Privacy Policy

The short version: the app does its work on your PC, we collect as little as possible, and we never sell your data.

This covers the BRUTAL Optimizer website and the desktop app. The short version above is the whole spirit of it; the rest of this page is the exhaustive detail — including every single time the app talks to the network. We would rather over-disclose than let you find a surprise.

BRUTAL Optimizer for Android has its own privacy policy at brutaloptimizer.com/android/privacy — same brand, but a different product with different data practices (it routes game traffic through a VPN relay, and its free tier shows rewarded ads). It was called Truepath until 2 August 2026. This page covers BRUTAL Optimizer for Windows and this website only.

Who we are (data fiduciary)

BRUTAL Optimizer is made and operated by ARHAS INDIA (OPC) PRIVATE LIMITED (CIN: U62013TS2026OPC220112), a One Person Company incorporated under the Companies Act 2013, registered office SY No. 4A & 4/AA, Peeramcheru, Golconda, Hyderabad 500008, Telangana, India ("we", "us", "the Company"). Under India's Digital Personal Data Protection Act 2023 (the "DPDP Act"), the Company is the data fiduciary for the personal data described on this page — that means we are the ones responsible to you for how it is handled. You can reach us any time at legal@brutaloptimizer.com.

What the app does on your PC

The desktop app runs locally and optimizes on your machine. By default the app uploads nothing about your files, browsing or settings. Two optional features change that in a small, stated way — server-side update checks and crash reports — and each one below says exactly what it sends and how to keep it off. Everything the app does send is listed below, in full, with the reason for each.

Deleted File Restore reads your files; we receive none of it. To show you what can still be put back, the app reads the Recycle Bin belonging to the Windows account you are signed in to, on each of this PC's fixed drives. When you choose a drive and press Scan — an internal drive, a memory card or a USB drive, formatted NTFS, FAT32 or exFAT — it reads that drive directly: the drive's own file table (which covers the deleted files of every account that used that drive) and then the blocks each deleted file's record points at. And when you search the point-in-time copies Windows keeps of your drives (shadow copies, the same thing behind "Previous Versions"), it reads those copies within your own user folders. All of this is read-only and happens only when you ask. That means it reads the names, paths, sizes, timestamps and contents of files you deleted. All of it stays on your machine. None of it is uploaded, none of it is written to any log file that could later ride along inside a crash report, and we never see a single filename. Restoring copies the file to a location you choose on a different physical drive — the app does not send it anywhere and keeps no index of what it found once you leave the page. Under the DPDP Act we are the data fiduciary only for personal data we actually process — your email address and licence record, itemised below. Content this feature reads never reaches us in any form, so there is nothing for us to hold, share, or be asked to delete.

