We don't use tracking cookies, third-party advertising scripts, or fingerprinting. Your visitors are never tracked across the web. Our analytics use privacy-friendly, daily-rotating hashes that can't identify individuals.
Your data is yours. We don't sell it, share it with advertisers, or use it for any purpose other than delivering your website. We're a website platform, not an ad company.
We honor Global Privacy Control (GPC) signals sent by your browser. When detected, we respect your preference automatically — no pop-ups, no cookie banners, no dark patterns.
All data is encrypted in transit with TLS and at rest with industry-standard encryption. Passwords are hashed with per-user salts. API keys are stored in dedicated secrets management. Your data is protected at every layer.
We only collect what's needed to run your website. Analytics store pseudonymized hashes that rotate daily — we never store raw IP addresses for analytics. Sessions expire after inactivity.
We publish our complete list of subprocessors and our Data Processing Addendum, and share our Transfer Impact Assessment on request. No surprises, no hidden third parties, no fine-print data sharing.
For EU customers, we go beyond compliance. Your visitors' data stays in Europe.
When you're identified as an EU-resident website operator, we automatically apply strict data residency measures. Your visitor data — form submissions, sessions, and user records, including any conversations your site's own chatbot keeps — is stored exclusively within EU data centers and processed there, except AI requests your site makes and automated spam screening of form submissions, which are processed outside the EU.
Visitor data stored exclusively in EU data centers
Your website email delivery is processed in the EU (Stockholm)
Content submission notifications routed through EU infrastructure
Jurisdictional storage restrictions via Cloudflare's EU jurisdiction API
Full compliance with the EU General Data Protection Regulation, including appointed Art. 27 representative in the EU.
Compliant with the UK General Data Protection Regulation, with an appointed representative in the United Kingdom.
Compliant with the EU Digital Services Act, including content moderation and transparency reporting obligations.
We act as a CCPA service provider and never sell or share personal information for advertising purposes.
Compliant with Canada's Personal Information Protection and Electronic Documents Act, with contractual protections for cross-border transfers.
Compliant with Switzerland's Federal Act on Data Protection, with appropriate transfer mechanisms in place.
Enterprise-grade protection via Cloudflare shields every website from attacks.
Each website runs in its own isolated sandbox with dedicated storage.
Proof-of-work challenges prevent automated abuse without CAPTCHAs.
Every website gets free SSL/HTTPS with automatic certificate management.
AI-powered spam detection protects your forms without degrading user experience.
Custom code runs in WebAssembly-based sandboxes — fully isolated from other websites.
Privacy Policy
How we collect, use, and protect your personal information.
Data Processing Addendum
Detailed terms for how we process visitor data on your behalf, including subprocessor lists and security measures.
Terms of Service
The full terms governing use of the platform.
Agency Terms
Additional terms for agencies managing client websites on the platform.
Refund & Cancellation Policy
How cancellations, refunds, and plan changes work.
Acceptable Use Policy
Guidelines for appropriate use of the platform.
Digital Services Act Disclosures
Our transparency disclosures, content moderation policies, and points of contact under the EU Digital Services Act.