Effective date: 13 August 2026 Last updated: 13 August 2026
1. Who PisgaX is
This Privacy Policy explains how PisgaX processes personal data when you visit the PisgaX website, read its documentation, contact PisgaX, download or install a PisgaX project, or use a PisgaX skill, tool, automation, or related service.
“PisgaX,” “we,” “us,” and “our” mean PisgaX, operating from Accra, Ghana. PisgaX’s privacy contact is privacy@pisga-x.com.
2. Scope and product-specific notices
This Policy applies to the public PisgaX website and personal-data processing controlled by PisgaX. A downloadable or installable project may collect different information, operate locally, connect to third-party services, or include its own telemetry and update mechanisms.
Before installing or using a project, read its README, licence, end-user licence agreement, security notice, permissions, dependency notices, and any product-specific privacy notice. If a product-specific notice conflicts with this Policy, the product-specific notice controls the processing described there.
This Policy does not apply to websites, AI providers, package registries, cloud platforms, email providers, social networks, operating systems, or other third parties that PisgaX does not control.
3. Personal data currently collected
The personal data collected depends on how you interact with PisgaX and may include the following categories.
Contact-form data
When you use the contact form, PisgaX collects:
- your name;
- your email address;
- the message and other information you choose to include; and
- your agreement to the Terms of Service.
Technical and security data
Hosting, delivery, security, and infrastructure providers may process technical information such as an IP address, browser and device information, request timestamps, approximate location derived from an IP address, referring page, error information, and security logs. The exact fields depend on the provider and service configuration.
Publicly supplied information
If you contact PisgaX through a public social or messaging platform, that platform and PisgaX may receive information associated with your account and message. The platform’s own privacy policy also applies.
Installed projects
An installed project may process files, prompts, configuration values, device information, logs, network requests, or other data depending on its documented behavior. Product-specific documentation should identify:
- permissions requested;
- files and directories accessed;
- data sent over a network;
- third-party services and AI providers contacted;
- telemetry, diagnostics, and crash reporting;
- local storage and retention;
- update and uninstallation behavior; and
- whether user content is used to improve a model or service.
PisgaX will not describe a product as “local-only,” “no telemetry,” or “private by design” unless that claim has been technically verified for the relevant version.
4. Information not intentionally requested
PisgaX does not intentionally request sensitive personal data through the public contact form. Do not submit passwords, API keys, private keys, payment-card details, government identification numbers, health information, confidential business information, or another person’s personal data through the form.
PisgaX does not intentionally collect children’s personal data through the current public contact form. If a parent or guardian believes a child has provided personal data, contact privacy@pisga-x.com.
5. How personal data is used
PisgaX may use personal data to:
- receive and respond to enquiries;
- communicate about a requested collaboration, support issue, or project;
- operate, host, secure, troubleshoot, and maintain the website;
- detect spam, abuse, fraud, unauthorised access, and security incidents;
- understand technical failures and improve reliability;
- comply with legal obligations, lawful requests, and dispute-resolution requirements;
- establish, exercise, or defend legal claims; and
- protect the rights, safety, and property of PisgaX, users, and third parties.
PisgaX does not use contact-form messages for unrelated advertising or sell them to data brokers.
6. Legal bases where applicable
Where a law such as the GDPR or UK GDPR applies, the legal basis may include:
- performance of a request: processing an enquiry or responding to a message;
- legitimate interests: operating, securing, and improving the website, preventing abuse, and maintaining business records, where those interests are not overridden by your rights;
- legal obligation: retaining or disclosing information where required by law; and
- consent: where consent is legally required, such as for certain optional cookies, marketing communications, or product telemetry.
The applicable basis depends on the specific processing activity, your location, and the legal relationship involved. Where Ghana’s Data Protection Act, 2012 (Act 843) applies, PisgaX provides information about the data collected, its purpose, the responsible party, whether supplying it is mandatory or optional, its recipients, and the available data-subject rights.
7. Contact-form processing
Contact-form submissions are sent through Resend and delivered to a PisgaX mailbox hosted by Hostinger using the server-side contact-form integration.
