LEGAL

Privacy Policy

Including our data-protection notice. We list every field we collect, where it goes and how long we keep it — line by line, not in vague generalities.

Effective: 2026-08-22 Version: 1.6 Software version: v1.9

Contents

  1. Data controller
  2. The short version
  3. What the app sends to our server
  4. What our server adds by itself
  5. What stays only on your device
  6. What we never collect
  7. What we see in the admin panel
  8. Third parties and international transfers
  9. Legal basis and purpose
  10. Retention
  11. Security
  12. Your rights
  13. Children and age limit
  14. Changes

1. Data controller

To be completed before launch

The data controller's legal name, address and contact channel will be published in this section, together with — for customers in the EU/EEA — the name and address of our representative in the Union under Article 27 GDPR. These details are mandatory (KVKK Art. 10 · Article 13 GDPR).

2. The short version

w0a is a licensed desktop application. It sends data to our servers for one reason only: to check whether your licence is valid. Your games, files, browsing history and keystrokes are never collected.

The app sends our server six fields in total: your licence key, a hardware ID derived from your device, a hardware summary sent with the licence checks the app makes and stored only at first activation, and the version, time and text digest of the agreement you accepted in the app (kept on your licence record as evidence of acceptance). The digest is a one-way checksum of the agreement text itself; it says nothing about you and exists so we can show which wording you were shown. Separately, our server records your IP address from the connection itself and the country derived from it.

3. What the app sends to our server

These are all the requests the app makes to our server for licence checks, and their full contents are listed below. Two more exist. While the app is open it holds a live connection to our server so that a cancelled or banned licence stops working within seconds; that connection carries the same licence key and hardware ID and nothing else, and the app re-opens it whenever it drops. And at exit: when you close the app it sends the same licence key and hardware ID as a sign-off notice, so the admin view stops showing the device as online. There are no others.

The only other traffic: the update check, a report you send, and the tests you start yourself

The app downloads a version file and a changelog file to see whether a newer build exists, and — only if you accept an update — the installer itself. These are read-only requests: nothing is uploaded — your licence key, hardware ID and everything else are absent from them. As with any HTTP request, the server hosting those files sees your IP address in its own logs. The DNS test, the game server ping, the Windows Update scan and the optional sensor-driver installation run only when you start them; who sees what during each of those is listed in section 8. The one thing that travels the other way is a problem report, and only when you press send: section 5 lists exactly what it carries.

3.1 Licence key

The key you enter is transmitted on every validation. We use it to determine your subscription's validity and duration.

3.2 Hardware ID (HWID)

To verify that one licence is used on one device, an identifier is generated from your machine. It is the SHA-256 hash of three values combined, of which only the first 32 characters are used: the product UUID the manufacturer wrote into your motherboard's firmware, the motherboard serial number and the processor ID. None of these belong to Windows, so reinstalling Windows does not change the identifier. Only on a machine whose firmware carries no usable identity — some virtual machines and boards shipped with placeholder values — does the app fall back to the Windows installation ID (MachineGuid) combined with the processor ID, and only there does a reinstall change the identifier.

The raw serial numbers never leave your device. Only the irreversible hash is sent to us; your processor and motherboard serial numbers are never transmitted. They are cached locally on your own device — in a small file under your Windows user folder — so your licence stays tied to this machine even if one reading later changes; that copy is never uploaded.

3.3 Hardware summary (sent with the licence checks)

To make support easier and to detect licence abuse, the fields below are sent when the app checks your licence. Two such checks run at the start of a session — the one at start-up and the first background check a few minutes later — and they do not know about each other, so where a key is already stored the summary is sent twice per launch rather than once. It is not re-sent after that while the app stays open, and it is also sent whenever you activate or re-check a key yourself on the Settings page. The server records the fields only at first activation; later submissions are ignored and the record is not updated.

Field Example content Personal?
Computer nameDESKTOP-A1B2C3Yes
Local network IP192.168.1.24Yes
Operating system and versionWindows 11 Pro 26200No
Architecture64-bitNo
Manufacturer and modelASUS / ROG StrixNo
Processor modelRyzen 7 9800X3DNo
Logical core count16No
Motherboard modelASUS B650-ANo
BIOS2.14No
Graphics cardRTX 5070 TiNo
Total RAM32 GBNo
RAM modules2 × 16 GB @ 6000No
Screen resolution2560 × 1440No
System uptime4 hoursNo

When the in-app Privacy (streamer) mode is on, your local network IP is sent masked. That is its only effect on data collection: it visually hides your licence key, HWID and IP on screen, but does not reduce what else is collected. We will not overstate it.

