Privacy Policy
Effective date: 9 August 2026. This policy explains what information the Tiyi project collects when you use our public website, download the Software, or purchase a paid license.
Who we are
Tiyi is a self-hostable web application firewall product published at www.tiyisec.com. For privacy questions, contact [email protected].
Self-hosted Software
When you install and run Tiyi on your own infrastructure, request traffic, WAF decisions, logs, certificates, and configuration stay under your control on systems you operate. We do not receive your production traffic or your customers' personal data through the Software itself.
Optional features you enable (for example update checks against a public release channel, ACME certificate issuance with a third-party CA, or SIEM egress you configure) contact those third parties under your configuration. Review those parties' policies separately.
Website and support
When you visit www.tiyisec.com, our hosting and CDN providers may process standard technical logs (IP address, user agent, referrer, timestamps) needed to serve pages and protect the site.
If you email [email protected], we process the message content and your email address to respond. We keep support correspondence only as long as needed for the request and ordinary business records.
Paid licenses and payments
Paid Tiyi licenses (for example Pro) may be sold through Creem, which acts as Merchant of Record. Creem processes payment details and issues receipts. We receive order information needed to fulfill your license (such as purchaser email, plan, and payment status). We do not store full card numbers.
See Creem's own privacy documentation for how they process payments: creem.io/privacy.
We use fulfillment data to create and email a signed license file and to provide related support. Subscription renewals and cancellations are handled through Creem's checkout and customer portal.
Downloads and updates
Downloading release artifacts from GitHub, Gitee, or our site may expose your IP address and user agent to those hosts. In-product update checks, when enabled, contact the configured release channel to determine whether a newer signed build exists and transmit only the minimum information needed for that check.
Cookies and local storage
The marketing site may store a theme preference (for example light/dark) in your browser's localStorage. We do not use advertising cookies on the marketing site.
Sharing
We do not sell personal information. We share data only with processors needed to operate the site, deliver email, process payments (Creem), or when required by law.
Retention
Support and license-fulfillment records are retained while the commercial relationship is active and for a reasonable period afterward for accounting, abuse prevention, and legal compliance, then deleted or anonymized when no longer needed.
Your choices
You may request access to or deletion of support and purchase-related personal data we hold by emailing [email protected]. Payment records held by Creem must be requested from Creem as well where applicable.
Changes
We may update this policy by posting a new version on this page with a revised effective date. Material changes will be reflected here before they apply to new processing.