Silvercode / silvercode.dev Published

Privacy Policy

This policy explains how Silvercode handles personal information as a company: on the silvercode.dev website, in the contact form, and in the business correspondence that follows. Each Silvercode application also has its own policy covering what that application processes.

Effective: August 4, 2026 Last updated: August 4, 2026

We limit the collection of personal information to the data required to operate and maintain our digital products. Data is transmitted through secure HTTPS connections and access is restricted using appropriate authentication and access controls. We do not sell personal information, and this website carries no analytics, advertising, or tracking scripts.

1. Who is responsible

Silvercode is an independent software studio based in Bosnia and Herzegovina. It builds web and mobile products and is the controller responsible for the processing described in this policy.

For privacy questions, access requests, or deletion requests, use the protected Silvercode contact form. You do not need to publish your request publicly.

2. What this policy covers

This policy covers the silvercode.dev website, the contact API at api.silvercode.dev, and the correspondence and client relationships that arise from them.

Silvercode products are covered by their own policies, because each product processes different data:

  • Moj Dom, the iOS household organizer, is covered by the Moj Dom Privacy Policy.
  • ZaigrajMe, the browser game collection at zaigraj.me, is operated by Silvercode. That site runs its own consent controls, where you can see and switch the individual measurement and error-reporting tools it uses, at zaigraj.me/privatnost.

Where a product publishes its own policy, that policy governs the product. This policy governs Silvercode as a company.

3. Information we process

Website visits

The website is served by Firebase Hosting, a Google service. Google processes technical request data on our behalf, including IP address, user agent, requested address, and timestamps, in order to deliver the site, secure it, and produce delivery statistics.

Silvercode adds no analytics, advertising, or tracking scripts to silvercode.dev. Loading a page requests files only from silvercode.dev, and the site sets no cookies. The only value stored in your browser is a silvercode-language entry in local storage that remembers your language choice. You can clear it at any time in your browser settings.

Contact form

When you send a message through the contact form, we process the email address you enter, an optional name, the message text, and the language of the page. The name is limited to 80 characters, the email address to 254, and the message to between 20 and 2,000 characters.

Your message is delivered by email to a Silvercode mailbox through Amazon Simple Email Service. Your email address is set as the reply address so we can answer you directly.

Anti-abuse information

The contact API protects itself from automated abuse with a signed challenge token, a minimum form-completion time, a hidden honeypot field, an allowlist of accepted origins, and rate limits of five submissions per fifteen minutes and twenty challenge requests per ten minutes for each source.

The records that make this work contain only a keyed hash (HMAC) of the source address, request counters, challenge identifiers, and expiry timestamps. They never contain your name, your email address, your message, or your raw IP address.

Our application logs record a request identifier, the route, the HTTP status, the response size, and an error type. They do not record message contents, email addresses, challenge tokens, or raw source addresses.

Business correspondence

If a conversation continues by email or leads to a project, we process the contact and project details you share with us, such as names, email addresses, company details, and the content of our correspondence, together with any records we are required to keep.

4. How we use information

  • Deliver, secure, and maintain the website and the contact API.
  • Receive, verify, and answer enquiries sent through the form.
  • Prevent automated abuse, spam, and misuse of the contact service.
  • Discuss, plan, and deliver work for clients.
  • Keep records that we are legally required to keep.

Under the GDPR, we rely on our legitimate interests in operating and protecting our own services and in answering enquiries (Article 6(1)(f)), on steps taken at your request before entering a contract and on the performance of a contract (Article 6(1)(b)), and on compliance with legal obligations where they apply (Article 6(1)(c)).

We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not build advertising profiles from website visits.

5. When information is shared

Silvercode does not sell personal information and does not share it for advertising. Information is shared only with the service providers that run our infrastructure, and only to the extent they need it:

  • Google, for Firebase Hosting, which serves the website and processes request data described above. See Firebase privacy information and Google's Privacy Policy.
  • Amazon Web Services, for the contact API. The stack uses API Gateway, Lambda, DynamoDB, Simple Email Service, Systems Manager Parameter Store, Certificate Manager, and Route 53, hosted in the Europe (Frankfurt) region. See the AWS Privacy Notice.

We may also disclose information where the law requires it, or where it is necessary to establish, exercise, or defend legal claims.

6. Retention

  • Anti-abuse records expire automatically. Rate-limit counters expire within twice their window, and challenge records expire roughly an hour after the challenge is issued.
  • Messages sent through the form are kept in the Silvercode mailbox for as long as needed to answer the enquiry and to keep a reasonable record of it, and are deleted afterwards or on request.
  • Hosting request logs are retained by Google according to Firebase Hosting's own retention periods.
  • Client and accounting records are kept for as long as the applicable legal retention periods require.

7. Security

All traffic is served over HTTPS with HSTS, and the site sends a strict Content Security Policy that blocks third-party scripts and connections. The contact API accepts only requests from our own origins.

Secrets are stored encrypted in AWS Systems Manager Parameter Store, and the contact function is permitted to read only those secrets, write only its own table, send only from its configured address, and write only its own logs. Access to the mailbox and to our cloud accounts is restricted and protected by authentication controls.

No system is perfectly secure, but we design for the smallest amount of data that still lets the service work.

8. International processing

Silvercode operates from Bosnia and Herzegovina, which is outside the European Economic Area. The contact API runs in the AWS Europe (Frankfurt) region. Firebase Hosting is a global content delivery network, so website requests may be served and logged outside your country. Our providers rely on their own transfer mechanisms, including the European Commission's standard contractual clauses where they apply.

9. Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.

Send requests through the protected contact form. We may ask for information that lets us confirm the request comes from you before we act on it.

You can also complain to a supervisory authority. In Bosnia and Herzegovina, this is the Personal Data Protection Agency. In the European Economic Area, it is the authority of your country of residence.

10. Children

The silvercode.dev website is aimed at people looking for professional software work and is not directed at children. We do not knowingly collect personal information from children through this site. Age requirements for individual products are described in their own policies and store listings.

11. Changes to this policy

This policy may be updated when our services, providers, or legal obligations change. The updated date appears at the top of this page, and material changes will be communicated through an appropriate channel when required.

12. Contact

Controller and privacy contact: Silvercode, Bosnia and Herzegovina. Use the protected contact form for questions or privacy requests.