The visitor’s email address is used as the reply-to address so PisgaX can respond. The sender address is a PisgaX address configured in Resend. Resend and Hostinger may process message content, email addresses, delivery metadata, security logs, and bounce or abuse information according to their own policies and contractual roles.
Do not send confidential or sensitive information through ordinary email. The retention periods for contact-form information are described in Section 13.
9. Downloadable and installable software
PisgaX projects may run on a user’s computer or other device. The privacy impact is product-specific. Installing a project does not authorise it to collect or transmit personal data beyond what is documented and lawfully required.
Each project that processes personal data should provide a product privacy notice stating:
- the controller or operator for the product;
- the categories of data processed;
- whether processing happens locally or remotely;
- purposes and legal bases;
- vendors and AI or cloud providers;
- international transfers;
- retention and deletion behavior;
- security controls;
- user controls and opt-outs; and
- a privacy contact and complaint route.
If a project accesses files, credentials, microphones, cameras, system information, browser data, or networks, its documentation must explain why and require appropriate user permission. PisgaX will not intentionally design software to collect credentials, private keys, unrelated files, or personal data covertly.
10. AI, automation, and user content
Some PisgaX tools may send prompts, uploaded material, configuration data, or generated content to third-party AI or automation providers. A product must clearly disclose this before the relevant data is sent.
Do not submit personal data, confidential information, copyrighted material without permission, secrets, or regulated information to an AI or automation feature unless the product expressly supports that use and provides appropriate safeguards.
PisgaX processes user-provided content only for the documented purpose of operating, securing, supporting, or improving the relevant product, or where required by law. PisgaX does not use user content to train models or create profiles unless that use is separately disclosed and legally permitted.
11. Service providers and recipients
Personal data may be disclosed to providers that help PisgaX operate the website or respond to users, including:
- website hosting and deployment providers, currently Vercel where applicable;
- email delivery providers, currently Resend;
- mailbox providers, currently Hostinger;
- security, anti-abuse, monitoring, and infrastructure providers;
- software, package, repository, and cloud providers used by a particular project; and
- professional advisers, law-enforcement authorities, regulators, courts, or other recipients where disclosure is required or permitted by law.
Providers may process information under their own terms, privacy policies, contracts, security practices, and legal obligations. PisgaX does not authorise providers to use contact messages for purposes unrelated to providing their services to PisgaX, except where their own legal obligations require otherwise.
12. International transfers
PisgaX and its providers may process personal data in countries other than the country where you live, including countries where hosting, email, security, or AI infrastructure is located.
Where data-protection law requires safeguards for an international transfer, PisgaX will use an applicable mechanism such as an adequacy decision, approved contractual terms, another lawful transfer instrument, or a permitted derogation.
13. Data retention
PisgaX retains personal data only for as long as reasonably necessary for the purpose for which it was collected, including responding to enquiries, maintaining security, resolving disputes, complying with legal obligations, and establishing or defending legal claims.
Under Ghana’s Data Protection Act, 2012 (Act 843), personal data should not be retained longer than necessary for the purpose for which it was collected and processed. When the applicable retention period ends, PisgaX will delete, anonymise, or securely dispose of the information unless continued retention is required or reasonably necessary by law.
The following retention periods apply to PisgaX-controlled copies:
| Data category | Purpose | Retention period |
|---|---|---|
| Contact messages | Responding to enquiries and maintaining necessary communication records | Up to 12 months after the last meaningful communication |
| Privacy, legal, or rights requests | Processing and documenting the request | Up to 24 months after closure, or longer where necessary to demonstrate compliance or resolve a dispute |
| Security vulnerability reports | Investigating, remediating, and documenting security issues | Up to 24 months after closure, or longer where necessary for security, legal, or audit purposes |
| Email delivery and bounce records | Delivery, troubleshooting, abuse prevention, and service reliability | Up to 30 days where retained by Resend under the applicable plan or service configuration |
| Hosting and application logs | Security, debugging, abuse prevention, and reliability | Up to 14 days by default where governed by Vercel’s standard runtime-log limits, unless the configured Vercel plan or observability settings provide a different period |
| Security or abuse investigation records | Detecting and investigating attacks, fraud, or misuse | Up to 12 months, or longer where reasonably necessary to complete an investigation or comply with law |
| Product telemetry or crash data | Product reliability and troubleshooting | Not collected by default; if introduced, the relevant product privacy notice will state the specific retention period |
| Legal, accounting, and compliance records | Meeting legal obligations and establishing or defending claims | For the period required by applicable law or reasonably necessary for the relevant claim or obligation |
| Backups and disaster-recovery copies | Service restoration and business continuity | According to the configured provider backup cycle; deleted or overwritten through the provider’s normal rotation process |
These periods apply to data that PisgaX controls. Third-party providers may retain copies of messages, metadata, logs, backups, or other information under their own privacy policies, contracts, security practices, and service configurations.