4. What our server adds by itself

The following are not sent by the app; our server derives them from the connection itself. We call them out separately because you would not otherwise realise they are recorded.

Data How it is obtained How often
Your public IP address Read from the connection; not truncated or anonymised At activation, then updated at most once per hour
Country code and name From your IP via a third-party service (see section 8) At activation; if the lookup returns nothing then, it is retried on a later licence check
Last seen timestamp The time of the validation request; the sign-off notice sent when you close the app moves it back by an hour Written at most once per hour
Your email address From the purchase notification sent by the payment provider Once, at purchase
The payment provider's customer and subscription references From the purchase notification, so that a later renewal or cancellation can be matched back to your key Once, at purchase
To be straight with you

On the live-revocation connection, your licence key and hardware ID are sent in the request headers rather than in the address line, so they do not appear in ordinary URL access logs. The infrastructure in front of our servers still handles the connection; we mention it so you know it exists and are not hiding it from you.

5. What stays only on your device

The following are stored on your computer under %AppData%\w0a\. Apart from the exceptions marked below, they are never transmitted to us:

Your RAM module serial numbers and mouse/keyboard model details are displayed in the app but are not included in the hardware summary sent to our server.

The one exception: problem reports

The error log above leaves your device in exactly one case: when you choose to send a problem report. Nothing is sent automatically and nothing is sent in the background. There are two ways to send one and they are not identical. On the app's Settings page you write the message yourself, and attaching the error log is your choice — a tick box you can clear. After a crash the app asks whether the crash may be reported; if you answer yes, the message is the error detail rather than text you wrote, and the last lines of the error log go with it in every case, because that prompt has no tick box. What is transmitted is that message, any contact detail you choose to add (the crash prompt asks for none, so there it is empty), the app version, your Windows build, your CPU and graphics card model, the error-log excerpt where one is attached, and — if you have one — your licence key and hardware identifier. Windows user-folder paths, your Windows username and anything shaped like a licence key are removed from both the message and the excerpt before sending. The username removal works by exact match and is not applied to usernames shorter than three characters, because blanking such a short string would mangle the report; the user-folder path removal still applies in that case. Your name and computer name are not included. For every report — whether from the app or the website form — our server also records the connecting IP address, used solely to limit abuse and deleted together with the report; on an IPv6 connection only the network half of that address is kept. Where report forwarding is switched on, the message, any contact detail you added, the app version, Windows build, CPU and graphics card model and the masked form of your licence key are relayed to our support channel (Discord) so that they reach us; the error-log excerpt is never forwarded. Reports are removed by a daily clean-up once they are 90 days old, and are used only to fix the problem you described.

Why the licence key travels with a report, since the report used to be fully anonymous: the reporting endpoint has to accept people who hold no secret, so limiting it by IP address alone did not work — anyone able to rent a few hundred addresses could send one report from each and fill the channel, keeping genuine reports out. The allowance is therefore one report per licence per hour, counted against the licence key, which is the only thing here we can actually verify and the only thing we can withdraw from someone abusing it. The key itself is never written into the report file: we store a one-way digest of it, and our operator console shows it masked (first four and last four characters). If you have no licence key, the hardware identifier is used instead, and if you have neither — the report form on this website — the connecting IP address is.

The same applies to the report form on our website: it sends only what you type into it, and our server additionally records your connecting IP address for that request — used solely to limit abuse of the form, and deleted with the report by that same 90-day clean-up. No account, cookie or tracking identifier is involved, and the form is never pre-filled with anything about you.

6. What we never collect

7. What we see in the admin panel

The panel we use to manage licences shows the operator everything listed in sections 3 and 4. For transparency, here is the full list:

Only an authorised operator can reach this panel, through a separate access channel that requires authorisation. Administrative actions taken there (creating a key, banning, changing duration) are written to a separate log server; those records are automatically deleted after 90 days and hold the time of the action, the action itself, a masked form of the licence key it was applied to — or, where the action covered several keys at once, how many — a short detail such as the new duration, and the operator's IP address, not yours.

The panel can also export the entire database to a file. When such an export is made, a copy of the data above exists on the operator's device. These copies are made only for backup and server migration, and are not shared with third parties.

