Privacy Policy
Last updated: September 10, 2026
This policy explains what Hosting Sav LLC (“we,” “us”) collects through your epipra.com account, why, and what your options are. It covers the account hub itself; a connected tool (sms.epipra.com, openseo.epipra.com, notes.epipra.com) may collect additional data specific to its own functionality, described in that tool’s own policy where one exists.
1. Information we collect
Directly from you, at signup:
- Name
- Email address
- Password (stored only as a salted cryptographic hash — we never see or store your plaintext password)
Automatically, to keep you signed in and secure your account:
- Session identifiers (via a cookie)
- IP address and browser user-agent string, attached to each session, for fraud and abuse detection
- Account timestamps (created, last updated)
If you use the password-reset flow, we generate a single-use reset token tied to your email address, valid for one hour.
2. How we use it
We use this information to:
- Authenticate you and maintain your session across epipra.com and connected tools
- Let you recover access to your account if you forget your password
- Detect and prevent unauthorized access or abuse
- Respond to support requests you send us
We do not use your account data for advertising, and we do not sell it to anyone.
3. Cookies
We set one essential, HttpOnly session cookie needed to keep you signed in. It is scoped to the epipra.com domain so that a connected subdomain (sms., openseo., notes.) can recognize the same session once it’s wired up to do so. We do not use tracking or advertising cookies. Because this cookie is essential to the Services functioning, there is no separate opt-out for it — declining it means you cannot stay signed in.
4. Who we share it with
We do not sell or rent your data. We share it only with:
- Connected tools you choose to use, so your one account works across them
- Infrastructure providers that host our servers and database, solely to operate the Services, under obligations to protect it
- Authorities, if legally required to comply with a valid legal process
5. Data retention
We keep your account data for as long as your account is active. If you delete your account, we delete your account record and active sessions; we may retain minimal records where required for legal, security, or dispute-resolution purposes for a limited period afterward.
6. Security
Passwords are hashed, never stored in plaintext. Sessions are authenticated with signed, HttpOnly cookies transmitted only over HTTPS. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
7. Your rights
You can review and update your name and email from your account page. You can request a copy of the personal data we hold about you, or request that we delete your account and associated data, by emailing [email protected]. We will respond within a reasonable time.
8. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to this policy
If we make material changes to this policy, we will update the “Last updated” date above and, where appropriate, notify you by email.
10. Contact
Questions about this policy, or requests regarding your data, can be sent to [email protected].