Privacy Policy
Short version: the programs collect nothing and send nothing about you. The website keeps ordinary server logs. Payment processors handle payments. This page spells all of it out. Effective 5 September 2026.
Effective date: 5 September 2026. Data fiduciary: EBITA AI PRIVATE LIMITED (brand EBITA.AI; registration number 103358, Registrar of Companies, Ernakulam), Ernakulam, Kerala, India. This policy applies to winbastion.com (including the feedback form), the WinBastion family of Windows programs and the browser edition of MediaBastion. It replaces the earlier WinBastion-only privacy page.
- 1. Who we are and what this covers
- 2. What we collect
- 3. How we use it
- 4. Who we share it with, and how
- 5. Cookies
- 6. Security
- 7. Retention
- 8. Your rights
- 9. Children
- 10. The DPDP Act, 2023 and the grievance officer
- 11. Users outside India
- 12. Changes to this policy
- 13. Contact
1. Who we are and what this covers
EBITA.AI is a software company based in Ernakulam, Kerala, India. WinBastion is its brand and micro-tech unit. This policy describes what personal data we collect through the website at winbastion.com, through the Windows programs we publish, through the browser edition at winbastion.com/mediabastion/app/, when you send a tip or buy a licence, and when you write to us. Where a program has extra product-specific notes (for example, exactly which folders WinBastion writes to), they are linked from this page: WinBastion data notes, MediaBastion Web notes.
2. What we collect
2.1 The website
The web server records ordinary access logs: your IP address, the browser's user-agent string, the pages and files requested, the referring page if your browser sends one, and the time. These logs are kept for a limited period by our hosting provider for security and troubleshooting (spotting attacks, finding broken links). There is no analytics service, no tag manager, no tracking pixel, no advertising and no cookies. The site is static HTML and CSS; it runs no scripts in your browser other than none at all. Fonts are loaded from Google Fonts, which sees your IP address as part of serving the font files (see section 4).
2.2 The Windows programs
The programs contain no telemetry, no analytics, no crash reporting and no accounts. They do not collect usage statistics, hardware identifiers, file names or anything else, and nothing about you leaves your PC. Everything a program records (its journal of changes with their previous state, alerts, health history, scan caches, settings) is stored on your own PC and is removed when you uninstall. Two optional features do use the network, and both can be turned off:
- Update check. WinBastion asks GitHub's public API for the list of releases and, if you allow automatic updates, downloads the installer from GitHub. GitHub sees the request like any web request, including your IP address. We run no update server and receive nothing.
- Optional model and engine downloads. Features such as background removal or media conversion may offer to download an AI model or an FFmpeg build. Those files come from GitHub and from Hugging Face; the request reveals your IP address to those services. Nothing about you or your files is sent with it. The download is offered, with its size, before it happens.
- Web descriptions (WinBastion). When you expand a service or an app, the dashboard may ask Wikipedia for a one-paragraph summary of that name. The name of the service or app is the only thing sent; results are cached locally for 30 days.
2.3 The browser edition (MediaBastion Web)
The browser edition at winbastion.com/mediabastion/app/ runs entirely inside your browser. Files you add are never uploaded: there is no upload endpoint, and the page's Content-Security-Policy restricts every connection to winbastion.com. The page and its engines are downloaded from our server like any other page, so the server logs described in 2.1 apply. Preferences (light or dark, approved engines) are stored in your browser's local storage, on your device only. Details: MediaBastion Web privacy note.
2.4 Tips and licence purchases
Payments happen on the payment processor's page, never inside our programs or on our server. The processors (Razorpay or Cashfree in India; Ko-fi, which uses PayPal; GitHub Sponsors, which uses Stripe; Stripe where offered) collect your name, email address and payment details under their own privacy policies and are independent data fiduciaries for that data. From them we receive: your name, your email address, the amount, the currency and a transaction id. We never receive card numbers, UPI PINs or bank credentials. If you request a supporter code or a licence file, we email it to the address the processor gave us.
2.5 Support email and the issue tracker
If you write to us, we keep the correspondence: your email address, your name if you give it, and what you wrote, including any screenshots or logs you attach. Issues filed on GitHub are public and governed by GitHub's privacy policy.
2.6 The feedback form (bug reports, feature requests, feedback)
The form at winbastion.com/feedback/ is the one part of the website that stores what you type. When you send a report we store: the kind of report, the application it concerns (and the name of a new application you would like), the title, the description, and the optional bug details (severity, steps to reproduce, expected and actual behaviour, program version, Windows version); your name and email address only if you fill them in, together with whether you allowed us to contact you; your consent; the files you attach (up to 10, 250 MB in total, kept exactly as sent, with a SHA-256 checksum); the time of submission; your browser's user-agent string and the referring page; and a salted one-way hash of your IP address, used only to limit abuse (ten reports per address per hour). The IP address itself is not stored. We also keep the ticket id we give you and the status notes we add while working on the report.
Reports are stored in a database on the same server that serves this website, hosted in the European Union. They are read by the owner only; no third party receives them, no analytics or email service processes them, and nothing is sent anywhere when you submit. Attachments may contain personal data (file names, user names, addresses inside log lines): please check them before attaching; we treat them as confidential and delete them with the report. Retention: until the report is resolved, plus 24 months, so that we can recognise a recurrence; deleted earlier on request, quoting the ticket id. The form sets no cookie.
3. How we use it
- Server logs: to keep the website secure and working, and to fix broken links.
