Your data, deliberately limited.
Device checks
The browser reads model and bootloader information after you approve USB access. It does not read messages, photos or app data. Model detection is remembered in this tab’s session storage. Reconnection is required before checkout.
Local helper and reports
The helper runs on your computer. Reports and recovery journals stay there. Importing a report displays it locally and does not upload it. The recovery journal contains a hash of the device serial to prevent changes to another phone.
Payment and session records
When paid setup opens, Stripe handles card information. Paranoid stores a random session identifier in a secure, HTTP-only cookie, plus order, entitlement and consent records in Supabase. It does not store card numbers. The session cookie lasts 30 days.
Optional service analytics
Funnel analytics are disabled in this preview. When enabled, they record step names, broad traffic source and model code, not USB serials or report contents. Browser Do Not Track is honoured. Successful payment events come from verified provider webhooks.
Before launch
Retention periods, the business contact and account-recovery process must be published before paid setup opens. This preview does not collect customer payments.