skip to content

privacy policy

last updated: 2026-05-27

This page explains what stressify.su("the Service") stores about you and what we do with it. Read it together with the Terms of Service. There is no legal entity behind the Service. It is a private project run from Minsk, Belarus, at the address shown in the footer (8 Aranskaya Str., 4th floor, block 1).

1. what we store

  • account: username, bcrypt hash of your password, bcrypt hash of your app-lock passcode (if you set one), and the lastSeenAt timestamp;
  • billing: payment history (plan, amount, currency, gateway invoice id, status);
  • boots: target, layer, method, duration, concurrents, start and end timestamps;
  • support: tickets you open and the messages inside them;
  • api keys: a hash of the key (we never store the key itself), its limits, and any IP allow-list you set;
  • an internal admin action log (which account did what — the action and affected record, for abuse handling; no IP).

We do not log or store your IP address at all — not for tracking, profiling, advertising, geolocation, user-agents, browser fingerprints or analytics, and not in the admin action log (login and registration included). The only place an IP is persisted is any IP allow-list you yourself add to an API key to restrict that key. Cloudflare may see your IP at the network edge. IPs used for rate-limiting stay only in memory and are discarded.

2. how long we keep it

Login sessions live for 7 days and then die server-side. We run automated cleanup: boot history and notifications are purged after 90 days, the admin action log after 90 days, and unpaid / stale invoices after 24 hours. Account, billing and ticket data stays as long as the account stays; an administrator can also purge data sooner.

3. third parties

We do not sell or trade your data. The only outside services we touch are:

  • Cloudflare Turnstile, captcha at signup and login to keep bots out;
  • a crypto payment gateway that settles plan purchases on chain.

If a Belarusian (or any other) law-enforcement body sends a lawful request, we hand over what we have. The Terms cover this in more detail.

4. your rights

  • Fix your data: you can change your password from the profile page whenever you want.
  • Hide your status: flip the prefHideOnline preference and we stop publishing your last-seen.
  • Silence notifications: flip prefMuteNotifs and we stop sending broadcasts and expiry warnings.

5. account deletion

We never auto-delete inactive accounts. If we terminate an account for breaking the Terms, the data goes with it. You can delete your own account at any time from your profile page, it wipes the account and everything tied to it.

6. data security

Passwords are stored as bcrypt hashes, never plaintext. Sessions are httpOnly and tied to a single account. The database sits on infrastructure we control directly.

7. changes to this policy

This page can change at any time.

8. acceptable use disclaimer

The Service is meant for authorised load-testing only. You may launch tests only against assets you own or have written permission to target. Sending traffic to third-party infrastructure without that permission is not allowed.

9. contact

Privacy questions and data-deletion requests: [email protected]