- Payment data: to send the receipt, the supporter code or the licence file; to handle refunds; to keep the accounting and tax records that Indian law requires.
- Support correspondence and feedback-form reports: to answer you, to fix the bug you reported, to decide what to build next, and to remember the context if you write again.
We do not use personal data for advertising, profiling or automated decision-making, we do not build marketing lists, and we do not send newsletters. A “Notify me” email about a future product gets exactly one reply, when that product ships.
4. Who we share it with, and how
We do not sell, rent or trade personal data. It is disclosed only to the following, only as needed, and only in the following ways:
| Recipient | What | How |
|---|---|---|
| Our hosting provider (a virtual server in the EU) | Server access logs; the feedback-form database and its attachments | Stored on the server they host, administered by us; they do not read them for their own purposes. |
| Payment processors (Razorpay, Cashfree, Ko-fi/PayPal, GitHub Sponsors/Stripe, Stripe) | Your payment; they send us name, email, amount, transaction id | You interact with them directly on their page; data flows from them to us over their dashboards and signed webhooks. |
| GitHub | Your IP address and request, when you check for updates, download an installer or engine, or file an issue | Direct request from your PC or browser to GitHub; nothing passes through us. |
| Hugging Face | Your IP address and request, only when you opt in to download an AI model | Direct request from your PC to Hugging Face. |
| Google Fonts | Your IP address and browser details, when a page loads its fonts | Direct request from your browser to Google's font servers. |
| Email provider | Support correspondence, receipts, supporter codes | Ordinary email. |
| Authorities | Whatever a valid legal order requires | Only when legally compelled, and only the minimum required. |
5. Cookies
The website sets no cookies of its own: no session cookie, no analytics cookie, no consent banner because there is nothing to consent to. (The owner's administration page for the feedback form sets a login cookie for the owner only; visitors never see it.) Payment processors set cookies on their own pages under their own policies. The browser edition uses local storage for its preferences, not cookies.
6. Security
The website is served only over HTTPS. The only database of personal data in our systems is the feedback-form store described in 2.6; it lives on our own server, is reachable only from that server, and its administration page is protected by a password known to the owner alone. Everything else is static files, and the programs keep their data on your PC. Payment records live in the processors' systems, protected by them; our copy is the receipts and the accounting records. Access to the server, the email mailbox and the processor dashboards is limited to the owner and protected by keys and two-factor authentication. Journals, settings and every other thing a program records stay on your PC and are yours to delete.
7. Retention
- Server access logs: rotated and deleted by the hosting configuration after a limited period, normally within 30 days.
- Payment records (name, email, amount, transaction id, receipt): kept for as long as Indian tax and accounting law requires, currently eight years from the end of the relevant financial year.
- Support correspondence: kept while the matter is open and for up to two years afterwards, so that we have the context if you write again; deleted earlier on request.
- Feedback-form reports and their attachments: kept until the report is resolved, plus 24 months; deleted earlier on request (quote the ticket id). The salted IP hash is deleted with the report.
- Data on your PC: kept until you uninstall the program or delete it; we never have a copy.
8. Your rights
You have the right to know what personal data we hold about you, to have it corrected if it is wrong, and to have it deleted where we no longer need to keep it by law. To exercise any of these, email mustafa@ebita.ai from the address you used with us (or tell us how to verify that you are the person concerned). We answer within 30 days and normally much sooner. You may also withdraw consent for anything that was based on consent, such as an optional download, simply by turning the option off. If you are unhappy with our answer, you may complain to the Data Protection Board of India (section 10) or to the supervisory authority in your own country.
9. Children
The website, the programs and the payment options are not directed at people under 18. We do not knowingly collect personal data from children. If you believe a child has sent us personal data or a payment, email us and we will delete or refund it.
10. The Digital Personal Data Protection Act, 2023 and the grievance officer
EBITA.AI processes personal data as a data fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made under it. The lawful bases for the processing described here are the performance of what you asked for (delivering software, receipts, codes and support), legal obligations (tax and accounting records), and legitimate uses such as keeping the website secure. Where processing is based on your consent (optional downloads), you can withdraw it at any time.
Grievance officer under the DPDP Act and the Information Technology Act, 2000: Mustafa Saidalavi, EBITA.AI, L.R. Towers, 39/2475-B1, South Janatha Road, Palarivattom, Ernakulam, Kerala 682025, India. Email mustafa@ebita.ai, telephone +91 99463 99946 (Monday to Friday, 10:00–18:00 IST). Grievances are acknowledged within 48 hours and resolved within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.
11. Users outside India
The website and the programs are used worldwide. Personal data we hold (payment records, support email) is processed in India and on our hosting provider's servers in the European Union; payment processors process your data where they operate. If you are in the EU, the UK or another jurisdiction with its own data-protection law, you have at least the rights listed in section 8, and you may contact your local supervisory authority.
12. Changes to this policy
We will update this policy when the programs, the law or our providers change. The current version is always at winbastion.com/privacy.html with its effective date at the top. A material change (for instance, a program starting to send something it did not send before) will also be stated in that program's release notes.
13. Contact
EBITA AI PRIVATE LIMITED (brand EBITA.AI; WinBastion is its micro-tech unit)
Email: mustafa@ebita.ai or hello@winbastion.com
Telephone: +91 99463 99946 (Monday to Friday, 10:00–18:00 IST)
Website: https://winbastion.com
L.R. Towers, 39/2475-B1, South Janatha Road
Palarivattom, Ernakulam
Kerala 682025, India
See also the Terms of Service and the Cancellation and Refund Policy.