Privacy Policy
Last updated: August 2026
Legal identity of the controller
The controller is Barış TOKAŞ, at Hafiziye Mah. Kurdoğlu Sok. İpekyolu/Van, tax ID 16820263648, telephone +905446260748. MihraSoft is the trade name/brand used by that seller for MihraOps. Privacy requests may be sent to destek@mihrasoft.com.
Scope and who we are
This policy explains how MihraSoft ("we") processes personal information through the MihraOps desktop app, the MihraOps website, license services and support channels. MihraSoft is responsible for the processing described here. You can contact us at destek@mihrasoft.com.
License, purchase and device data
To sell, activate and maintain Pro licenses, we process the customer name and email supplied by the payment provider; order, product, variant, license and refund identifiers and status; purchase and, where applicable, license-expiry dates; the accepted contract version and hash recorded at checkout; the license key in encrypted and hashed forms; and device activations. Device data includes separate one-way hashes of the operating system’s stable machine identifier and the app-generated installation identifier, device label, operating system, app version, activation status and last-seen time. Raw machine and installation identifiers never leave the device. We use this information to perform the contract, enforce device limits, handle refunds, prevent abuse and provide support.
Server credentials and infrastructure data
SSH private keys and passphrases remain on your computer and are not sent to MihraSoft. The app connects directly from your computer to servers you choose. If you ask MihraOps to remember a Git or Docker registry credential, it is sent over that SSH connection and stored encrypted on the server you control; it is not routed through or stored by our license backend. Commands, logs, source code, container data and environment values exchanged with your server likewise do not pass through our backend. Local MihraOps records are protected with the operating system secure-storage facility when available.
Agent monitoring, recipients and SMTP
If you enable monitoring and email notifications, host/Docker samples, threshold state, incident history and delivery records stay in bounded files under `/opt/mihraops/agent/data` on the server you control; they are not uploaded to the MihraSoft backend. The SMTP host, sender and recipients are stored in Agent settings, while the SMTP password is kept in a separate encrypted secret file using a separate master key. The password does not return to the renderer. When the Agent sends mail, your SMTP provider processes sender, recipient, message content, time and connection data under its own terms and privacy policy.
Anonymous usage tally
To ask whether an update exists, the desktop app fetches the release manifest from our server; that request already shows the app is installed and running. Whether the app is being used is inferred from nothing else: we do not have the app send a separate signal, and it sends no installation id, device id, account or licence data. All that is written to the database is a per-day tally: “N installations ran on day D on platform P”. There is no per-installation record, so the data is anonymous rather than pseudonymous and cannot be linked to a person. Repeat checks on the same day are folded together in memory only, using the IP address; that address is not written to the database and is not stored alongside the tally. No server/IP/domain, SSH data, container, email, license key, file, command, error content or machine identifier appears anywhere in this flow.
Website, updates and support
When you use the contact form, we process your name, email address, message category, message, language and submission time so we can respond. Update checks process the app platform, channel and version information needed to return release metadata. IP addresses may be used temporarily for rate limiting and may appear in security or hosting logs. We do not use the desktop app for behavioural advertising and do not sell personal information.
Service security, request and error records
To operate the MihraOps website and licensing backend, diagnose failures and protect the service, we keep limited operational records for requests reaching the backend, including time, level, request route and method, status code, response duration, request ID, client IP address and User-Agent, in a centrally managed log service that we operate. For errors, the backend component, error type and technical stack trace may also be recorded. IP and User-Agent data is used for security review, abuse investigation and client compatibility diagnostics. The sender does not send query parameters, object bodies, cookies, authorization headers, license keys, email addresses, SSH data, renderer state or managed-server contents to the central request record. MihraOps records are kept in a database separate from our other products, and a log-service failure does not stop the primary service.
Payments and service providers
Purchases are processed by the payment provider shown at checkout under its stated role and privacy terms; MihraSoft does not receive complete card details. We receive the limited customer and transaction data needed to issue and administer a license. Hosting, database and support-email providers may process limited data on our behalf to operate the service. An SMTP provider you choose for Agent notifications is not MihraSoft’s subprocessor; you configure it and its own terms apply. Microsoft separately processes Store acquisition and diagnostic data under its own terms. We may also disclose information when required by law, to protect users and the service, or in connection with a lawful business transfer.
Legal grounds
Depending on where you live, we process data to perform our contract with you, pursue legitimate interests such as service security, fraud prevention, support and measuring whether the product is actually used, comply with tax, accounting and other legal duties, and rely on consent where applicable law requires it. You may withdraw consent at any time without affecting processing that already occurred.
Retention
We keep personal information only as long as reasonably necessary for the purposes above and for legal, accounting, security and dispute-resolution requirements. Core order and license records may remain for the life of a perpetual license so that it can continue to work and be recovered. Deactivated device records may be retained to administer activation limits and prevent abuse. The usage tally holds only a day, a platform and a total; it contains no personal information, so it may be kept indefinitely and there is no record belonging to a person that could be deleted. Central technical records are deleted automatically by level: normal records after 3 days, warnings after 14 days, errors after 30 days and critical errors after no more than 90 days. Agent samples and histories remain on the user’s server within configured count and size caps. Support messages and webhook records are removed when no longer needed. A deletion request may require deactivating the associated license, and we may retain limited records where the law requires or permits us to do so.
Security
MihraOps uses HTTPS for communication with our services, one-way hashes for machine and installation identifiers before raw values leave the device, one-way hashes for refresh tokens, encryption for stored license keys, signed entitlement tokens and restricted administrative access. Server credentials are sent directly over SSH. No security measure can eliminate every risk, so you should also protect your computer, SSH keys and managed servers.
Your choices and rights
You choose which servers to add, whether to save eligible Git, registry or SMTP credentials on them, whether to enable Agent monitoring and email, whether to activate Pro and what to include in a support request. You can remove local server records and remote credentials, and deactivate a licensed device. Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability of your personal information and may complain to your local data-protection authority. We may need to verify your identity before completing a request.
International processing and children
Our service providers may process information in countries other than yours. Where required, we rely on lawful transfer mechanisms and contractual safeguards. MihraOps is a server-management tool intended for adults and business or professional users; it is not directed to children, and we do not knowingly collect children’s personal information.
Changes and contact
We will update this policy when our data practices or legal obligations materially change and will revise the date shown above. For a privacy question, rights request or deletion request, use the contact page or email destek@mihrasoft.com directly.