Privacy
What this platform actually stores — derived from its own source, not a template.
This is an accurate technical description of system behaviour, not legal advice. Have a professional review it before commercial operation.
What is stored
- Account data — the name, email and avatar supplied by your sign-in provider (GitHub or Google), plus the username generated for you.
- Sessions — a session token in the database and a matching cookie. Not used for tracking.
- What you publish — component source, descriptions and tags. Public by nature.
- Engagement — likes and bookmarks, tied to your account.
- Copy events — to enforce the free daily quota and the install counter. For signed-out visitors a SHA-256 hash of the IP and user agent is stored, never the address itself.
What is not stored
- No passwords — sign-in is provider-based only.
- No payment details on our servers.
- No advertising trackers, no third-party analytics.
Third parties you touch as a user
Previews compile in your browser, so your browser fetches npm packages from esm.sh and build tooling from jsDelivr. Those services see your IP address, as any CDN would. None of your data passes through them.
Hosting
The application and its database run on a single server operated by whoever runs this instance. Data is not shared with a third-party cloud provider.
Deletion
You can request deletion of your account and everything attached to it. Deleting an account removes your sessions, likes, bookmarks and published components.