01Who is the data controller
The controller of any personal data processed under this policy is Diyan, a sole natural-person seller based in Dobrich, Bulgaria, operating the IQBot Cert software and the website cert.iqbotbg.pro. For any privacy question or GDPR request, write to support@iqbotbg.pro.
02What data we collect
IQBot Cert is designed to collect as little personal data as possible. We handle four distinct categories:
2.1 Phone diagnostic data (read over USB / ADB)
When you scan a phone, the software reads standard, publicly documented Android system properties over ADB. These readings are compiled into a PDF certificate. The following identifiers may be read from the phone:
- Model, brand, hardware revision, Android version, security patch level;
- Full IMEI (used locally to compute the masked form; only the masked form leaves the machine);
- Serial number (used only in the local PDF; not uploaded);
- Battery fuel-gauge readings, sensor inventory, camera hardware, display specs;
- Bootloader lock state, verified boot state, SELinux state.
The full IMEI, the full serial number, and all raw ADB dumps stay on the operator's Windows machine that ran the scan. They are not uploaded anywhere.
2.2 Certificate data (uploaded for online verification)
When a certificate is generated, a small record is uploaded to our server so the QR code on the PDF can be verified publicly. The record contains only:
- Certificate reference (for example
IQB-E5F0C2EA-202609091407); - Grade and score;
- Device brand and model (e.g. "OPPO CPH2819");
- Masked IMEI (e.g.
866068 •••••• 19) — the middle 6 digits are never uploaded; - Timestamp of issue;
- Result of online IMEI checks where enabled (GSMA blacklist status, TAC brand/model).
2.3 Purchase & licensing data
When you buy a PRO license, Gumroad, Inc. collects your name, email address, billing country and payment information as the merchant of record. We do not receive your card details. Gumroad shares with us: your email, your license key, purchase timestamp and refund/chargeback status.
When you activate a license in the software, we store the license key, a non-reversible machine identifier hash (derived from the Windows MachineGuid), and the activation timestamp on our server, so we can enforce the one-machine license.
2.4 Support correspondence
If you email support@iqbotbg.pro, we receive your email address and the content of your message. We use it only to answer you.
03What we do NOT collect
The website does not use: Google Analytics, Facebook Pixel, third-party trackers, advertising cookies, session recording tools or fingerprinting scripts. The public verification page at
cert.iqbotbg.pro/c/<ref> is served without any tracking script.
04Legal basis
- Performance of contract (Art. 6(1)(b) GDPR): to deliver the license, activate it, generate certificates and enable QR verification.
- Legitimate interest (Art. 6(1)(f) GDPR): to prevent abuse of the license activation endpoint and the online IMEI upstream, and to respond to support requests.
- Legal obligation (Art. 6(1)(c) GDPR): to comply with Bulgarian tax and accounting rules for a sole natural-person seller.
05Who we share data with
We only share the minimum data necessary with the following processors:
- Gumroad, Inc.
- Payment processor and merchant of record. Handles purchase, invoicing, VAT and refunds. See gumroad.com/privacy.
- Spaceship
- Domain registrar and DNS provider for iqbotbg.pro; hosts our support mailbox.
- Amazon Web Services (AWS)
- Hosts the verification server (EC2, Ohio region). Encrypted at rest, TLS in transit.
- imeicheck.com
- Third-party upstream provider for GSMA blacklist and TAC IMEI lookups. We send only the phone's IMEI. Their data is provided as is under their own terms of service and we are not liable for outages, delays or inaccuracies in their responses. See their privacy notice on their site.
- Storage.googleapis.com
- Public Google Play supported devices catalog, downloaded to our server. No user data is sent.
We do not sell your data. We do not share it for advertising. We do not disclose it to third parties except when legally required.
06Where the data lives
The certificate records, license activation records and IMEI cache live on our server in Ohio, United States (AWS EC2). Gumroad stores purchase data on its own infrastructure. If you are in the EU/EEA, personal data transferred to the US is protected by (a) AWS's Standard Contractual Clauses (SCCs) as approved by the European Commission and (b) where applicable, the EU-US Data Privacy Framework (Adequacy Decision 2023/1795 of the European Commission, upheld by the EU General Court in September 2025 in Latombe v. Commission). UK residents are covered by the UK-US Data Bridge extension of the Framework. In the event that the Data Privacy Framework is invalidated or suspended by the Court of Justice of the European Union, we will either (i) migrate the verification server to an AWS region located within the European Economic Area (e.g. Frankfurt or Ireland) within 30 days, or (ii) rely on SCCs plus supplementary technical measures — whichever is required to preserve lawful transfers under Chapter V of the GDPR.
07Retention
- Certificate records: kept for 90 days after issue. The QR verification page stops resolving after this period; buyers who need long-term proof should archive their downloaded PDF.
- License activation records: kept for the lifetime of the license (needed to enforce the one-machine rule).
- IMEI upstream lookup cache: 168 hours (7 days), then evicted.
- Support emails: up to 2 years, then deleted.
- Purchase records (invoices): kept by Gumroad and by us for as long as required by Bulgarian tax law (typically 10 years).
08Your GDPR / UK GDPR / US state-privacy rights
EU / EEA residents (GDPR). Under the General Data Protection Regulation you have the right to:
- Access the personal data we hold about you;
- Have inaccurate data corrected;
- Have your data erased (subject to legal retention obligations);
- Restrict or object to processing;
- Receive your data in a portable format;
- Withdraw consent where processing is based on consent (not the default here);
- Lodge a complaint with the Bulgarian Commission for Personal Data Protection (cpdp.bg) or your local supervisory authority.
United Kingdom residents (UK GDPR + Data Protection Act 2018). The rights above apply equivalently under UK data-protection law. Complaints may be lodged with the UK Information Commissioner's Office (ico.org.uk).
United States residents. Depending on the state you live in, you may have specific rights under state privacy laws — including the California Consumer Privacy Act as amended by the CPRA (California), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA) and equivalent laws in other states. In particular you may have the right to (a) know what personal information we hold about you, (b) request deletion of that information, (c) correct inaccurate information, (d) opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising, and (e) not be discriminated against for exercising these rights. We do not sell or share personal information for behavioural advertising. California residents may designate an authorised agent to make requests on their behalf.
To exercise any of the rights above, email support@iqbotbg.pro with the subject "Privacy request". We respond within 30 days (GDPR/UK GDPR) or 45 days (US state laws).
09Cookies & tracking
The website cert.iqbotbg.pro and its verification pages do not set any cookies of their own. No third-party analytics or advertising scripts are loaded. Web fonts are self-hosted on our server (no Google Fonts CDN). Three.js is loaded from a public CDN (unpkg.com) which may see your IP address and browser user-agent as a technical part of serving the JavaScript file.
10Security
The verification server is fronted by nginx with automated Let's Encrypt TLS certificates. Administrative access is restricted to a single SSH key with fail2ban IP-banning and rate limiting enabled. License activation tokens are HMAC-signed and expire after 30 days. All secrets are stored in an environment file with mode-0600 permissions readable only by the service account.
11Children
IQBot Cert is a business tool intended for adults selling second-hand phones. It is not directed at children under 16 and we do not knowingly collect data from them.
12Changes to this policy
If we make a material change we will update the "Last updated" date at the top of this page. For substantial changes affecting existing customers we will send a notice to the email address on file.
13Contact & complaints
- Data controller
- Diyan · sole natural-person seller, Dobrich, Bulgaria
- Contact email
- support@iqbotbg.pro
- Supervisory authority
- Commission for Personal Data Protection (CPDP), Bulgaria — cpdp.bg