report.

7. Who we share it with

We share personal information only with the parties below, and only to the minimum extent needed for the stated purpose.

  • Resend Inc. — transactional email delivery. We send them your email address and the message content (OTP code, reset link). Located in the United States.
  • CryptAPI.io — cryptocurrency payment routing. We send them our merchant wallet address and the callback URL for your order. They generate a unique deposit address and notify us of payment events. We do not send them your identity.
  • Our infrastructure provider(s) — the server on which our API runs and the content delivery for the website. They process data on our instructions as data processors.
  • Law enforcement, courts, regulators — on receipt of valid legal process or when we reasonably believe disclosure is necessary to prevent imminent harm.
  • Professional advisors (lawyers, accountants, auditors) under confidentiality.
  • Successors in the event of a sale, merger, or acquisition of FP System LLC. We will notify you before your information becomes subject to a different privacy policy.

We do not sell personal information. We do not share it with advertisers, data brokers, or marketing networks.

8. Cryptocurrency payments — special note

Cryptocurrency transactions are recorded publicly on the blockchain. While we do not publish your identity, sophisticated chain analysis can in some circumstances link a deposit address to your wallet. Understand before paying:

  • Our merchant wallet addresses are public on-chain. Your deposit address is unique per order.
  • We and our payment processor can see the sender wallet of your transaction. We do not match it to your account identity beyond the order record.
  • If you want maximum privacy, use privacy-preserving wallets and routing appropriate to the jurisdiction and law that applies to you.

9. How long we keep it

  • Account data — until you ask us to delete it or we terminate the account. Minimum 30 days after termination to recover from accidental deletions.
  • License + HWID records — for the active life of the license plus 2 years, for fraud-investigation and dispute-resolution purposes.
  • Payment records — 7 years (US tax and accounting-retention norm).
  • HTTP request logs — 30 days.
  • Audit log of sensitive actions — 2 years.
  • Profile blobs (encrypted) — until you delete the profile, plus 30 days soft-delete retention.
  • Support correspondence — 3 years from the last message.
  • We may retain information longer where required by law or to defend against legal claims.

10. How we protect it

  • Encryption in transit. TLS 1.2 / 1.3 everywhere. Modern cipher suites, HSTS on the website.
  • Encryption at rest. Profile blobs are client-side AES-256-GCM encrypted before upload. Runtime binary is AES-256-GCM encrypted on the server. Passwords stored only as salted hashes.
  • Access control. Scoped-token access to server operations; admin token rotated as needed. Principle of least privilege.
  • Hardware binding. Licenses pin to a specific Mac's hardware serial, reducing the attack surface of a leaked credential.
  • Rate limiting. Anti-abuse ceilings on authentication and sensitive endpoints.
  • Third-party audits. We periodically review configuration and dependencies. No formal SOC 2 or ISO 27001 certification yet — that is roadmap.

No system is perfectly secure. We disclose breaches as described in Section 17.

11. International transfers

Our servers and primary vendors are located in the United States. If you are based in the European Economic Area, the United Kingdom, or a country with an adequacy framework, transferring your data to the US may involve a cross-border transfer. We rely on standard contractual clauses (Commission Decision (EU) 2021/914) and/or other lawful mechanisms for such transfers. At launch, registration is restricted to US residents, which minimizes this exposure.

12. Cookies and similar technologies

The iStealth website (fpsystem.us) uses the minimum set of browser storage necessary to operate.

  • localStorage: istealth_session_v1 — your session token + account metadata so the site knows you are signed in. Cleared on sign-out.
  • No analytics, advertising, or fingerprinting third-party cookies are set.
  • We do not use a consent banner because we set no non-essential storage. If we add optional functionality in the future, we will add a proper consent mechanism before doing so.

Sites you visit inside the iStealth browser set their own cookies, which are part of your browsing activity and subject to the cryptographic isolation described in Section 3.4.

13. Your privacy rights

Subject to the limits of applicable law, you have the following rights:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Ask us to correct inaccurate or incomplete information.
  • Deletion. Ask us to delete your personal information, subject to retention obligations in Section 9.
  • Portability. Request a machine-readable export of data you provided to us.
  • Objection. Object to processing based on our legitimate interests.
  • Restriction. Ask us to restrict processing in certain circumstances.
  • Withdraw consent. Where processing is based on consent, you can withdraw it without affecting the lawfulness of processing already carried out.
  • Lodge a complaint. With the data-protection authority in your country. You do not have to contact us first, but we'd appreciate the chance to resolve the issue.

To exercise any right, email [email protected] from the email on your account. We verify identity before acting on deletion or access requests. We respond within 30 days (extendable to 60 for complex requests, with notice).

14. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act give you additional rights.

14.1 Categories of information we collect (disclosure)

  • Identifiers (email, name, IP)
  • Customer records (billing address, plan, license key)
  • Commercial information (purchases, subscriptions, renewals)
  • Internet/network activity (HWID, launcher version, heartbeat)
  • Geolocation (approximate, from IP during account creation)
  • Inferences — none. We do not profile you or infer preferences.

14.2 Purposes

As described in Section 5. We retain each category as described in Section 9.

14.3 Sale or sharing of personal information

We do not sell personal information and do not share it for cross-context behavioral advertising. You do not need to opt out because we have nothing to opt out of.

14.4 Your California rights

  • Right to know what personal information we collect, use, disclose.
  • Right to delete personal information.
  • Right to correct inaccurate information.
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising any right above.
  • Right to opt out of sales or sharing — not applicable (see 14.3).

Exercise any right by emailing [email protected]. You may also authorize an agent to submit requests on your behalf by providing signed authorization and proof of identity.

15. Other US state privacy laws

If you reside in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Iowa, Tennessee, Indiana, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Rhode Island, or any state with a comparable privacy law in force, you have rights equivalent to those in Section 13: access, correction, deletion, portability, opt-out of targeted advertising and sales, and non-discrimination for exercising them. We honor Universal Opt-Out Mechanisms (e.g., Global Privacy Control) where applicable.

Exercise rights the same way: email [email protected]. If we deny a request, you may appeal to the same address within 30 days and we will respond within 60 days with reasons.

16. Children

The Service is intended for adults. You must be 18 or older to register. We do not knowingly collect personal information from children under 13, and we do not knowingly sign up minors under 18. If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.

17. Data breach notification

In the event of a personal-data breach affecting you, we will notify you and the relevant authorities as required by applicable law — generally within 72 hours of becoming aware of the breach for EU/UK residents (GDPR Art. 33/34), and without unreasonable delay for US residents subject to state breach-notification statutes. Notice will describe what happened, what data was affected, what we are doing about it, and what you can do.

18. Changes to this policy

We may update this Policy from time to time. Material changes will be announced on the website with a new “Last updated” date at the top of this page and, where appropriate, by email to your account. Continued use of the Service after the effective date of a change constitutes acceptance of the revised Policy. If you do not agree, stop using the Service and contact us to delete your account.

19. How to contact us

© 2026 FP System LLC, Delaware USA. All rights reserved.  · Back to iStealth