8. Third parties and international transfers

Who What is transferred When
Geolocation service (ipwho.is) Your public IP address At activation; if the lookup returns nothing then, it is retried on a later licence check
Payment provider (Paddle - merchant of record) Your payment details (never reach us), your email address (does reach us) During purchase
Email delivery provider (Google / Gmail SMTP) Your email address and licence key When your key is sent
Front-end proxy / CDN (Cloudflare) Your IP address, and on a licence check the request contents (licence key and hardware ID) as they pass through to our server On every request to our servers
Support forwarding (Discord) The text you write in a problem report, any contact detail you choose to add, and the app version, Windows build, CPU and graphics card model that accompany it — the error-log excerpt is never forwarded Only if you send a problem report, and only where report forwarding is enabled
Public DNS providers Your connection's public IP, plus the random test name the resolver is asked to look up — a subdomain of microsoft.com, chosen so the resolver cannot answer from cache (nothing returns to us) Only if you run the DNS speed test
Reference hosts in each game-server region Ping packets carrying your connection's public IP (nothing returns to us). These are not FACEIT's own machines — FACEIT does not publish those. They are third-party endpoints verified to sit in each region: Valve relays, and network operators in Finland, Russia and Kazakhstan. Only if you run the game server ping test
Microsoft (Windows Update) The update search is performed by Windows' own update service against Microsoft's servers; the app only reads the result and uploads nothing Only if you press Scan on the Updates page
GitHub (PawnIO driver setup download) Your connection's public IP address, which GitHub sees as it serves the setup file Only if you choose to install the optional sensor driver

Each of these transfers happens for one purpose only: the geolocation service to derive your country, the payment provider to take the payment and issue the invoice, the email provider to deliver your key, the front-end proxy to carry and filter the connection, the support forwarding to bring your report to us, and the DNS, ping, Windows Update and driver-download requests to run the test or installation you started yourself. None of them is used for advertising, profiling or any other purpose.

Several of these recipients — the geolocation service, the payment provider (Paddle), the email delivery provider (Google), the front-end proxy (Cloudflare) and, where enabled, the support-forwarding service (Discord) — are established abroad; to that extent your personal data is transferred internationally. Where a transfer is necessary to perform your contract — payment processing and delivery of your key — we rely on that necessity. For the remaining recipients we rely on the international transfer mechanism that provider makes available to its customers under the applicable law; you can ask which mechanism applies to a given recipient, and how to obtain a copy of it, through the contact channel in section 1. The remaining recipients in the table above — the public DNS resolvers, the regional reference hosts, Microsoft and GitHub — are abroad as well. We pass them nothing and receive nothing back: those connections are opened by your own computer straight to the host, and only when you start the test, the scan or the installation yourself. The geolocation lookup can be switched off entirely in our server configuration, in which case no country data is collected at all. How long any of these services retain their own records is outside our control.

Paddle is our merchant of record and acts as an independent data controller for the details you enter at checkout — your name, email address, billing address and payment method — under its own privacy policy (paddle.com/legal/privacy). Those payment details never reach us. After the purchase Paddle passes us your email address so that we can deliver your key.

9. Legal basis and purpose

Data Purpose Legal basis
Licence key, HWID Performing the contract: delivering the access you bought, enforcing the one-device rule Directly related to the conclusion and performance of a contract (Article 6(1)(b) GDPR · KVKK Art. 5/2-c)
IP address, country, last seen Detecting licence sharing and abuse, service security Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
Hardware summary Resolving your support requests, diagnosing compatibility issues Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
Email address Delivering your licence key to you Performance of the contract (Article 6(1)(b) GDPR · KVKK Art. 5/2-c)
Problem report content and the attached error-log excerpt Resolving the problem you reported to us Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
The connecting IP address of a problem report Preventing abuse of the report form Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
A digest of the licence key or hardware identifier that sent a problem report Enforcing the one-report-per-hour allowance and withdrawing it from a licence that abuses it Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
Accepted agreement version and time Holding evidence that the agreement was accepted Performance of the contract and legitimate interest (Articles 6(1)(b) and 6(1)(f) GDPR · KVKK Art. 5/2-c and 5/2-f)
Device-release history — the licence key and the time of each self-service release of its device binding Enforcing the limit of 2 releases in any 30 days Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)
Free-trial claim record — the public ID of the Discord account and the hardware ID of the device that claimed the one-day trial, and when Granting the trial once per Discord account and once per device — the record is what makes a second claim impossible, so it is kept for as long as the trial offer exists Legitimate interest (Article 6(1)(f) GDPR · KVKK Art. 5/2-f)

Your data is never used for advertising, profiling or sale, and is never shared with any third party for marketing purposes.

