Privacy Policy
Last Updated: January 2025
Effective Date: January 2025
1. Introduction
OnePage AI Builder ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, password (encrypted), name (optional)
- Project Data: Website content, block configurations, color customizations
- Payment Information: Processed by Stripe; we don't store card details
- Communications: Support requests, feedback, inquiries
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent
- Device Information: Browser type, operating system, IP address
- Cookies: Authentication tokens, preferences, analytics
- localStorage: Auto-save backups, session data
2.3 Third-Party Information
- GitHub: Account info when you authorize GitHub deployment
- Stripe: Payment verification for subscriptions
- AI Service: Content generation requests (anonymized)
3. How We Use Your Information
We use collected information to:
- Provide Services: Enable website building, save projects, process payments
- Improve Platform: Analyze usage patterns, fix bugs, develop features
- Communication: Send updates, respond to support requests
- Security: Protect against fraud, unauthorized access, abuse
- Compliance: Meet legal obligations, enforce terms
- Analytics: Understand how our service is used (anonymized)
4. Data Storage and Security
4.1 Where We Store Data
- Supabase: User accounts, project data (PostgreSQL database)
- Your Browser: localStorage for auto-save backups
- Stripe: Payment and subscription data
4.2 Security Measures
- Passwords encrypted with bcrypt
- HTTPS encryption for all data transmission
- Row-level security (RLS) in Supabase
- Regular security audits and updates
- Access controls and authentication
4.3 Data Retention
- Active Accounts: Data retained while account is active
- Deleted Accounts: Data permanently deleted within 30 days
- Backups: May persist in backups for up to 90 days
- localStorage: Cleared after successful save or 24 hours
5. Data Sharing and Disclosure
We do not sell your personal data. We may share information with:
5.1 Service Providers
- Supabase: Database and authentication hosting
- Stripe: Payment processing
- AI Provider: Content generation (anonymized requests)
- GitHub: When you use deployment features
5.2 Legal Requirements
We may disclose information if required to:
- Comply with legal obligations or court orders
- Protect our rights and property
- Prevent fraud or security threats
- Protect user safety
5.3 Business Transfers
If we merge, are acquired, or sell assets, user data may be transferred. We'll notify you of any such changes.
6. Your Rights and Choices
6.1 Access and Control
- Access: View all your data in the dashboard
- Correction: Update account information anytime
- Export: Download your projects as ZIP files
- Deletion: Delete projects or your entire account
6.2 Communication Preferences
- Opt out of marketing emails (account emails still sent)
- Manage notification preferences in account settings
6.3 Cookie Controls
- Required cookies: Essential for authentication and security
- Optional cookies: Can be controlled via browser settings
- localStorage: Can be cleared via browser settings
7. Cookies and Tracking
7.1 Types of Cookies
- Essential: Authentication, security, session management
- Functional: Remember preferences, auto-save data
- Analytics: Understand how the platform is used
7.2 Third-Party Cookies
- Stripe: Payment processing
- GitHub: OAuth authentication
7.3 localStorage
We use browser localStorage to:
- Auto-save your work every time you make changes
- Restore your work if you refresh the page
- Store session information for 24 hours
- Data is stored only on your device, not on our servers until you save
8. Children's Privacy
Our service is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it immediately.
9. International Data Transfers
Your data may be stored and processed in any country where we or our service providers operate. By using our service, you consent to such transfers. We ensure appropriate safeguards are in place to protect your data.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by:
- Posting the new policy on this page
- Updating the "Last Updated" date
- Sending an email for material changes (if you're subscribed)
Continued use after changes constitutes acceptance of the new policy.
11. Data Protection Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
- Right to Access: Request a copy of your data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a usable format
- Right to Object: Object to certain processing activities
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@onepageai.builder
12. California Privacy Rights (CCPA)
California residents have additional rights:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Opt-out of the sale of personal information (we don't sell data)
- Access personal information
- Request deletion of personal information
- Non-discrimination for exercising privacy rights
13. Contact Us
For questions about this privacy policy or our data practices:
- Email: privacy@onepageai.builder
- Support: Contact Page
- GitHub: Open an Issue
14. Your Consent
By using OnePage AI Builder, you consent to this privacy policy and our processing of your information as described herein.