Back to all posts

Privacy Policy

What widget.diy collects, what we deliberately don't, who processes data on our behalf, retention, and your rights — in plain language.

2026-09-12

Effective date: 2026-09-12. Questions or requests: [email protected] (we answer within 30 days). The legal contract is the Terms of Service.

Our design rule: if data can stay in your browser, it never reaches our servers. Cropping happens in your browser; your login token lives in your browser's local storage, not in our cookies.

What we do NOT do

  • We do not sell or rent personal data, to anyone, for any purpose.
  • We do not use your data for advertising or cross-site profiling.
  • We do not read or inspect your widget content (including custom HTML source) except when you ask for support or when moderation of the public plaza requires it.
  • We do not see or store payment card numbers — checkout runs entirely at Dodo Payments.
  • We do not track you across other websites.

What we collect

Account

  • Email + password hash (we never store the password itself), or
  • name, email and avatar image if you sign in with Google or Notion.

Your widgets and their storage

  • Title, description, target page URL, crop region or HTML source, configuration values.
  • For plaza-published widgets: the editorial story text. Plaza content (title, description, story, author name) is public by design.
  • Key-value data (KV) that custom HTML widgets read and write through our embed bridge — including data written by visitors of pages where a widget is embedded. The widget author controls what their widget stores; embed visitors can clear it by clearing the host page's site data.

Logs, counters and analytics

  • Aggregate counters: widget page views and reuse counts (counters, not per-visitor logs).
  • Standard hosting logs (IP, user agent, timestamps) kept by Cloudflare and Google Cloud Run for security, ~30 days.
  • Google Analytics 4 (GA4) page-view analytics on widget.diy and embed.widget.diy, with cookies (e.g. _ga). No ad use, no cross-site profiling.

Payments and email

  • Membership status and expiry (the purchase outcome). Dodo Payments handles cards and invoices.
  • Your email, used only for transactional messages (magic links, receipts) via Brevo / Resend.
  • Contract: running your account, widgets, embeds, plaza and membership.
  • Legitimate interest: security, rate limiting, human checks (Cloudflare Turnstile), debugging.
  • Consent: analytics cookies — withdraw anytime by blocking cookies; the site keeps working.

Who processes data on our behalf

ServicePurposeData it sees
CloudflareCDN, protection, human checks, static hostingrequest logs, IPs
GoogleCloud Run hosting, GA4 analytics, optional sign-inrequest logs, analytics events, OAuth profile (if used)
Tursodatabase hostingaccount + widget data
Upstashcache and rate limitingcounters, session rate-limit keys
Brevo / Resendtransactional emailyour email address
Dodo Paymentscheckout and invoicingpayment details (we never see cards)
Notionoptional Notion sign-inOAuth profile (only if you choose it)

Each acts as a processor under its own privacy terms and data-processing agreements. We share nothing beyond this table.

Where data lives

API in Singapore, database in Tokyo, static assets on Cloudflare's global edge; the processors above operate in the US/EU/Asia. For EU/UK users this is a cross-border transfer; we rely on the processors' standard contractual clauses or equivalent safeguards (e.g. EU–US Data Privacy Framework where applicable).

How long we keep it

  • Account and widgets: until you delete them or request account deletion.
  • Plaza content: until unpublished or removed by curation.
  • KV data: until the owning widget is deleted.
  • Logs ~30 days; analytics per GA4 retention (aggregate); billing records as law requires.

Your rights — and how to exercise them

  • Access / export: email us; we reply with your account data and widget JSON.
  • Correct: edit titles, descriptions and settings in your dashboard, or email us.
  • Delete: delete widgets in your dashboard; email us to delete your account and everything in it.
  • Withdraw consent (analytics): block cookies or use a blocker; nothing breaks.
  • Complaint (EU/UK): lodge it with your supervisory authority — though we'd appreciate a chance to fix things first.

We may verify ownership before acting. Response within 30 days, at [email protected].

Children

Not directed to children under 13. If we learn we hold data of a child under 13 without verifiable parental consent, we delete it.

Security

Hashed passwords, TLS everywhere, short-lived API tokens, restricted admin access, rate limiting. No system is 100% secure; we apply reasonable, industry-standard care.

Changes

The effective date at the top of this page changes with each revision; material changes affecting accounts are also announced by email where we have one. Continued use after a change means acceptance.