Privacy Notice

Effective 27 September 2026 · Version 2026-09-27

This notice explains what personal data Wharfsync uses and why. It covers the Wharfsync editor extension, the licence service and this website.

Who we are

The controller is Nikah AI Ltd, trading as Wharfsync, a company registered in England and Wales (company no. 17199968), registered office Office 1216, 60 Tottenham Court Road, London W1T 2EW. We are registered with the Information Commissioner's Office under registration number ZC176381. For anything about your data, email privacy@wharfsync.com. For anything else, email support@wharfsync.com.

The short version

  • The extension runs on your computer. Your files, server addresses, usernames and passwords go only from your computer to your own servers. We never receive them.
  • There is no telemetry, no analytics and no tracking in the extension or on this website. This website sets no cookies.
  • If you subscribe, Stripe handles the payment. We keep only a random licence ID linked to your Stripe customer and subscription IDs, and the subscription's status and dates. We do not store your name, email address or card details in our own systems.
  • Once a day the extension sends your licence key, and nothing else, to our licence server to renew it. You can turn that off.

What the extension keeps on your computer

This data stays on your device. We cannot see it.

  • Server passwords and key passphrases, only if you choose to save them or move them out of sftp.json. They are kept in your operating system's keychain through your editor's secret storage (Windows Credential Manager, macOS Keychain, or the Secret Service / keyring on Linux).
  • Your licence key, in the same keychain.
  • Pinned host keys and certificates: the host name, port and fingerprint of servers you have chosen to trust, and the servers for which you accepted the plain-FTP warning.
  • Licence housekeeping: when the licence was last renewed and, if our server said a subscription has ended, that licence's random ID.
  • Sync records: for files Wharfsync has transferred, the remote path, size and modification times, so it can warn you about conflicts. Stored in your editor's workspace storage.
  • Backups (Pro): copies of remote files taken just before Wharfsync overwrites them, in the .wharfsync/backups folder of your project. Day folders older than 7 days (you can choose 1 to 90) are deleted automatically when the editor starts and once a day while it runs.
  • Temporary copies of remote files you open from the remote explorer (Pro), in your editor's storage for Wharfsync. Copies not modified for 7 days are deleted automatically when the editor starts and once a day while it runs.
  • The Wharfsync output log, kept by your editor. Passwords, passphrases and licence keys are removed from every line before it is written.

What reaches us, and why

Licence renewal (subscribers)

About once a day, if automatic renewal is on (it is by default), the extension sends your licence key to our licence server. The key contains a random licence ID, the products and plan it covers, and its issue and expiry dates. It contains no name, email address or other identifying details. Our server replies with a renewed key, or says the subscription has ended. The Manage or cancel subscription command sends the same key to open your Stripe customer portal.

  • Lawful basis: performance of our contract with you (UK GDPR Article 6(1)(b)).
  • You can turn automatic renewal off with the wharfsync.licence.autoRefresh setting. Your key then keeps working until its expiry date.

Buying a subscription

You enter your email address, name, card details and billing address on Stripe's checkout page, not on ours. Stripe processes the payment. From Stripe we receive and store: your Stripe customer ID, subscription ID, the plan, the subscription status and its current period end. Through our Stripe account we can also see the details you gave Stripe (such as your email address, billing country and invoices), and we look at them only when we need to, for example to answer a support request or a dispute.

  • Lawful bases: performance of our contract with you (Article 6(1)(b)); legal obligations to keep accounting records (Article 6(1)(c)); and our legitimate interest in preventing fraud and handling payment disputes (Article 6(1)(f)).
  • Where the checkout page shows the purchase is sold through Stripe's merchant-of-record service (Onelink in the UK), that service is the seller of the payment and is an independent controller of the data it collects for it, under its own privacy policy.

Retrieving a lost licence key

On the Retrieve my licence page you enter your email address and a receipt number, invoice number or checkout reference. We use them once to find the matching record in Stripe and show your key. We do not store what you type, with one exception: invoice numbers are sequential, so to stop someone guessing their way into another person's licence, when a receipt or invoice number does not match we keep a keyed one-way hash of the email address, in memory only, for 24 hours, and allow three such misses per address.

  • Lawful basis: performance of our contract with you (Article 6(1)(b)); for the limit on misses, our legitimate interest in keeping licences and customer accounts secure (Article 6(1)(f)).

Your IP address

Any server has to see your IP address to reply to you. Our licence service holds it in memory only, for up to 15 minutes, to limit abuse such as repeated guesses on the recovery page. It is never written to a log file or database. The web server in front of the licence service is configured not to keep access logs. Our operational logs record events such as "webhook received" and error messages, without names, email addresses, IP addresses or licence keys.

  • Lawful basis: our legitimate interest in keeping the service secure and available (Article 6(1)(f)).

Emails you send us

If you email privacy@wharfsync.com or support@wharfsync.com, we use your email address and message to reply.

  • Lawful basis: performance of our contract with you, or our legitimate interest in answering enquiries (Article 6(1)(b) and (f)).

Who we share data with

  • Stripe (Stripe Payments UK Ltd and Stripe, Inc.) processes payments. Stripe acts as our processor for some purposes and as an independent controller for others, such as fraud prevention and meeting its own legal obligations. See stripe.com/privacy.
  • OVHcloud hosts our licence server in a data centre in London, UK.
  • Our email providers carry and store emails you send us.
  • Microsoft (Visual Studio Marketplace) and the Eclipse Foundation (Open VSX) distribute the extension under their own privacy policies. We receive only totals such as install counts, and any public reviews you choose to post. Your editor may send its own telemetry to its vendor according to the editor's settings; Wharfsync adds none.

We do not sell your data and we do not use it for advertising.

International transfers

Our licence server is in the UK. Stripe may process payment data in the United States and other countries. Stripe relies on the UK Extension to the EU-US Data Privacy Framework and on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. If any of our email providers stores messages outside the UK, we rely on UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.

How long we keep data

DataHow long
Licence record (licence ID, plan, Stripe customer and subscription IDs, status, dates)While the subscription runs, then deleted automatically 12 months after it ends
Stripe webhook event IDs (to avoid processing an event twice)30 days, then deleted automatically
IP addresses for rate limitingUp to 15 minutes, in memory only
Keyed hash of an email address after a receipt/invoice number did not match24 hours, in memory only
Payment records held by StripeAs set out in Stripe's privacy policy
Our accounting records6 years from the end of the financial year they relate to, as UK law requires
Support emails24 months after the conversation ends
Data the extension keeps on your computerUntil you delete it (backups and temporary copies: 7 days by default)

Your rights

You have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to our use of it, and to data portability. Email privacy@wharfsync.com and we will reply within one month. To delete everything the extension keeps on your computer, uninstall it and delete your project's .wharfsync folder; saved passwords can be removed with the Wharfsync: Remove saved passwords from keychain command.

We do not make decisions about you by automated means that have legal or similarly significant effects.

Complaints

If you are unhappy with how we use your data, please tell us first. You also have the right to complain to the Information Commissioner's Office: ico.org.uk, telephone 0303 123 1113.

Children

Wharfsync subscriptions are for adults. We do not knowingly collect data from children.

Changes

We will post any change to this notice here, with a new effective date.