🔒 Privacy & Data Protection

Privacy Policy

Transparent, responsible, and privacy-focused data practices for GHUFRAN GEN users and subscribers.

📅 Effective Date: September 2026 🔄 Last Revised: September 2026

01. Introduction & Scope

Welcome to GHUFRAN GEN ("we", "us", "our", or the "Platform"). GHUFRAN GEN is an independently developed software product, web platform, and browser companion extension owned and operated by Muhammad Ghufran (Founder & Developer). GHUFRAN GEN is accessible via our primary web portal at https://ghufrangen.billing.ghufran.net and authenticated API services at https://ghufran.net/api.

This Privacy Policy explains how we collect, process, store, and protect your information when you create an account, use our browser extension, purchase subscription plans, or contact our support desk. We are committed to maintaining the confidentiality and integrity of your data through standard technical security safeguards.

02. Information We Collect

We collect only the information necessary to deliver authenticated software services, verify license entitlements, and maintain system security:

  • Account Registration Information: When you register for an account on GHUFRAN GEN, you provide a chosen username and a valid Gmail address (@gmail.com). Account registration currently requires a Gmail address as an application authentication rule for one-time verification. Passwords are cryptographically salted and hashed using bcrypt before storage; we never store or have access to plaintext passwords.
  • Authentication & Session Data: Upon successful sign-in, our backend issues a digitally signed JSON Web Token (JWT) containing your account identifier and username. This token authenticates API communication between your browser extension and our backend server.
  • Payment & Billing Information: Payments for GHUFRAN GEN are processed through Safepay (getsafepay.com), a third-party payment service provider. GHUFRAN GEN does not collect, capture, or store raw payment card numbers, card expiration dates, or CVV/CVC security codes on its application servers. All card data is handled directly by Safepay. GHUFRAN GEN only receives and retains non-sensitive transaction reference identifiers (such as Safepay customer tokens, tracker reference IDs, plan identifiers, transaction amounts, currency, and payment timestamps) necessary to grant and maintain your software license.
  • Technical & Diagnostic Logs: Standard web server connection metadata (such as IP addresses, browser user-agent, request timestamps, and error diagnostic logs) collected temporarily for system performance, rate limiting, and server protection.
🛡️ Cardholder Data Security Notice

Payment card credentials are submitted directly to Safepay during checkout. GHUFRAN GEN application servers do not store raw card numbers or CVV codes.

03. Cookies & Local Browser Storage

GHUFRAN GEN does not use third-party advertising tracking cookies or behavioral profiling trackers. We utilize standard client-side browser storage strictly for essential operational functionality:

  • localStorage (ghufran_web_token): Holds your active authentication token locally in your browser so you remain signed in across page reloads.
  • localStorage (ghufran_web_user): Caches your basic username and plan tier to render the user interface promptly.
  • chrome.storage.local: Used by the GHUFRAN GEN Chrome extension to synchronize active license status from the web portal to the extension.

04. How We Use Your Information

We process collected information for legitimate operational and customer service purposes:

  • Account Verification: Sending transactional 6-digit one-time verification codes (OTP) to your registered email address to verify account ownership.
  • Subscription Fulfillment: Processing webhook notifications from Safepay to activate and manage your Pro subscription or trial tier.
  • Security & Abuse Prevention: Monitoring application endpoints against unauthorized credential misuse, automated scraping, or security threats.
  • Customer Support: Responding to user inquiries, billing assistance requests, cancellations, and refund claims.

05. Third-Party Service Providers

We do not sell, rent, or trade your personal information. We share data only with service providers necessary to operate the application:

  • Safepay (Payment Processing): Payments for GHUFRAN GEN are processed through Safepay, a third-party payment service provider that handles payment card transactions and payment tokenization.
  • Email Delivery Infrastructure: Transactional mail server infrastructure used solely to deliver account verification codes and password reset emails.
  • AI Services & APIs: GHUFRAN GEN features may interact with third-party generative AI APIs (such as Google Gemini APIs) to process user-initiated prompts and creative generation requests. Prompts submitted by users for generation are transmitted to the relevant API provider in accordance with their standard terms and privacy policies. Google and Gemini are trademarks and technologies of Google LLC; GHUFRAN GEN does not claim ownership of Google's underlying models or infrastructure.

06. Data Retention & Account Deletion

Account records and subscription history are retained while your account remains active to provide ongoing service and maintain necessary accounting records. If you wish to delete your account, you may submit a request to facebookrd811@gmail.com. Upon verification of account ownership, your user credentials and stored session tokens will be removed from our active database. Certain transaction, accounting, security, or legally required records may be retained where necessary.

07. Data Security Safeguards

We implement appropriate technical measures designed to protect your personal data:

  • Encrypted Communications: Data transmitted between your browser and our servers is encrypted using standard Transport Layer Security (HTTPS / TLS).
  • Password Hashing: Passwords are encrypted using salted bcrypt hashing algorithms prior to storage.
  • Webhook Signature Verification: Billing event webhooks received from Safepay are cryptographically verified using SHA-256 HMAC signatures to prevent unauthorized tampering.
  • Server Protection: Application servers are maintained in managed cloud hosting environments with firewall configurations and access controls.

08. Your Rights & Choices

As a user of GHUFRAN GEN, you have the right to:

  • Review the username, email address, and subscription tier associated with your account.
  • Request cancellation of your subscription by contacting our support desk.
  • Request a refund within the terms of our 7-Day Customer Satisfaction Refund Policy.
  • Request deletion of your account by emailing support.

09. Policy Updates

We may update this Privacy Policy periodically to reflect enhancements to our software, operational practices, or legal requirements. Updates will be posted on this page with a revised "Last Revised" date. Your continued use of the platform following any posted revisions constitutes your acknowledgment of the updated policy.

10. Contact & Customer Support

If you have any questions, feedback, or requests regarding this Privacy Policy or your data, please contact our support desk:

📬 Customer Privacy & Support Desk
👤 Operator / Developer: Muhammad Ghufran
✉️ Support Email: facebookrd811@gmail.com
✉️ Contact Privacy Support