Only the details you choose.
This notice applies to the ReturnDocket invitation beta. It supplements, and does not replace, the existing Berg App privacy policy.
Who operates ReturnDocket?
Berg App LLC, 30 N Gould St Ste N, Sheridan, WY 82801. Contact privacy@bergapp.net. The product is intended for adults 18 and older.
What we store
A random account identifier; hashed credentials; purchase item and merchant names; USD amounts; purchase and return-by dates; short source notes; return/refund status; timestamps and versions. Do not put card details, addresses, children's information or sensitive personal details in these fields. We do not request email, mailbox access, photos or receipts.
Why and where
We use these records to provide your docket, authenticate access, prevent abuse, handle requests and improve reliability. Cloudflare hosts Workers and D1 and provides Turnstile verification. Cloudflare processes technical request information under its own applicable terms. If you connect Muse, Meta receives the data you choose to share through that service; it has its own privacy practices.
Usage and security records
We keep operation receipts for safe retries for 30 days, brief abuse-control counters and content-free diagnostic logs. Aggregate daily event counts are retained for 90 days. Account activity dates let us assess activation and repeat use. We do not log credential strings or purchase payloads. We do not sell your records or use them for third-party advertising.
Your controls
Use your recovery key to export data, rotate or revoke connector access, delete individual records or delete your account. All purchase and account data is removed from the active database on account deletion, with credentials revoked immediately. D1 recovery backups on the current free plan can retain a prior state for up to seven days. Support correspondence has a separate limited retention period described when necessary for your request.
Retention and changes
Purchases remain until you delete them or the service is retired with notice where possible; there is no email address on file for individual notices. Expired connector hashes are cleaned daily. Abuse counters are normally removed within three days. Operational hosting logs follow the account's configured retention. A backup restoration requires deletion reconciliation before service reopens. We will update this page if these practices change.
Requests
For access, correction, deletion or other privacy requests, use account controls or email privacy@bergapp.net. We verify control of the account before disclosing data. No password or email recovery exists; keep the recovery key safe.