Every network call the app makes

  • License check. Signing in is optional on the free tier — the app works without it. When you do sign in (to use Pro or Ultra, or to keep a free license you can recover on any PC), you use your email address (a passwordless 6-digit code, no password to create). That email is your license identity. After that the app contacts our license server to verify your license, sending your license key and a one-way hash of a machine identifier (Pro keys bind to one machine; the free tier works on any PC). We can't see your hardware details in that hash, and we use it for nothing except licensing and safe update rollout.
  • Update check & adoption count. The app asks our update endpoint whether a newer version exists, sending its current version number and the same one-way machine hash used for licensing — the hash lets us roll a release out gradually (a stable slice of machines gets the new version first); we can't see your hardware details in it. Each check also counts anonymously toward per-version adoption totals (a bare counter — the check itself carries nothing extra), so we can see how a release is spreading and catch a bad one early.
  • Anonymous version beacons. On launch, and if an update fails, the app posts a small anonymous note — at most once per day for each kind (launch, failed update) — carrying only the app version number. The payload itself carries no identifier: no account, no machine hash, no Windows version, no hardware details. This is how a crash-on-launch build becomes visible to us at all. You can switch these off under Settings → Diagnostics, separately from every other switch.
  • Game catalog. On launch and every few hours (and when you open the game pages) the app fetches our game catalog — the ban-safety list and per-title kill-switches — from our server, so a title we've had to disable stops being offered without waiting for an app update. The request carries no personal data.
  • Help search. If you use Search help articles in Settings, the words you type are sent to our server, which matches them against the Help Center articles we have published and sends back titles and links. The request carries no account, license key or machine identifier, and our server does not save your query; a one-way hash of your IP address is used to limit how many searches one connection can make. Because the words travel in the request address, they appear in the short-lived Cloudflare request logs described below — so there is no need to type personal details into it.
  • Announcement check. The app periodically asks whether we have posted an in-app notice to show you (an offer or an update notice). It sends only your tier (free or Pro) so the correct notice is chosen — nothing else.
  • Smart Route intel (networking feature). If you use Smart Route, the app fetches our current relay-server list from our server, and shares anonymous route-quality measurements so routing improves for everyone. Sharing is on by default and has its own on/off switch in the app; the measurement payload never carries an identifier. The same switch governs the route-prediction query — when sharing is on, the app may ask our server which relay has been winning for your game (sending the game's name and its server address, nothing about you) so measuring can start from the best candidate.
  • Smart Route engage (networking feature). Measuring is local; if you choose to route (or auto-route) a game, the app opens a WireGuard tunnel from your PC to one of our relay servers, and only that game's traffic to its game server travels through it. The relay necessarily sees your IP address (like any VPN hop); it carries packets and keeps no log of your gameplay. Requesting a relay slot sends the same one-way machine hash used for licensing plus a tunnel public key generated on your PC (the private key never leaves it). If WireGuard isn't installed, the app offers to fetch the official installer from download.wireguard.com. Disengage or exit the game and the tunnel is torn down.
  • Country check (Smart Route). Smart Route is not offered in a short list of countries where VPN use is restricted by law or comprehensive sanctions apply. When the app asks for the relay list or a relay slot, our server compares the country Cloudflare reports for your connection with that list, and the website's checkout makes the same check before it sells Ultra (nothing about the checkout check is stored). The check starts in an observation mode that refuses nobody. In that mode, if an account with a paid Smart Route subscription (Ultra) asks for a relay slot from one of those countries, we record the license key, the country, which app the request came from (Windows or Android), when it was first and last seen, and how many times, so we can contact those customers before Smart Route stops in their country and arrange a refund. That record is deleted 90 days after it was last updated, and when your account is deleted. Once we stop offering Smart Route in a country, requests from there are refused before your account is looked up, so nothing is recorded against it; we keep only an anonymous count per country.
  • Driver & app updates use the vendors' own channels. Scanning for driver updates queries Windows Update (Microsoft) and, for NVIDIA GPUs, NVIDIA's driver service — which learns your GPU model and Windows version, the same as checking on their sites. Searching the Microsoft Update Catalog sends the device's hardware ID to Microsoft. App-update scanning runs Microsoft's winget tool, which contacts Microsoft's package repositories. A background daily quick-check for driver and app updates uses the same channels; downloads come from the vendor, never from us.
  • Server-side update checks (optional, off by default). If you switch on "check updates server-side", the app uploads a minimal inventory — package ids and one-way hashes of installed app names with their versions, driver hardware-ID prefixes, and your GPU's PCI id — with the licensing machine hash, so our server can answer "what's outdated" in one call. Turn it off and the app goes back to checking locally.
  • Price display. Once per session the app asks our own website which country the connection appears to be from (a Cloudflare loc= lookup) purely to show prices in ₹ or $ — no location is stored and checkout is unaffected.
  • Network tests you run. The ping test, route analyzer, DNS benchmark and bufferbloat test send probe packets to public reference endpoints (AWS regional hosts, Cloudflare, Google and other public DNS resolvers, and Cloudflare's speed-test service). They carry no personal data — the endpoints just see a ping, and the bufferbloat test intentionally moves bulk throwaway data to load your line.
  • Optional DNS features. If you apply a recommended DNS, enable ad-blocking DNS (AdGuard) or encrypted DNS (Cloudflare/Google/Quad9), your PC's DNS lookups go to that provider — that is how those features work, and each provider publishes its own privacy policy. One click reverts to your previous DNS.
  • Crash reports (the app always asks first). If the app crashes, it prepares a report and asks you before anything is sent — every time, unless you choose "Always send"; choosing "Never" sends nothing and deletes the pending report from your disk. Before you decide, you can press "View the exact report" to read the precise bytes that would be sent. A report contains: what crashed (the error and where in the code), the app version, your Windows version and hardware tier, your recent in-app actions, and the tail of the app's own log — with file paths, usernames and machine names scrubbed out before it is built. It deliberately contains no account, no email, no machine ID, and no memory contents, and we keep no IP address with the report — a one-way hash of it lives for about a day purely to stop one machine's crash loop being counted twice. Raw crash dumps, which can hold memory contents, never leave your machine — only their metadata (the error code and which module faulted) rides along in the report. Reports are kept for 30 days and then deleted; only anonymous aggregate counts (how many crashes per app version) are kept longer, as statistics with nothing tying them to you. The app shows you a short report ID for each report it sends — to have one deleted sooner, email legal@brutaloptimizer.com with that ID. The separate "Report a problem" button (and the website contact form) sends what you type, the app version and a build-identity token, and only the attachments you explicitly tick — all previewable byte-for-byte before sending — plus your email only if you enter it.

Like any internet service, every call above reaches our servers through Cloudflare, which keeps standard security logs (IP address, user agent) for a short period — that applies to the app's API traffic as well as the website. Where we call something "anonymous" above, we mean the payload itself carries no identifier.

