1. Controller and scope
Publishto is the controller of account and product-usage information described here. This Policy applies to publishto.host, the authenticated dashboard, and Publishto’s hosting API. Privacy requests are available through the Privacy and Account section of the signed-in dashboard.
2. Data we collect
Private account data
We collect your email address, authentication identifiers, session and security information, dates of legal acceptance, and essential records needed to associate published assets with your account.
Public content
Files, website code, titles, chosen subdomains, and custom domains you publish are public internet content, not private storage. Anyone may access, copy, index, archive, or redistribute them while they are available. Do not upload personal, confidential, regulated, or sensitive data.
Analytics data
If Google Analytics is configured and you choose “Allow analytics,” Google may receive device/browser information, approximate location derived from network information, page URLs, referrers, interactions, and similar usage events. Publishto does not send account email or uploaded-file contents to Google Analytics and does not enable advertising personalization through its analytics configuration.
3. Why and on what basis we process data
- Contract: account email, authentication, asset ownership, publishing, editing, and deletion are processed to provide the service you request.
- Legitimate interests: limited logs and security signals may be processed to prevent fraud, abuse, malware, and service attacks, balanced against user rights.
- Consent: Google Analytics loads only after affirmative consent. You may decline or withdraw consent without losing core publishing functionality.
- Legal obligation: information may be preserved or disclosed when legally required.
4. Retention and deletion
- Published R2 files and public routing records are permanently deleted after 48 hours, or sooner when you delete them.
- Expired asset metadata may remain in the dashboard for up to 30 days so you can understand what expired, after which it may be removed.
- Your account email and acceptance records remain while the account is active and are deleted when you use account deletion, subject to narrowly applicable legal or security retention duties.
- Authentication and infrastructure providers may retain short-lived security, delivery, and audit logs under their documented retention schedules.
- Analytics retention is controlled in the Google Analytics property and should be configured to the shortest period needed for aggregate product measurement.
5. Service providers and international processing
Publishto uses Vercel for the application interface, Cloudflare for public file delivery and storage, Supabase for authentication and account metadata, and Google Analytics only after consent and configuration. These providers may process data in multiple countries and use contractual or legal safeguards for international transfers.
6. Sharing, sale, and advertising
Publishto does not sell personal information. Publishto does not share personal information for cross-context behavioral advertising and does not use uploaded assets for advertising profiles. Public assets are disclosed at your direction because public hosting is the service’s purpose.
7. Your EEA, UK, and similar privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data and may withdraw analytics consent. You may also lodge a complaint with your local data-protection authority. The dashboard provides access to asset records, editing, deletion, account deletion, and analytics choices.
8. United States state privacy rights
Applicable US state laws may provide rights to know or access, delete, correct, obtain a portable copy, opt out of sale or targeted-advertising sharing, limit certain sensitive-data use, and receive non-discriminatory service. Publishto voluntarily provides account deletion and consent controls even where a particular law’s business thresholds do not apply. Publishto does not sell personal information or offer targeted advertising.
9. California notice at collection
Categories collected are identifiers (email and account ID), internet or electronic activity (security and consented analytics events), and customer records (asset ownership and legal acceptance). Purposes are authentication, service delivery, security, compliance, and consented analytics. Publishto does not sell or share these categories for cross-context behavioral advertising. Retention is described in Section 4.
10. Security
Publishto uses HTTPS, Supabase authentication, row-level ownership controls, server-side service credentials, R2/KV isolation, file-type restrictions, path-traversal checks, and automatic deletion. No internet service can guarantee absolute security, and public asset content should be treated as disclosed.
11. Children
Publishto is not directed to children and does not knowingly collect children’s personal data. Do not use the service if you are below the age required to consent to online services in your jurisdiction.
12. Changes and requests
Material updates will be identified by a new effective date and version. Use the authenticated dashboard to review, edit, export where available, or delete account and asset information. You may also contact the relevant supervisory or consumer-protection authority.