Privacy policy

Version of 31 August 2026.

Courtesy translation. If translations differ, the French version prevails, subject to applicable mandatory law.

Current status: a showcase with no database, no access log

As of this version, endlesslock.com is a pure showcase: it sells nothing, takes no payment, opens no account and no longer keeps any database at all. Installation is self-service through the assistant: nothing is handed to the user, and no operation is linked to a name, an e-mail address, an account or an IP address.

No access log is kept. Neither the web server nor the application is configured to write one: the IP address, the visited URL and the timestamp of a visit are not retained on disk beyond the immediate handling of the request. The web server is further configured to strip everything describing the request from its error messages, that is the IP address, the requested URL, the forwarding headers and the browser: only the technical cause of the error remains. The system log is kept for seven days.

What the site does not control. The machine and the network serving endlesslock.com belong to the host, Mynymbox Hosting LLC (Amsterdam, Netherlands), named in the legal notice. Its network and infrastructure logs belong to it: the operator can neither read them, nor erase them, nor prevent them from existing. What is described here is therefore what this site does, not what its host does.

Minimisation principle

The site works without an account, without a name, without an e-mail address, without a cookie and without an advertising tracker: we ask you for none of that information, and no payment is possible here. Some data may nevertheless be personal or pseudonymous data where it can be linked to a person: correspondence with support and, outside this site, the technical device identifier and the top-up data described below. It is described below in accordance with applicable data protection law.

Topping up premium credit takes place on a separate service, the top-up portal, operated by the same controller: what that portal processes is described below under “Data, purposes and retention”. This policy therefore covers endlesslock.com, the installed software and that top-up.

Controller

Endlesslock LLC, New Mexico limited liability company
1209 Mountain Road Pl NE, Ste R
Albuquerque, NM 87110
United States
Entity ID (New Mexico): 0008124326
E-mail: contact@endlesslock.com

Data, purposes and retention

  • Installation and enrolment: installation is self-service through the assistant, with no account. The assistant installs the software and enrols the device; endlesslock.com keeps no data on that occasion. The enrolment service keeps only a technical fingerprint derived from the device, with no identity, to enforce the "one installation per device" rule.
  • Technical device identifier: tracking premium credit requires recognising a device from one installation to the next. An identifier derived from the device is used for that. It survives a factory reset, contains no personal data and is linked to no name, no account and no means of payment; it only attaches a time credit to the right device. It is nevertheless a persistent identifier, and it is described here as one. It lives on the top-up service and on the enrolment service, never on endlesslock.com.
  • Premium credit top-up: the top-up portal processes only the technical identifier of the device to be credited, the chosen tier, the Monero payment address dedicated to the top-up, the conversion rate frozen at its creation and its timestamp. Payment is currently made in Monero only, with no payment provider: no banking or identity data is collected on that occasion. This data is kept for as long as needed to perform the top-up, defend legal rights and comply with legal duties. Once payment by card becomes available, the payment provider will collect the data needed for the transaction; no service of ours will keep any of it and that means of payment will be de-anonymising.
  • Evidence of consent, collected by the installation assistant: terms version, selected language and the timestamp of acceptance. No identity or IP address is added to this record, which is kept for as long as needed to defend legal rights and comply with legal duties.
  • Technical logs: the system log keeps service messages (start-ups, errors, certificate renewal) for seven days. The web server strips whatever describes the request from them, as explained above. If an access log were ever enabled, IP address, date, requested resource and security events could be recorded to keep the service available, prevent abuse and investigate incidents; they would be deleted after no more than seven days unless longer retention is strictly needed for a documented incident or required by law, and would not be used for user profiling.
  • Correspondence: where a person contacts support, their sender address, message and any material they choose to provide are used to respond and handle the request. They are deleted when no longer needed, subject to legal duties or the establishment of legal claims.

Processing relies as appropriate on contract performance, legal duties, and legitimate interests in securing the service and defending legal rights. No decision with legal or similarly significant effects is made solely by automated means.

Cookies, payments and recipients

The site sets no cookies and loads no third-party font, advertising, analytics or script. No payment is possible on endlesslock.com: no page here asks for a card or a wallet. Topping up premium credit happens on the top-up portal and is currently paid in Monero only: that payment is direct, with no payment provider and no other intermediary. Payment by card is temporarily unavailable; once offered, it will go through a payment provider and will be de-anonymising; that provider will then be a recipient of the transaction data.

Data is accessible only to authorised persons and indispensable technical providers bound by appropriate duties. Data may also be disclosed where a valid legal duty requires it. It is neither sold nor used for advertising.

International transfers

Host of the site: Mynymbox Hosting LLC, Amsterdam, Netherlands. If data is sent to a country that does not guarantee an adequate level of protection, the controller implements the safeguards required by applicable law and informs the data subjects. The same regime applies to the data processed by the top-up portal.

Individual rights

Within the limits of applicable law, a person may request information about their data, correction, delivery or deletion, and, where the law provides for it, contact the competent supervisory authority.

Requests are sent to the e-mail address given above. As no identity is linked to a device, it may be necessary to supply something only the holder has, for instance the device identifier shown by the application. This check avoids disclosing data to the wrong requester. A request about a top-up is sent to the same address; the device identifier may again be needed to match it to the right device.

Security

Measures include encrypted transport, a restrictive content security policy, service separation and the absence of access logs. As no system can be guaranteed risk-free, any incident likely to create a high risk is handled and notified as required by applicable law.