What the website collects

  • Registering & signing in (free or Pro): we store your email address to issue and recover your license, tie it to that address, and send your one-time sign-in codes. For Pro we also remind you before your year ends. We never send marketing. Nothing more.
  • Contacting us: when you email one of our addresses, use the contact form, or press Report a problem in the app, we keep the conversation in our support desk — your email address, your name if you give it, and what you wrote (plus any diagnostics you chose to attach) — so we can answer you, and a copy of each message goes to our support inbox, which runs on Google's Gmail. Both are kept until you ask us to delete them; deleting your account deletes the support-desk copy, and we delete the inbox copies when you ask.
  • Bot protection: the registration and giveaway forms use Cloudflare Turnstile to keep bots out — a privacy-respecting alternative to reCAPTCHA.
  • Giveaway screenshot screening: screenshots submitted to the Share & Win giveaway are automatically screened for validity using Google's Gemini API before human review; Google processes the image as our processor and we don't let it be used for anything else.
  • Hosting and logs: the site runs on Cloudflare, which keeps standard request logs (IP, user agent) for security and abuse prevention. Cloudflare also injects its own cookieless Web Analytics beacon (static.cloudflareinsights.com) at the hosting layer — it sets no cookie and does not track you across sites, and it loads with the page rather than through the consent banner.
  • Analytics (only with your consent): if you click "Accept" on our cookie banner, we use Google Analytics to see how the site is used — which pages, roughly where visitors come from — so we can improve it. Nothing loads and no analytics cookie is set until you accept, and you can change your mind any time: the Cookie settings button in the website's footer reopens the choice, and pressing Decline there stops Google Analytics at once and deletes its cookies. We do not enable Google's advertising features.

For the full list of third parties that process data on our behalf, see our subprocessors page. For where each piece of data physically lives and how long we keep it, see our data-residency statement.

Legal basis: why we're allowed to process this (DPDP Act)

Under the DPDP Act we process personal data on two bases, and we'll tell you plainly which is which:

  • Your consent. When you give us your email to activate a license, you're consenting to us using it for exactly the purposes stated at that moment: issuing, verifying and recovering your license, and sending you the transactional emails that make that work (sign-in codes, your key, renewal reminders). Website analytics runs only after you click Accept. Crash reports are sent only after you approve each one (or choose "Always send", which you can turn off). We ask for consent in plain language, for stated purposes only, and we only ask for what those purposes need.
  • Legitimate uses recognised by the Act. Some processing happens because the service can't work without it, or because the law recognises it as legitimate: verifying the license you asked us to verify, delivering updates you asked to check for, security and abuse prevention on our servers (Cloudflare request logs, Turnstile), complying with legal obligations (keeping the financial record of a paid purchase), and responding when you voluntarily contact us.

Withdrawing consent is as easy as giving it. Analytics: the Cookie settings button in the website's footer, then Decline. Crash reporting and version beacons: their own switches in Settings → Diagnostics. Your account itself: email us and we delete it (details under "Your rights" below). Withdrawing consent doesn't affect the lawfulness of what was done before you withdrew, and it may mean the parts of the service that needed that data stop working — we'll tell you which, not just switch things off silently.

Your rights (data principals)

If we hold personal data about you — for almost everyone that is just your email address and license record — you have the right to:

  • Access: ask for a summary of the personal data we hold about you and what we've done with it, including which processors it has been shared with.
  • Correction and updating: have inaccurate or incomplete data corrected, completed or updated (for example, moving your license to a new email address).
  • Erasure: have your personal data deleted. We delete your email and license record on request, together with your support conversations (including the copies in our support inbox). If you bought a paid key, the record of that purchase is kept as the financial record tax law requires: the license record itself is reduced to a stub that no longer identifies you, but the payment events Razorpay sent us for it — which carry the email address and phone number you paid with — stay in our billing ledger for as long as the law requires us to keep them. Data we delete can also remain in our private weekly disaster-recovery copies for up to 90 days, until those copies expire.
  • Grievance redressal: a real response through the Grievance Officer below, and if you're not satisfied, the right to complain to the Data Protection Board of India.
  • Nominate: name another person to exercise these rights for you if you die or are incapacitated.

To exercise any of these, email legal@brutaloptimizer.com from the address on the account (that's how we verify it's you — we'll never ask for more ID than the request needs). These choices apply wherever you are, including under the EU/UK GDPR and California's CCPA.

Grievance Officer

Grievance Officer: Arafath Hashmi, Director, ARHAS INDIA (OPC) PRIVATE LIMITED
Address: SY No. 4A & 4/AA, Peeramcheru, Golconda, Hyderabad 500008, Telangana, India
Email: legal@brutaloptimizer.com (subject line "Grievance")

Acknowledgement: within 48 hours of receiving your grievance
Resolution: within 30 days of receipt, or sooner where the applicable rules require it; if it will take longer, we tell you why and when.

