GDPR / privacy
Privacy Policy
How we process data on the site, in the Windows/Mobile apps, and on pay.smoothwizard.com - data categories, Footprint/HWID, cookies, and GDPR.
Full policy
How we process data (GDPR)
Last updated: 21 August 2026
We take care of your privacy. This notice fulfils the information duties under Articles 13 and 14 GDPR (Regulation 2016/679) and describes cookies / similar technologies across SmoothWizard services. It reflects actual processing in our products: the marketing site, pay.smoothwizard.com, the Windows desktop application, and SmoothWizard Mobile.
1. Controller
Artur Spychalski, conducting business as SkullMedia Artur Spychalski, entered in the Polish CEIDG register, NIP 5922292367, REGON 524191477.
Privacy contact: [email protected]. No Data Protection Officer (DPO) has been appointed - use the address above for GDPR matters.
2. Scope of services
This policy covers, among others:
- the SmoothWizard marketing site (smoothwizard.com),
- the payments and account service pay.smoothwizard.com (sign-up, login, subscriptions, orders, affiliate program),
- the SmoothWizard Windows application and related license / account APIs,
- the SmoothWizard Mobile app (App Store / Google Play) and the local mobile server in the PC app (phone-PC pairing on the LAN),
- support channels (email, Discord) when you send us data in correspondence.
3. Categories of data
Depending on what you use, we may process among others:
- Account / identity: email, display name, avatar, external account IDs (Google, Discord, Steam, Twitch), hashed password (for email/password accounts),
- Transactional data: order and subscription history, amounts, currency, payment status, operator transaction IDs (Stripe; other PSPs when enabled), billing data as required by law,
- Affiliate data: partner code, sale attribution, commission balance, payout requests, phone (BLIK), IBAN / transfer details,
- Technical / security: IP address, access and security logs, session IDs, browser / device type, timestamps,
- App / license data: device identifiers used for Footprint / license binding (including HWID or an equivalent hardware fingerprint), plan status (Basic / Pro / trial), activation and license-verification logs via API,
- Mobile / LAN data: when using SmoothWizard Mobile - data needed to discover the PC on the local network, pairing (PIN), optimization control and usage view; phone-PC traffic usually stays on the LAN (not a cloud remote panel),
- Support communications: email / Discord message content (including screenshots and Discord user IDs) when you contact support,
- Cookies / local storage: e.g. login session, currency preference, partner code - see Cookies below.
We do not store full payment card numbers in SmoothWizard databases - card vaulting is handled by the payment provider.
4. Purposes and legal bases
Purposes include:
- registration, login, and account maintenance,
- license activation, verification, and abuse prevention (API, Footprint / HWID),
- fulfilling Pro orders and subscriptions (one-shot and auto-renew),
- affiliate program operations (codes, attribution, commission payouts, converting balance to a one-shot checkout discount),
- support and complaints,
- newsletter / marketing - where you consent,
- security, abuse prevention, establishing or defending claims,
- legal obligations (accounting, tax).
Bases (GDPR Art. 6):
- (b) contract or pre-contract steps (account, license, order, affiliate),
- (c) legal obligation (e.g. accounting, tax),
- (a) consent (e.g. newsletter, some non-essential cookies),
- (f) legitimate interests (security, license-fraud prevention, service improvement, claims) - balanced against your rights. For (f) you may object (Art. 21 GDPR).
5. Application, Footprint and license API
The SmoothWizard application and license backend may process device identifiers (including HWID / Footprint) in order to:
- bind Pro / trial licenses to a device,
- limit device-limit circumvention and trial abuse,
- verify entitlements on API calls (e.g. login + HWID).
Footprint is for licensing and security, not behavioural marketing profiling. License terms: Application License Agreement. Account, payments, and marketing communications are covered by this policy.
5A. Mobile app (SmoothWizard Mobile)
SmoothWizard Mobile (iOS / Android) connects to the PC app on the local network (Wi-Fi / LAN) using a PIN. In that scope we may process among others LAN device identifiers, connection status, control commands (optimization, usage view, shutdown / restart / lock), and the PIN on the PC side. The purpose is remote control of the PC on the same network - not marketing. App stores (Apple / Google) may process data independently as controllers under their own policies.
6. Login via external platforms
You may sign up / sign in via identity providers (including Google, Discord, Steam, Twitch - as enabled at the time). This is also an Art. 14 GDPR case (data from a source other than an email form).
Scope (examples):
- Google: email and basic profile (e.g. name, avatar) per OAuth scopes,
- Discord: user ID, username, email (when shared),
- Twitch: user ID, login / display name, avatar, and verified email (scope
user:read:email/ OIDCemailclaim;emailfield on Helix Get Users), - Steam: profile identifiers needed to link the account - Steam does not provide an email (sign-in only after account linking).
We use this data for identification, secure login, license linking, and account personalization. We do not sell it. Google API data is used under the Google API Services User Data Policy (including Limited Use). Profile data is not used to train AI/ML models.
7. Payments
Payments are handled by external providers. Card numbers are not stored in SmoothWizard databases - card vaulting is done by the provider (e.g. Stripe). For payments via the operator (Stripe) we process transaction data needed to fulfill the order and accounting. Data for other PSPs - when that gateway is enabled in the Store.
Providers may act as independent controllers or processors under their own terms and privacy policies. Checkout and account: pay.smoothwizard.com; store rules: Store Terms.
8. Affiliate program
If you join the affiliate program, we process partner account data, codes, sale attribution, commission balances, and payout details (e.g. BLIK phone, IBAN). Buyer emails in the partner panel may be masked (buyer privacy). See the Partnership Program Regulations.
9. Cookies and similar technologies
We use cookies / local storage for sessions, security, preferences and - after consent - analytics / ads. Examples actually used (as of the update date):
- session / auth (necessary) - keeping you signed in on pay.smoothwizard.com (Better Auth / session cookies),
- sw_currency - currency preference (up to about 12 months),
- sw_partner_code - partner code for sale attribution (about 30 days) after visiting /r/…,
- sw_promo_code - promo landing attribution (about 30 days),
- sw_acq - first-touch traffic source (Facebook / TikTok / organic, about 30 days). The attribution cookie may use Domain=.smoothwizard.com; that is not marketing consent,
- sw_ttclid - TikTok Ads click id on Pay (host-only, about 30 days) to attribute a subscription purchase,
- sw_pay_cookies_ack / sw_pay_marketing - Pay consent choice (about 12 months),
- OAuth / 2FA state cookies (short-lived, necessary for login).
On the marketing site, WordPress / plugin session cookies may run and - when enabled and after CMP consent - analytics (e.g. Google Analytics) or marketing tools (TikTok Pixel: analytics.tiktok.com). Necessary cookies may rely on legitimate interest or service necessity; others (analytics / marketing) on consent (CMP / banner).
Consent given on the marketing site applies to that host (consent cookies are host-scoped, without a shared .smoothwizard.com domain). It does not automatically carry over to pay.smoothwizard.com. When the TikTok Pixel is configured on Pay, the Pay cookie banner shows “Necessary only” / “Accept all”. The pixel and events (PageView, ViewContent, InitiateCheckout, CompletePayment) load only after marketing consent on Pay. Pay may also send a CompletePayment event to the TikTok Events API (server-side, recipient: TikTok) on the first paid Stripe or PayPal subscription, including the ttclid click id when stored - only if you gave marketing consent on Pay (sw_pay_marketing cookie). If you choose "Necessary only", the Events API is not called. The event does not cover subscription renewals or Cashbill / prepaid payments.
You can manage cookies in your browser; blocking some may limit features (e.g. login, remembered currency, partner or ads attribution).
10. Recipients, processors and transfers outside the EEA
Recipients / categories:
- identity providers (Google, Discord, Steam, Twitch - when used),
- payment operators (including Stripe and PayPal; other PSPs when enabled),
- email delivery (e.g. AWS SES),
- hosting / IT infrastructure (including cloud services),
- accounting / advisors - as needed,
- TikTok (Pixel on Pay and on the marketing site after CMP consent; Events API on the first paid Stripe / PayPal subscription, only after Pay marketing consent),
- other analytics / cookies tools - when enabled and based on consent or legitimate interest.
Where providers act as processors, we enter into data processing agreements (GDPR Art. 28), unless they act as independent controllers.
Data may be transferred outside the European Economic Area (EEA), in particular to the USA (e.g. Google, Stripe, AWS, TikTok), where an appropriate mechanism applies: an adequacy decision, Standard Contractual Clauses (SCCs), or another GDPR-compliant basis.
11. Retention
We apply among others the following frames (or shorter if the purpose ends earlier):
- user account - for as long as you keep the account; after account deletion we retain selected transactional data and logs (not the full account) until claim limitation periods expire (usually up to about 6 years), unless law requires longer,
- accounting / tax order data - typically 5 years (accounting / tax rules),
- license / Footprint / HWID data - for the life of Pro / trial entitlements and abuse-claim periods,
- security logs - typically 12-24 months (risk / industry practice),
- sw_partner_code - about 30 days,
- sw_currency - up to about 12 months,
- consent-based data (e.g. newsletter) - until consent is withdrawn; withdrawal does not affect prior lawfulness,
- support correspondence - for the life of the ticket and claim limitation periods.
12. Profiling and automated decisions
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). Automatic rules (e.g. license checks, device limits, fraud detection) support security and contract performance - they are not behavioural marketing profiling.
13. Minors
SmoothWizard services (including Pay and the affiliate program) are aimed at adults or lawfully operating businesses. We do not knowingly collect data from children under 16. If you believe a child provided data, email [email protected] - we will delete it unless law requires otherwise.
14. Support (email / Discord)
When you write to [email protected] or on Discord, we process the ticket content, your identifier (email / Discord ID / nick), and attachments (e.g. screenshots). Basis: (b) (contract support) or (f) (handling enquiries). We do not publish your tickets publicly without need.
14A. Whether providing data is required
Providing data needed to create an Account (including email), sign in, and complete payment / Pro licensing is a contractual requirement (Article 13(2)(e) GDPR). Without it we cannot create an Account, sell / activate SmoothWizard Pro, or provide features that require sign-in. Payment details are usually collected directly by the payment operator (e.g. Stripe, PayPal) - without providing them to the operator, payment will not complete.
Marketing cookies and similar technologies rely on your consent - withholding them does not block the Account or purchase, but may limit ad personalisation. Sign-in via external platforms (Google, Discord, Steam, Twitch) is a voluntary alternative to email; without linking an external account those sign-in paths are unavailable.
15. Your rights
You may request access, rectification, erasure, restriction, portability, and object (including to marketing based on (f)). Where processing is based on consent, you may withdraw it.
To exercise rights, email [email protected]. You may also lodge a complaint with the Polish Data Protection Authority (UODO), Stawki 2, 00-193 Warsaw, uodo.gov.pl.
16. Security
We apply organizational and technical measures appropriate to risk (including HTTPS/TLS, OAuth, password hashing, access controls, admin 2FA).
17. Changes
We may update this policy when law or our services change (including pay.smoothwizard.com and the application). The current version is published on this page with the last-update date.

Privacy questions?
Write to [email protected]. The current policy always lives on this page.
GDPR contact
