Last updated: September 25, 2026
Swebsy is a local-first, browser-based website builder. This policy explains how Swebsy handles information when you visit swebsy.com, the template gallery, or the documentation, use Swebsy Studio, connect an AI service or coding agent, deploy a website, or use a Swebsy account and the paid cloud services — cloud sync, Swebsy Hosting, custom domains, and Swebsy Forms.
Swebsy Studio stores most project and app data on your device through browser storage, including PouchDB and IndexedDB, localStorage, and sessionStorage. This lets the core editor work without a server-side user account.
Local data may include:
This information leaves your device only when you choose an action that requires another service, such as an AI request, coding-agent task, image search, deployment, or cloud sync. Browser storage can be cleared or evicted, so export a project backup — or turn on cloud sync — before clearing site data or changing browsers or devices.
Studio works signed out, and an account is only needed for the paid cloud services. When you create one we store your name, your email address and whether it has been verified, a profile image if you sign in with Google or GitHub, and which version of the Terms and Privacy Policy you accepted and when — that last pair is what lets us tell you when these documents change.
Each sign-in creates a session record that stores the IP address and browser user-agent it was created from, so that you can review and revoke your own sessions and so we can investigate suspected account takeover. Sign-up is protected by Cloudflare Turnstile.
To keep free trials from being farmed, we record coarse signup provenance — the network operator your signup came from and a bot score supplied by Cloudflare — and, when a trial is claimed, a keyed one-way hash of your network prefix rather than your address. The hash is kept 90 days. This is a deliberate trade: it answers "how many trials has this network already taken?" without Swebsy keeping a log of IP addresses.
Transactional email — verification codes, billing notices, and form notifications — is delivered through Resend. Swebsy's own delivery logs record the recipient's domain rather than the full address.
If you have an account, we also send a small number of product emails — help getting started, feature tips, and trial and billing reminders — delivered through Cloudflare Email Service. Which email you get, and when, depends on your plan and billing status and on progress facts Studio reports while you are signed in: dates, counts, and categories, such as when you first created or published a site. These facts never include site content, page text, or prompts, and Studio stops reporting them if you decline analytics.
Every product email has a one-click unsubscribe link. Notices about your subscription and billing are still sent after you unsubscribe from the rest. If you reply, a person reads it: your reply is forwarded to the Swebsy team and pauses further product email to you for 14 days.
Cloud sync is an opt-in paid feature. Your browser stays the source of truth: sync uploads from it rather than turning it into a cache of our servers. When it is on, your project JSON and your uploaded asset bytes are stored in Cloudflare R2, and we hold the metadata needed to manage them — project names, sizes, checksums, version history, and timestamps.
We access the contents of your projects only as needed to operate the service, to act on a support request you make, or where the law requires it. We do not use your project content to train models, and we do not sell it.
When you publish to Swebsy Hosting or attach a custom domain, Swebsy serves the site to your visitors. Their requests are handled by Cloudflare and by our Worker, which process standard request data — IP address, browser and device headers, requested URL, request time, and security signals — to deliver the site and protect it from abuse. We can see request counts per hostname, which is how we monitor capacity and fair use.
For the personal information your published site itself collects from its visitors, you are the one who decides what is collected and why; Swebsy processes it on your behalf. Giving your visitors the right privacy notice and consent controls remains your responsibility.
If you enable a hosted form, Swebsy receives and stores what your visitor submitted, the page the form was submitted from, and the visitor's country as reported by Cloudflare. We deliberately do not store the visitor's IP address: the country is enough to spot an abuse wave, and an address log would turn every customer's inbox into a liability.
Submissions are delivered to the addresses you configure and are kept for 90 days; submissions quarantined as spam are kept 7 days and never delivered. You can read and delete submissions sooner from Studio. Because these are your visitors' details, telling them what you collect and why is your responsibility.
Payments are handled by Stripe. Card details are submitted to Stripe and never reach Swebsy's servers. We store the Stripe customer identifier for your account together with your plan, subscription status, and the dates on which it changed, which is what the app uses to decide what your account can do.
We keep an audit record of account and billing events — a subscription created, a trial started, a grace period expired — so that we can answer a billing question, prove what happened to an account, and meet accounting obligations.
When you visit Swebsy’s public site, documentation, or app, our hosting and security providers, including Cloudflare, may process standard request data. This can include your IP address, browser and device headers, requested URL, request time, and security signals.
This information is used to deliver the service, prevent abuse, diagnose failures, and protect Swebsy and its users. Swebsy does not use it to build advertising profiles.
Swebsy uses PostHog, through our own address at p.swebsy.com, to understand how swebsy.com, the template gallery, the documentation, and Studio are used and where they break, so we can fix and improve them. PostHog stores this data in the United States, under the safeguards it provides for transfers from the EU and UK. We ask once, with a short cookie notice, and your answer applies to all of them.