You can also raise a grievance through our contact form (it runs in your browser, so JavaScript must be enabled), or by post to the address above — no email client needed.

If you're not satisfied with our response, you can escalate to the Data Protection Board of India once you've exhausted this process. We'll never make you regret asking.

Children

BRUTAL Optimizer is a Windows maintenance tool that requires Administrator rights, intended for the PC's owner or administrator. Under the DPDP Act, everyone under 18 is a child, and processing a child's personal data requires verifiable parental consent. Today the only personal data an account involves is an email address, and email sign-up will include a self-declared 18+/parental-consent attestation; if you are under 18, ask a parent or guardian to create the account and accept this policy for you.

The Act also prohibits tracking, behavioural monitoring and targeted advertising directed at children — and we are comfortable stating plainly: the desktop app shows no ads in any tier, does no behavioural monitoring, and contains no advertising or cross-service tracking of any kind; the only persistent identifier it ever sends is the one-way machine hash described above, used solely for licensing and safe update rollout. Website analytics is off unless the visitor opts in. If we learn we hold a child's data without the required consent, we delete it. If you believe a child has given us personal data, email legal@brutaloptimizer.com.

If something goes wrong (personal data breaches)

If a breach of personal data happens on our side or at one of our processors, we will notify the Data Protection Board of India and each affected user in the form and timelines the DPDP Act and its Rules require — and our own bar is simpler and higher: if your data is involved, you hear it from us directly and promptly, in plain language, with what happened, what of yours was involved, and what we're doing about it. We keep so little (for most users: an email address and a license record) that the blast radius of our worst day is deliberately small — that's a design choice, not luck.

Where your data lives, and for how long

Almost all product data — optimization backups, Guardian logs, benchmarks, the encrypted license file — stays in %LOCALAPPDATA%\BRUTAL on your own machine and never leaves it. For the little that does leave, our data-residency statement is the authoritative per-datastore table: what each piece of data is, where it physically lives, and exactly how long we keep it. That table is part of this policy — any change to it is a change to this policy, moves the "last updated" date, and triggers the same notice as any other change. The headline retention periods it records today: your email and license record for the life of the account; support conversations until you ask us to delete them (they are deleted with your account); payment records for as long as tax law requires; crash reports for 30 days; the crash-loop IP-hash for about a day; a Smart Route country-check record (described above) for 90 days after it was last updated; our weekly disaster-recovery copy of those server records for 90 days; Cloudflare request logs for the provider's standard short period.

Cross-border transfers

Our infrastructure runs on Cloudflare (a US-headquartered provider whose network is global, with no jurisdiction pinning on the products we use), billing runs through Razorpay in India, consent-gated website analytics is processed by Google in the USA, copies of the messages you send us sit in our support inbox at Google (Gmail) in the USA, and a weekly disaster-recovery copy of our server records — including license records with email addresses, support-desk messages and payment events — is kept as a private build artifact by GitHub (Microsoft) in the USA for 90 days, so a copy exists outside Cloudflare if something goes wrong there. The data-residency page gives the same picture, datastore by datastore. The DPDP Act permits transferring personal data outside India except to countries the Indian government restricts by notification; we do not store personal data in any restricted country, and if the government's list changes we will move data or change providers to comply, and update the data-residency page in the same change.

Cookies

We keep cookies to a minimum. Essential: a small record of your cookie choice, plus a Cloudflare Turnstile token on the sign-in and giveaway forms. Analytics (optional, off by default): Google Analytics cookies, set only after you accept. There are no advertising cookies. Change your choice any time with the Cookie settings button in the website's footer; choosing Decline deletes the Google Analytics cookies.

Email

Transactional email — your sign-in codes, your key and renewal reminders — is sent through Cloudflare's email service. We email you about your license, not marketing.

Payments

Payments and renewals run through Razorpay. Your card number never reaches us. For each payment Razorpay sends us a record of it — including the email address and phone number you paid with and the payment method as Razorpay reports it (for example a card's network and last four digits) — which we keep as described in our data-residency statement.

What we don't do

We don't sell your data. We don't run advertising trackers and we don't build a profile on you. Our only optional analytics is Google Analytics — used for product improvement only, with ad features off, and off until you opt in. The hosting layer also runs Cloudflare's cookieless Web Analytics beacon, described under "Hosting and logs" — it sets no cookie and does not identify you. And we never receive the contents or filenames of anything Deleted File Restore reads on your PC — that feature is wholly local.

Changes to this policy

When we change this policy, the "last updated" date changes with it, and any new network call, datastore or provider lands here in the same change that introduces it — this page tracks reality, it doesn't lag it. For material changes to how we handle your email or license record, we'll tell you in the app or by email before they take effect.