Effective Date: 06/09/2026
Welcome to Cheatsheet (the "Service"). This privacy policy explains how we collect, use, disclose, and safeguard your information when you visit our website cheats.aarontrotter.com, use our web application, and engage with our services that utilize Firebase and Google services. It is an information notice rather than a contract, so there is nothing here for you to agree to.
The data controller for the personal data described in this policy is Aaron Trotter, trading as Cheatsheet, in Poland (Polish NIP PL5272928902). You can contact us about anything in this policy, including to exercise any of the rights set out below, at [email protected]. We are not required to appoint a data protection officer and have not appointed one.
Account Information: When you register an account with us, we collect your email address, username, and password.
Profile Information: Additional information you provide in your profile, such as your name, bio, and profile picture.
Log Information: We collect information about your use of the Service, including the type of browser you use, access times, pages viewed, your IP address, and the page you visited before navigating to our Service.
Device Information: We collect information about the device you use to access the Service, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
Firebase: The website runs on Google Firebase. We use Firebase to collect and analyze usage data and performance metrics and store all data. Specifically, we use Firebase Analytics to understand how visitors use the Service (such as pages viewed and general usage patterns) and Firebase Performance Monitoring to measure page load times and app performance; both may set cookies or use similar identifiers on your device.
Algolia: We use Algolia to provide search functionality and may collect data about your search queries and interactions with our search features.
Code Snippets: We store the code snippets you create and save within the Service. This includes any metadata associated with the code snippets.
Vault Content: If you use the Vault feature, your notes are encrypted on your device before being sent to us. We store only the encrypted content and cannot read it, since we never receive your passphrase.
Task Content: If you use the Tasks feature, we store your to-do lists, AI plans, and similar notes unencrypted. Tasks are kept out of cheat search and do not have visible revision history.
Pennies Content: If you use the Pennies feature, we store your logged crypto/stock buy and sell orders unencrypted. Pennies data is kept out of cheat search and does not have visible revision history.
Projects Content: If you use the Projects feature, we store your project names and the cards on your board unencrypted. Projects data is kept out of cheat search and does not have visible revision history. A project is private to you unless you choose to share it. If you invite someone to a project, we store their email address, the access level you gave them, and an invite record, and we send them an email containing the project name, your name or email address, and a link to accept. Once they accept, they can see everything on that board, and anyone you gave editing access can also change it. You can remove someone, or cancel a pending invite, at any time.
Upgrade Requests: If you request a Pro plan upgrade, we store your email address and display name so we can follow up with you and provide an activation code.
Plan Status: We store whether your account is on the Free or Pro plan.
API Keys: If you generate an API key, we store a one-way hash of the key (not the key itself), along with its label, permitted scopes, and when it was created and last used.
API Usage: We track how many API requests your account makes each day in order to enforce a daily limit.
Payment Information: Paid Pro subscriptions are processed by Stripe, which handles the payment as an independent controller under its own privacy policy. We never receive or store your card details. What we do store is the subscription record Stripe sends back to us: a Stripe customer and subscription identifier, the plan you are on, its status, and the current billing period. Stripe may also need your billing country for tax purposes.
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to tell you which legal basis we rely on for each use of your personal data. Ours are:
We do not sell your personal data, we do not use it for advertising, we do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not use the content you store on the Service to train any AI model.
The providers we rely on to run the Service are based in, or transfer data to, countries outside the European Economic Area, including the United States. This applies to Google (Firebase), Algolia, and Stripe. Where personal data is transferred outside the EEA or the UK, we rely on the transfer safeguards those providers have in place, which are the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for more detail about the safeguards that apply to a particular transfer.
We use administrative, technical, and physical security measures to help protect your personal information. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable.
Account Information: You can delete your account yourself at any time, using the Delete Account button on your Profile page. Deletion happens immediately and cannot be undone. I use Firebase Authentication to manage accounts. If you signed in using a third-party provider, you may also revoke this app’s access through your account settings with that provider, which will prevent future logins. Please note that revoking access does not delete any account data already stored, so use Delete Account if you want that data removed. If you have any difficulty deleting your account, contact me at [email protected] and I will act on your request in a timely manner.
Cookies: We use cookies and similar identifiers that are strictly necessary to run the Service, such as keeping you signed in. Those do not require your consent. We also use Firebase Analytics and Firebase Performance Monitoring, which set optional cookies and identifiers that are not strictly necessary, and we ask for your consent before either of those starts. You can change or withdraw that choice at any time, either from the Cookie Settings link in the footer of any page or from the Cookies section of your Profile page. You can also remove or reject cookies through your browser settings, though the strictly necessary ones are needed for sign-in to work.
Communications: You may opt out of receiving promotional communications from us by following the instructions in those communications.
Account Deletion and Published Content: If you delete your account, any private cheats or code snippets you have created will be removed, as is everything held in your Vault, Tasks, Brain, Pennies, and Projects, together with your API keys, trusted devices, account links, and any project invites you sent or received. Projects you own are deleted along with every card on them, and you are removed from any project someone else shared with you. However, any cheats that you have published publicly will remain visible on the Service, as they are considered public content, and cards you added to someone else's shared project stay on their board for the same reason. If you wish for everything to be removed, please make all content private, and remove your cards from any shared project, before deletion.
Account Deletion and Pro: Deleting an account on the Pro plan ends that plan immediately and is non-refundable. If you sign up again later, contact us for a new upgrade code.
Merging Accounts: Merging closes the account you merge from and moves its content, including its Vault, Tasks, Brain, Pennies, and Projects, to the account you keep. Any projects other people shared with the closed account move across too, keeping the same access level. Its API keys, trusted devices, account links, and pending project invites are deleted rather than transferred. Its Pro plan, if any, does not transfer automatically to the account you keep; contact us afterward and we will apply Pro to it at no charge.
If you are in the European Economic Area or the United Kingdom, you have the following rights over your personal data. You can exercise any of them by emailing us at [email protected]. We will respond within one month, and we do not charge for this.
You also have the right to complain to a data protection authority. Ours is the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), at uodo.gov.pl. You may also complain to the authority in the country where you live or work.
Our Service is not directed at anyone under the age of 16, and you must be at least 16 years old to use it. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us at [email protected]. If we become aware that we have collected personal information from a child under 16, we take steps to remove that information from our servers.
We may update this privacy policy from time to time. If we make changes, we will notify you by revising the effective date at the top of the policy, and in some cases, we may provide additional notice (such as adding a statement to our homepage or sending you a notification). We encourage you to review the privacy policy whenever you access the Service to stay informed about our information practices and the ways you can help protect your privacy.
If you have any questions about this privacy policy, please contact us at: