Privacy Policy
Last Updated: September 4, 2026Data Controller: Kadmium (Emil Fredrik Sjöstedt, Enskild firma, Sweden)
Kadmium ("we", "our", or "us") respects your privacy and is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This Privacy Policy explains how we collect, use, and handle data across our website (https://www.kadmium.dev), products, developer tools, and video games.
1. Information We Collect
Purchases & Order Fulfillment (Gumroad & Epic Games / Fab):
Financial transactions on our direct storefront are managed exclusively by our Merchant of Record, Gumroad, Inc., or respective third-party marketplaces (e.g., Epic Games / Fab).
We do not process, receive, or store credit card numbers, bank credentials, or sensitive billing details.
We receive order confirmation metadata from Gumroad (such as your name, email address, country, purchased products, and order ID) strictly to issue license keys, verify customer entitlements, and provide technical support.
License Key Activation & Technical Verification:
For compiled tools, launchers, or applications requiring activation, our systems or Gumroad's API may verify license keys, basic system handshakes, or hashed machine identifiers strictly to authenticate your license and prevent unauthorized distribution.
Customer Inquiries & Bug Reports (Email):
When submitting bug reports, feature feedback, or licensing requests via our official email addresses (e.g., support@kadmium.dev), we collect your email address, provided name, and the technical logs or content included in your message.
In-Game Diagnostics & Tool Analytics:
Our games, launcher, and compiled applications may collect aggregated, non-identifiable telemetry and crash data (e.g., framerates, crash traces, engine events, OS build, graphics hardware). We do not collect Personally Identifiable Information (PII) such as personal names, home addresses, or private file paths through these diagnostics.
2. Legal Basis for Processing (GDPR)
Contract Performance (Art. 6(1)(b) GDPR): To fulfill digital orders, issue download links, validate license keys, and provide customer and technical support.
Legitimate Interests (Art. 6(1)(f) GDPR): To inspect anonymous crash logs, resolve engine bugs, prevent software piracy, and maintain the performance and security of our software ecosystem.
Legal Obligation (Art. 6(1)(c) GDPR): To maintain invoice receipts and transaction records as required by Swedish statutory accounting and tax regulations (Bokföringslagen).
3. Third-Party Services & Sub-Processors
Gumroad, Inc.: Authorized Merchant of Record handling billing, VAT/tax compliance, fraud screening, and digital product delivery.
Google LLC (Google Workspace, Google Sites, Google Analytics): Infrastructure for professional domain email, web hosting, and aggregated analytics telemetry.
Epic Games / Fab: Third-party marketplace operator for Unreal Engine assets and plugins (governed independently by Epic Games’ privacy terms).
4. Data Storage & Retention
Support Communications: Retained in our secure Google Workspace email repository only as long as necessary to address your technical inquiry and maintain service history.
License & Transaction Metadata: Retained for the active lifecycle of your software license to facilitate key recovery, or for up to 7 years in compliance with Swedish accounting legislation.
Diagnostics & Crash Logs: Anonymized metrics are automatically purged or aggregated according to standard operational retention schedules.
5. Your Rights Under GDPR
If you are a resident of the European Union (EU) or European Economic Area (EEA), you possess the following statutory rights under the GDPR:
The right to request access to the personal information we hold about you.
The right to request rectification of inaccurate personal details or erasure of your customer support records.
The right to restrict or object to the processing of your data.
The right to data portability.
The right to lodge a complaint with a supervisory authority, specifically the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY, https://www.imy.se).
Please note: Because crash dumps and technical telemetry are entirely anonymized and cannot be tied back to an individual user, we cannot isolate, extract, or delete telemetry on a per-user basis.
6. Contact & Data Requests
To exercise your GDPR rights or ask questions regarding this Privacy Policy, contact our Data Controller directly:
Data Protection & Legal Inquiries: legal@kadmium.dev
General Technical Support: support@kadmium.dev
Direct Contact: Emil Fredrik Sjöstedt, emil@kadmium.dev