Qodium

Privacy Policy

How Qodium handles personal data and information stored in your browser.

Last updated: September 13, 2026

Data controller

Roselabs SAS, 230 route des Dolines, 06560 Valbonne, France, is the data controller for Qodium. Privacy requests can be sent to contact@roselabs.co.

Data we process

  • Accounts: name or username, email address, password hash, verification status, connected provider identifiers, and account timestamps.
  • Sessions and security: session identifiers, expiry dates, IP address, user agent, and technical logs needed to authenticate users and protect the service. Rate-limit counters use a hashed technical identifier and an expiring window; these identifiers are not treated as anonymous data.
  • Contact requests: name, email address and message content submitted through the contact form.
  • Audience measurement, when enabled: a random session identifier, page URL without query strings or fragments, referrer origin, timestamp, screen and viewport sizes, pixel ratio, and an optional campaign identifier. Account and authentication pages are excluded from this measurement.

Tool inputs and uploaded files

Most Qodium tools run locally in your browser. Their text, data, and uploaded files are not sent to Qodium servers. PNG-to-ICO conversion also runs entirely in your browser. The exception is URL Checker, which sends the URL to the server so it can contact the requested destination. These inputs are not intentionally retained.

QR generation, image reading and palette analysis are local. The QR reader requests camera access only after you choose Start camera, does not request audio, and stops the camera after a match, cancellation, leaving the page or a 60-second scanning session. Images and camera frames are not uploaded or retained by Qodium.

When you explicitly request a password breach check, Password Security sends the first five characters of its SHA-1 hash directly to Have I Been Pwned. The complete password and hash stay in your browser. The provider also receives ordinary connection data such as your IP address. No lookup is performed while you type.

Device Information reads browser-reported capabilities locally. Only when you click its public IP lookup button does it contact ipify, which receives your IP address and ordinary connection metadata. No automatic IP lookup runs on page load, and Qodium does not store the result.

Purposes and legal bases

  • Providing accounts, authentication, and requested tools: performance of the service.
  • Protecting Qodium, preventing abuse, and maintaining technical logs: our legitimate interest in operating a secure service.
  • Responding to contact requests: our legitimate interest in answering users and managing support.
  • Measuring service usage and improving navigation: our legitimate interest in improving Qodium, subject to applicable rules for browser storage.

Audience measurement

Qodium uses Qive for audience measurement. When measurement is enabled, audience events are sent to Qive. A random identifier is stored in your browser to link page views within a navigation history and expires after no more than 13 months. It is not used by Qodium for advertising. You can disable this measurement at any time below; doing so also removes the local audience identifier.

Cookies and browser storage

  • Authentication cookies keep signed-in users connected and secure their sessions.
  • The theme cookie remembers the light or dark appearance for up to one year.
  • Local storage holds the audience preference and, when measurement is enabled, its random session identifier.
  • Session storage may temporarily retain palette data until the browser tab is closed.

Recipients and service providers

Data is accessible only to Roselabs SAS and providers that need it to operate Qodium: Scaleway for hosting, Brevo for transactional email, and Qive for audience measurement. Google or GitHub receives the data needed for authentication when you choose social sign-in. The URL Checker also sends the URL you provide to its destination host. Have I Been Pwned receives the limited hash prefix described above for password breach checks; ipify receives connection metadata only when you request your public IP. Package attributions are static links: displaying them does not contact the npm registry.

Retention

  • Account data is retained while the account remains active and is deleted on request.
  • Session and verification data is retained until it expires or is no longer needed.
  • Contact messages are retained for the request's handling and up to 13 months after the last exchange.
  • Transactional email records are retained for up to 13 months after sending. This does not extend the validity of verification or password-reset links.
  • Technical logs are retained for up to 13 months after collection.
  • Audience statistics are retained for up to 13 months after collection. The local audience identifier expires after no more than 13 months from its creation and is removed sooner when you opt out or clear browser storage.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your data, and object to processing based on legitimate interests. You may also delete your Qodium account from its settings.

Account deletion removes the account, its sign-in methods and sessions. It does not erase files on your device or browser-stored preferences and palette data. Contact requests and technical records are handled separately under the retention rules above; contact us to exercise your rights concerning those records.

To exercise your rights, email contact@roselabs.co. You may also lodge a complaint with the CNIL.

Policy changes

This policy may be updated as Qodium evolves. The current revision date is displayed at the top of this page.