For the current contact form, messages are transmitted through Resend and delivered to a PisgaX mailbox hosted by Hostinger. Resend’s published service information states that data retention depends on the applicable plan, with its current pricing information describing 30-day data retention. Vercel states that runtime-log retention depends on the plan and whether enhanced observability is enabled. Hostinger may retain mailbox content and backups according to the applicable mailbox, hosting, and backup configuration.
PisgaX will periodically review stored contact messages and delete or anonymise records that are no longer required. Deletion may not immediately remove copies held in encrypted backups, provider archives, email systems, or legally preserved records. Such copies will remain protected and will be deleted or overwritten according to the applicable provider’s retention cycle.
PisgaX does not retain personal data indefinitely merely because it may be useful in the future.
14. Security
PisgaX uses reasonable administrative, technical, and organisational safeguards appropriate to the nature and risk of the data. These may include server-side secret handling, access controls, dependency updates, secure hosting, input validation, spam controls, least-privilege access, backups, and incident response.
No internet service is completely secure. Do not submit passwords, API keys, private personal information, or other sensitive data through public forms or public GitHub Issues.
If you discover a potential security vulnerability, report it privately to security@pisga-x.com. Do not create a public GitHub Issue for security vulnerabilities. Do not access, copy, retain, modify, or disclose data outside the intended testing scope.
Security reports should include:
- a clear description of the vulnerability;
- the affected project, page, package, or version;
- reproduction steps or a proof of concept;
- the potential security impact; and
- any suggested mitigation.
PisgaX may acknowledge valid reports and will assess, contain, document, and address security incidents. Where required by applicable law, PisgaX may notify affected persons or regulators.
15. Privacy rights
Depending on where you live and whether the relevant law applies, you may have rights to:
- ask whether PisgaX processes your personal data;
- access a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to processing;
- withdraw consent where processing relies on consent;
- request portability where applicable;
- object to direct marketing or certain profiling; and
- complain to a data-protection authority.
To make a request, contact privacy@pisga-x.com. PisgaX may need to verify your identity and may ask for clarification. PisgaX will respond within the time required by applicable law. Rights are subject to lawful exceptions, including security, legal privilege, the rights of others, and legal retention duties.
If you are in Ghana, you may contact the Ghana Data Protection Commission after first giving PisgaX a reasonable opportunity to address your concern. If you are in the EU/EEA, UK, California, or another jurisdiction with additional rights, those rights apply where the applicable legal thresholds are met.
16. Children’s privacy
The current public website is not intended to knowingly collect personal data from children under 18 years. If PisgaX learns that it collected such data without a legally valid basis or required consent, PisgaX will take reasonable steps to delete it.
17. Third-party links and services
The website may link to social networks, repositories, package registries, documentation, AI providers, or other third-party services. PisgaX does not control their privacy practices. Review their privacy notices before providing personal data or installing software from them.
18. Changes to the Policy
PisgaX may update this Policy when its services, vendors, products, or legal obligations change. The updated version will display a new “Last updated” date. Where law requires notice or consent for a material change, PisgaX will provide it through an appropriate channel.
19. Contact and complaints
For privacy questions, requests, or complaints, contact:
- Privacy contact: privacy@pisga-x.com
- General contact: hello@pisga-x.com
- Security contact: security@pisga-x.com
- Legal contact: legal@pisga-x.com
- Legal operator: PisgaX
- Address: Accra, Ghana