Privacy Policy
What widget.diy collects, what we deliberately don't, who processes data on our behalf, retention, and your rights — in plain language.
2026-09-12
Effective date: 2026-09-12. Questions or requests: [email protected] (we answer within 30 days). The legal contract is the Terms of Service.
Our design rule: if data can stay in your browser, it never reaches our servers. Cropping happens in your browser; your login token lives in your browser's local storage, not in our cookies.
What we do NOT do
- We do not sell or rent personal data, to anyone, for any purpose.
- We do not use your data for advertising or cross-site profiling.
- We do not read or inspect your widget content (including custom HTML source) except when you ask for support or when moderation of the public plaza requires it.
- We do not see or store payment card numbers — checkout runs entirely at Dodo Payments.
- We do not track you across other websites.
What we collect
Account
- Email + password hash (we never store the password itself), or
- name, email and avatar image if you sign in with Google or Notion.
Your widgets and their storage
- Title, description, target page URL, crop region or HTML source, configuration values.
- For plaza-published widgets: the editorial story text. Plaza content (title, description, story, author name) is public by design.
- Key-value data (KV) that custom HTML widgets read and write through our embed bridge — including data written by visitors of pages where a widget is embedded. The widget author controls what their widget stores; embed visitors can clear it by clearing the host page's site data.
Logs, counters and analytics
- Aggregate counters: widget page views and reuse counts (counters, not per-visitor logs).
- Standard hosting logs (IP, user agent, timestamps) kept by Cloudflare and Google Cloud Run for security, ~30 days.
- Google Analytics 4 (GA4) page-view analytics on widget.diy and embed.widget.diy, with cookies (e.g.
_ga). No ad use, no cross-site profiling.
Payments and email
- Membership status and expiry (the purchase outcome). Dodo Payments handles cards and invoices.
- Your email, used only for transactional messages (magic links, receipts) via Brevo / Resend.
Why we collect it (legal bases)
- Contract: running your account, widgets, embeds, plaza and membership.
- Legitimate interest: security, rate limiting, human checks (Cloudflare Turnstile), debugging.
- Consent: analytics cookies — withdraw anytime by blocking cookies; the site keeps working.
Who processes data on our behalf
| Service | Purpose | Data it sees |
|---|---|---|
| Cloudflare | CDN, protection, human checks, static hosting | request logs, IPs |
| Cloud Run hosting, GA4 analytics, optional sign-in | request logs, analytics events, OAuth profile (if used) | |
| Turso | database hosting | account + widget data |
| Upstash | cache and rate limiting | counters, session rate-limit keys |
| Brevo / Resend | transactional email | your email address |
| Dodo Payments | checkout and invoicing | payment details (we never see cards) |
| Notion | optional Notion sign-in | OAuth profile (only if you choose it) |
Each acts as a processor under its own privacy terms and data-processing agreements. We share nothing beyond this table.
Where data lives
API in Singapore, database in Tokyo, static assets on Cloudflare's global edge; the processors above operate in the US/EU/Asia. For EU/UK users this is a cross-border transfer; we rely on the processors' standard contractual clauses or equivalent safeguards (e.g. EU–US Data Privacy Framework where applicable).
How long we keep it
- Account and widgets: until you delete them or request account deletion.
- Plaza content: until unpublished or removed by curation.
- KV data: until the owning widget is deleted.
- Logs ~30 days; analytics per GA4 retention (aggregate); billing records as law requires.
Your rights — and how to exercise them
- Access / export: email us; we reply with your account data and widget JSON.
- Correct: edit titles, descriptions and settings in your dashboard, or email us.
- Delete: delete widgets in your dashboard; email us to delete your account and everything in it.
- Withdraw consent (analytics): block cookies or use a blocker; nothing breaks.
- Complaint (EU/UK): lodge it with your supervisory authority — though we'd appreciate a chance to fix things first.
We may verify ownership before acting. Response within 30 days, at [email protected].
Children
Not directed to children under 13. If we learn we hold data of a child under 13 without verifiable parental consent, we delete it.
Security
Hashed passwords, TLS everywhere, short-lived API tokens, restricted admin access, rate limiting. No system is 100% secure; we apply reasonable, industry-standard care.
Changes
The effective date at the top of this page changes with each revision; material changes affecting accounts are also announced by email where we have one. Continued use after a change means acceptance.