Hellcat Music Group
Privacy Policy
This policy explains what information is processed when you visit our site, contact us, purchase or donate through an external provider, use Hellcat license services, or submit and manage a bug report.
Effective July 25, 20261. Who we are
Hellcat Music Group operates this website and its associated software-license services. Questions or privacy requests can be sent to contact@hellcatmusicgroup.com.
2. Information we process
General website use
We do not use advertising or audience-analytics cookies. Like most hosted websites, our hosting provider (IONOS) creates security and access logs containing an IP address, requested URL, date and time, browser or device information, referral information, and server-response details. These temporary logs are used exclusively to maintain server security, performance, and stability.
Third-Party Content Delivery (Fonts & Scripts)
To ensure fast load times and consistent visual layout, our website loads typography assets directly from the Google Fonts API. When your browser requests these fonts, Google receives technical network information, including your IP address and user-agent string. This transaction is a necessary technical requirement to deliver the assets and is governed by Google’s privacy practices.
Messages and contact
If you contact us by email, we process the email address, message, attachments, and other information you choose to provide so we can respond and maintain appropriate business records.
Software licenses
When a license is issued or used, we may process the purchase email, product, license status, a keyed hash and partial hint of the license key, a hashed machine identifier, an optional machine name, activation and validation timestamps, download and verification records, and troubleshooting events. We also use a short-lived, one-way hash derived from the requesting IP address to prevent abuse. Raw license keys are encrypted only while needed for secure delivery or recovery and are not used as ordinary database identifiers.
Bug-report accounts and submissions
Access to bug-report submission and editing is limited to email addresses connected to an active Hellcat license. We store a one-way hash of the license email, a securely hashed account password, an optional display name and selected profile icon, short-lived one-way hashes for single-use password setup or reset links, notification preferences, and secure session data. We never store the account password in readable form. Signed-in users can update their display name, profile icon, qualifying license email, and password in account settings.
A submitted report may contain its title, description, product and version, selected operating system, status, timestamps, screenshot, and MP4 attachment. Those report contents and attachments are public. The account email, private administrator notes, and optional device details are not displayed publicly.
If you affirmatively select “Include device details,” the report may include browser and operating-system identifiers, language, CPU thread count, approximate memory where available, screen dimensions, pixel ratio, and time zone. This collection is optional and is used only to reproduce and diagnose the reported issue.
We create in-site notifications when a report status changes. Status-change email is enabled by default for a bug-report account and can be disabled at any time in that account’s preferences.
Visitors may continue as a guest to browse and filter public reports without creating an account. A guest session does not permit report submission, account editing, or notifications and ends when the visitor signs out or the browser session expires.
3. Cookies and local browser storage
We use only storage necessary to provide security and requested functionality. We currently do not place advertising, cross-site tracking, or analytics cookies.
| Name | Type | Purpose | Typical duration |
|---|---|---|---|
hmg_storage_notice | First-party cookie | Remembers that this browser-storage notice was acknowledged. | 180 days |
PHPSESSID | Strict, secure, HttpOnly session cookie | Protects license administration, bug-report account sign-in, report ownership, form security, and notification preferences. It is not used for visitor tracking. | Browser session |
hellcat-license-recovery-v1 | Local storage | After a verification-code request, remembers the email, selected product, and request time so mobile refreshes do not hide the code-entry screen. It never stores the code, license key, or license-file contents. | 10 minutes, or until successful recovery/deactivation |
You can delete these items through your browser settings. Choosing “Dismiss once” on our notice does not create the acknowledgement cookie, so the notice may appear again. Blocking necessary storage may prevent session or recovery features from working as expected.
4. Bug-report terms
Only submit content that you are permitted to share publicly. Remove license keys, passwords, private messages, personal data, confidential project material, and third-party content that you do not have permission to publish. Screenshots and MP4 files are provided to help reproduce software defects and must not be used to distribute malware, unlawful material, harassment, advertising, or unrelated content.
You retain ownership of your submission and grant Hellcat Music Group a non-exclusive license to host, display, copy, reproduce, diagnose, and use it as reasonably necessary to investigate, document, and resolve the report. You may edit or delete your own report while its status is Open or Investigating. Reports are locked against owner edits and deletion when marked Fixed or Closed. Administrators may edit status and report contents, remove unsafe or irrelevant attachments, close reports, or remove content needed to protect the service or comply with law.
Public visibility does not guarantee a response, fix, release date, or continued hosting. Report status is informational and may change as an investigation develops.
5. Purchases, Stripe, and donations
VST purchases redirect you to Stripe Checkout, and donation links redirect you to Buy Me a Coffee. These are separate services. Their cookies, fraud-prevention tools, payment processing, and privacy practices begin when you visit or interact with their sites and are governed by their own policies.
Payment providers process payment-card, billing, contact, device, and transaction information. Hellcat Music Group receives confirmation of payment, customer contact details, purchased product, donation information, and transaction identifiers needed to fulfill the purchase, provide support, prevent fraud, and maintain records. We do not receive or store your complete payment-card number.
See Stripe's privacy policy and Buy Me a Coffee's privacy policy for details.
6. How information is used
- Deliver downloads, licenses, verification codes, updates, and customer support.
- Activate, validate, deactivate, recover, revoke, or troubleshoot licenses.
- Complete purchases and donations and maintain appropriate transaction records.
- Secure the website, prevent automated abuse, investigate errors, and enforce license limits.
- Publish, reproduce, investigate, manage, and respond to software bug reports and their attachments.
- Authenticate bug-report account owners and deliver requested password setup, reset, and status notifications.
- Comply with legal obligations and protect our users, services, and rights.
7. Sharing and service providers
We do not sell personal information. Information may be processed by providers that help us operate the service, such as IONOS hosting and email infrastructure, Stripe for checkout and payments, and Buy Me a Coffee for donations. We may also disclose information when required by law or reasonably necessary to prevent fraud, abuse, or harm. Links to Instagram, SoundCloud, Google, GitHub, Stripe, Buy Me a Coffee, and other external services are governed by those services once opened.
8. Retention
-
Server Access Logs: Technical security and access logs containing raw IP addresses are held temporarily by our hosting provider and are automatically limited or cleared down after 30 days.
-
Browser recovery state expires after approximately ten minutes.
-
Verification codes expire after ten minutes and are scheduled for cleanup after use or expiration.
-
License download links normally expire after seven days. An encrypted recovery copy may be retained until an unactivated license is first activated.
-
License and activation records are retained while needed to provide and enforce the license. A revoked license can be permanently deleted by an administrator.
-
Rate-limit and troubleshooting records are automatically limited or cleaned up according to service settings.
-
Payment, support, email, and hosting records are retained only as reasonably needed for operations, disputes, security, accounting, or legal obligations.
Bug-report accounts are retained while needed to let licensed users manage submissions. Single-use password links expire after 30 minutes and are invalidated when used or replaced.
Bug reports, public attachments, private device details, and notifications are retained while the report remains published or is needed for investigation. A signed-in owner can delete an Open or Investigating report and its stored attachments; Fixed and Closed reports are locked. Operational backups may persist for a limited recovery period.
9. Security and your choices
We use HTTPS, restricted administration, hashed identifiers, signed license responses, encrypted temporary license delivery, rate limiting, and limited retention to reduce risk. No online service can guarantee absolute security. Regardless of your geographic location, we extend the right to request access, correction, deletion, or restriction of the personal data we hold to all of our users. Contact us using the email address above if you wish to submit a privacy request. We may need to verify your identity before completing a request.
10. Changes to this policy
We may update this policy when our website, license system, payment providers, or legal obligations change. The effective date at the top identifies the current version.