We still count visits and actions, and collect error reports and console output, but without cookies or anything else stored on your device for analytics. PostHog derives an identifier on its servers from your IP address and browser details, using a secret that changes every day, so it cannot follow you from one day to the next, and it does not keep your IP address. We do not record sessions or link activity to your account. Because nothing is stored, a visit that moves from swebsy.com to the docs or Studio may be counted as more than one visitor.
PostHog sets a first-party cookie on swebsy.com and its subdomains, with a matching copy in local storage, holding a random identifier and session details, so one visit across swebsy.com, the docs, and Studio counts as one visitor and keeps the page you first arrived from. In Studio it also enables:
Your answer is stored in a cookie named swebsy_cookie_consent on swebsy.com and its subdomains for one year, so you are asked once rather than on every site. Browsers that send Global Privacy Control or Do Not Track are treated as a no and are not asked.
Swebsy’s analytics events are built from an allowlist that leaves out project or page content, generated HTML or CSS, component trees, uploaded asset names, AI prompts or responses, deployment tokens, repository names, and custom code. Error messages and console output are captured as the app writes them, so they can occasionally include a fragment of that content, such as a page name in an error. We use them only to find and fix problems, and we do not intentionally log credentials.
Some account events are sent to PostHog by Swebsy's server rather than your browser, so they do not depend on the cookie notice: when you create an account, with your account ID, email address, name, and sign-up date; when your plan or subscription changes; when we send you a product email, fail to deliver it, or you reply, answer, or unsubscribe; and when you delete your account. When you delete your account we also remove your email address and name from PostHog.
You can change your answer at any time in Studio under Global settings → App preferences → Analytics cookie, or clear the swebsy_cookie_consent cookie in your browser to be asked again. A change applies from then on; it does not delete data already processed.
If you use Swebsy’s built-in AI, requests are sent from your browser to the provider you configure, such as Anthropic, OpenAI, or an OpenAI-compatible service. Your API key is stored locally. A request may include your prompt, relevant site or page context, selected content, recent chat history, and any image or screenshot you attach.
The optional PII sanitizer replaces some obvious email addresses, phone numbers, and similar text patterns before a request, but it cannot guarantee removal of all sensitive information. Text inside attached images is sent as-is. Do not submit personal, confidential, or regulated data unless you are comfortable sending it to your selected provider. That provider’s terms, privacy policy, and retention practices apply.
When you pair a coding agent, a local bridge on your device relays commands to the open Studio tab. The agent can receive the non-secret site content, settings, screenshots, and exports needed for the tasks you request. Your coding-agent provider may process that information under its own privacy policy.
Studio removes AI API keys, deployment tokens, AI chat history, and analytics settings from agent-visible settings. Agents are also blocked from changing credentials, deployment configuration, analytics scripts, security headers, and raw code-injection settings.
If you configure an Unsplash access key for AI-assisted image search, Swebsy sends the descriptive image query and access key to Unsplash. The selected image is then downloaded and stored with your local project. Unsplash’s terms and privacy policy apply.
If you deploy to GitHub Pages or Cloudflare Pages under your own account, Swebsy uses the credentials and configuration stored in your browser to call the service you selected. Those providers receive the files and account or repository details needed to complete the deployment, and their terms, privacy policies, security practices, and retention rules apply. Swebsy does not include deployment tokens or repository names in product analytics. Publishing to Swebsy Hosting is different — there Swebsy stores and serves the site itself, as described above.
Swebsy lets you export static websites and add analytics tags, tracking scripts, pixels, embeds, forms, custom code, or other third-party services. You control those additions. They are separate from Swebsy’s product analytics, and you are responsible for the privacy notices, consent controls, and other legal requirements that apply to the websites you publish.
Swebsy does not sell personal data. Information is shared only as needed for the service or action you choose, including with:
Local project data remains in your browser until you delete it, clear browser storage, or the browser removes it. On the cloud side we keep defined periods: a deleted cloud project and its assets are purged 90 days after deletion; up to three deployments per site are retained so you can roll back; form submissions are kept 90 days and submissions quarantined as spam 7 days; the trial-gate hash of a network prefix is kept 90 days; session recordings are kept 30 days; and a record that an account deletion completed is kept 30 days as proof the cleanup ran. Data sent to a third-party provider is retained under that provider's settings and policies. Swebsy may retain analytics and infrastructure logs for product improvement, security, troubleshooting, and legal obligations.
Swebsy uses technical and organizational safeguards intended to limit unauthorized access, disclosure, or loss. Uploads to Swebsy's servers cross an authenticated route with length and checksum verification, and administrative access requires a verified email address and an explicitly granted admin role. No browser storage, transmission, or third-party service can be guaranteed completely secure.
You can control much of the information described in this policy by:
Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to certain processing. Contact us to make a request. We may need enough information to verify the request, and pseudonymous data may not always be linkable to you.
We may update this policy as Swebsy, its providers, or applicable requirements change. We will revise the date above and provide an additional notice in the site or app when a change is material. If you hold a Swebsy account, we may ask you to accept the revised Privacy Policy and Terms the next time you sign in.
Questions or privacy requests can be sent to [email protected].