Last updated September 14, 2026
Privacy
Release Claims collects only what is needed to authenticate authors, route release requests, prevent abuse, process workspace subscriptions, report request status, and show authors how their public pages are used.
Who we are
Release Claims (release.claims) is operated by Lukany LLC, a company based in the United States. For any question or request about your data, email support@release.claims.
Data we process
- Author email, public author-page fields, plan, and verification evidence.
- Requester name and email, public project URL, track and claim details, and submitted evidence.
- Short-lived abuse-prevention hashes derived from IP data, user agent, security events, and Cloudflare request metadata.
- For paid plans: the email used at checkout and the Stripe customer, subscription, plan, status, and billing-period identifiers. Card numbers are entered directly on Stripe and never reach our systems.
- Aggregated product events for service reliability and author-facing metrics.
- Page traffic for public author and track pages: daily counts of views, the domain a visit came from (for example youtube.com), clicks on catalog and profile links, and license checks. These are counters per author page and day; no IP address, cookie, or visitor identifier is stored with them, signed-in visits are not counted, and the text pasted into the license check is not kept.
- Alert settings chosen by an author: a Slack or Discord webhook address, or a Telegram bot token and chat ID, stored so that new-request and reply alerts can be posted to that channel. Those alert messages carry the request reference, request type, track title, and platform, never the requester's name or email.
Payments
Paid plans are billed through Stripe, Inc., an independent payment processor. At checkout Stripe collects your payment details, name, email, and billing address directly and uses them under the Stripe Privacy Policy. We receive only the identifiers listed above and the payment status, which we use to grant plan features, send billing-related emails, and keep accounting records. Stripe emails receipts and lets you update your payment method, email, or subscription in its customer portal, reachable from Manage billing in your dashboard.
Storage and processors
Application and session data is stored in Cloudflare D1; uploaded evidence can be stored in private Cloudflare R2; transactional messages use Cloudflare Email Sending; bot checks use Cloudflare Turnstile; product events use Workers Analytics Engine. Stripe processes paid-plan checkout, invoicing, and subscription management. If an author connects a Slack, Discord, or Telegram channel, alert messages are delivered to that service under its own terms; the author can disconnect it at any time from the dashboard. Google AdSense is loaded only on ad-supported public pages when configured; on those pages visitors in the European Economic Area, the United Kingdom, and Switzerland are shown Google's certified consent message before any advertising cookie is set, and the choice made there governs whether ads are personalised. We do not sell personal data.
Emails we send
Authors receive transactional emails: sign-in codes, an alert for each new request, alerts for requester replies on paid plans, and a periodic digest of requests and page traffic (monthly on Free, weekly on paid plans). The digest can be turned off under Alerts and digest in the dashboard. Requesters receive a receipt with their private tracking link and an email whenever the status of their request changes or the author replies.
Cookies
After sign-in we set one HttpOnly session cookie that expires after 30 days. Stripe sets its own cookies on its checkout and customer-portal pages. We do not use advertising cookies unless Google AdSense is shown on a public page, and there only as far as the consent message allows.
Retention
Authentication challenges expire after ten minutes. Sessions expire after 30 days. Claim records are retained while the workspace exists and for as long as needed to handle disputes. Billing records are kept for as long as accounting and tax obligations require, typically seven years. Other data is deleted or anonymized when it is no longer needed.
Your rights
Email support to access, correct, export, or delete your personal data; we answer within 30 days and may need to verify that you control the email address concerned. You can change the email on your subscription in the Stripe customer portal. Requesters may also contact the author shown on the relevant page about a submitted record.
Changes
We may update this policy. Material changes are announced by email or in the dashboard before they take effect, and the date at the top always shows the current version.