10. Retention

Records tied to your licence (key, HWID, IP, country, hardware summary, accepted agreement version, time and text digest, last seen, purchase email, and the payment provider's customer and subscription references) are kept while the licence is live. After it expires, a clean-up job runs on our server every day and deletes the whole record once the licence has been expired for 24 months. You can ask us to delete it sooner. Two cases are handled differently: a record with no expiry date — a lifetime plan, or a key that was never activated — is not covered by that job, and a banned key keeps the ban but has its HWID, IP address, country, hardware summary and payment-provider customer reference erased at the same 24-month point. What stays on a banned record is the key itself, the purchase note that holds your email address, the payment provider's subscription reference, your last-seen timestamp, and the accepted-agreement version, time and text digest. One record deliberately outlives the licence row. Before a licence record is deleted, the fact that its owner accepted an agreement is copied into a separate ledger, because a claim about that acceptance can be brought long after the licence itself has gone. That ledger holds no personal data: the licence key appears only as a one-way digest, next to the agreement version, the digest of its text, and the acceptance time. It identifies nobody on its own — a key has to be presented alongside it before any row in it can be matched to a person — and it is kept for as long as such a claim remains possible.

When you release your key's device binding yourself, the key and the time of the release are recorded so the limit of 2 releases in any 30 days can be counted. Entries older than that 30-day window are deleted the next time the same key's binding is released, and once a licence record itself is deleted, the key's remaining release history is removed by the daily clean-up.

Administrative action logs are automatically deleted after 90 days. Our licence server also prints operational lines to its own console — an activation, a rejected key, a country lookup that returned nothing — and those lines carry your IP address and a shortened form of your licence key. How long they survive is decided by the log-rotation settings of the system we run the server on, not by us.

One more short-lived record exists. When you buy, our server writes two duplicate-payment guard entries that contain your purchase email address, so that two notifications about the same payment cannot issue you two keys. They stop being useful after 30 days and are removed by a clean-up that runs at most once a day, on the next purchase notification the server receives — so on a server taking no further orders they would sit until one arrives.

If you request deletion, your licence record is deleted in full — which also ends your access with that key. Deleting only the IP or hardware summary while keeping the licence active is not currently possible, and we are telling you plainly so your expectations are accurate.

11. Security

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you in the manner and within the period the law requires.

12. Your rights

Under the data-protection law that applies to you — the GDPR in the EU/EEA, the KVKK (Art. 11) in Türkiye, and equivalent laws elsewhere — you have the following rights:

Your right to object

Where we process your data on the basis of our legitimate interest — your IP address, country, last-seen time and hardware summary — you may object at any time on grounds relating to your particular situation (Article 21(1) GDPR). If you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, or the data is needed to establish, exercise or defend legal claims.

The channel for exercising these rights will be published in section 1. Answering your request is free of charge; we may ask for a reasonable fee only where a request is manifestly unfounded or excessive. Your request will be answered within 30 days at the latest. For a request made under the GDPR, where the request is unusually complex we may extend that period by up to two further months and will tell you the reason within the first month (Article 12(3) GDPR); for a request made under the KVKK the period is thirty days in every case and cannot be extended (KVKK Art. 13/2). If we cannot identify you from the request itself, we may ask for the licence key or the purchase email address the record is held under — we do not ask for identity documents. If you are not satisfied with the response, you may complain to your data protection authority — the KVKK Board in Türkiye, or your national supervisory authority in the EU/EEA and elsewhere.

We take no decision about you that produces legal effects, or similarly significant effects, on a solely automated basis. The one-device rule is applied automatically during the licence check, but a refusal only blocks activation on a second machine: you can release the binding yourself on the bound device (Settings → License → "Unbind This Device", at most 2 releases in any 30 days), and where the bound device can no longer do that, an operator can review the case and reset the binding on request through the channel in section 1. The free one-day trial key is the exception: it stays bound to the device that claimed it and is released by neither route, because it expires within a day.

13. Children and age limit

w0a is not directed at children under 16, and we do not knowingly collect data from anyone under 16. The box you tick to accept the agreement in the app carries your declaration that you meet the age terms in clause 2 of that agreement; that declaration is the only age check there is, because we have no way of verifying age and do not attempt one. If we discover data from someone under 16 has been processed, we delete it and cancel the associated licence.

If you are 16-17, you may use w0a with the knowledge and consent of your parent or legal guardian. Purchases, and the data processing tied to them, must be made or approved by your parent or guardian. A parent may always contact us regarding their child's account and data.

14. Changes

If we update this notice we will change the version number and effective date on this page. If we make a material change that expands what we collect, we will notify you inside the app before it takes effect.

Related documents: Terms of Service · Refund Policy · Cookie Policy