In short
- You create an account, describe your business, and we generate a website you edit and publish. Each of those steps involves a different set of data, and this policy is organised the same way.
- The description you write is sent to an AI provider to generate your website. Payments go to Stripe, which handles your card; we never see it. Sign-in is handled by Clerk.
- You can edit your details, delete a website, or delete your whole account from the dashboard at any time.
- This summary is here so the page is readable. The sections below are the policy.
Jump to a section
- Introduction
- Information we collect
- How we use information
- Accounts and authentication
- AI generation and what you write
- Websites you publish
- Uploads and images
- Contact forms and email
- Payments and billing
- Domains
- Cookies and analytics
- Service providers and sharing
- International transfers
- How long we keep things
- Security
- Your rights and choices
- Children
- Changes to this policy
- Contact us
Introduction
Instantsite is a service for generating, editing and publishing a website from a description of your business. This policy explains what personal information the service handles, why, and what you can do about it. It covers instantsite.app, the dashboard and editor, and the websites published on instantsite.app addresses and on connected custom domains.
It does not cover what visitors do on a website you publish, or the information you choose to collect through it. You decide what goes on your website and what you ask your visitors for (see Websites you publish).
Questions about this policy or requests concerning your personal data can be sent to accountassistance@instantsite.app.
Information we collect
Everything below is either something you gave us, something a provider sent us about your account, or something the service recorded while you used it.
- Account details
- Your email address, and the username, name and profile image held by your sign-in provider. You can add a short bio. New accounts are also given a reserved address on instantsite.app.
- Approximate location and IP address
- When you sign up and each time a session starts or ends, we record the IP address reported by the sign-in provider and look up the approximate country and city it belongs to. This is kept on your account and in a sign-in log.
- What you write for the generator
- The description of your business, and anything you supply during generation and editing: services, prices, opening hours, contact details, testimonials, addresses and phone numbers.
- Your websites
- The content of every website you create, both the draft you are editing and the published snapshot, along with its pages, navigation, images, logo, search metadata, plan of what the generator built and why, and the address it is published at.
- Files you upload
- Images, logos and favicons, stored with the website they belong to.
- Billing details
- On a paid plan: your plan, billing cycle, subscription status and period dates, the identifiers of your customer and subscription records at our payment provider, and a record of each invoice: number, amount, currency, date, status and a link to the invoice hosted by the provider. Card numbers never reach our servers.
- Domains
- Domains you buy or connect: the domain name, when it was registered and when it expires, whether auto-renew is on, the DNS records used to verify it, and the prices involved.
- Messages you send us
- What you write in a contact or support form (your name, email, an optional company name, the topic and your message) plus anything you attach to it in the text. Feedback submitted through the feedback page is stored with your name, email, message and rating.
- Generation records
- For each website we generate: which stage ran, whether it succeeded, how long it took, which model was used, how many tokens it consumed, and any error code. These records identify your account but do not store the text of your description.
- Usage and analytics
- Only if you agree to it: pages viewed, referrer, device and browser, approximate location. Nothing is collected until you turn Analytics on, and we ask before anything loads. See Cookies and analytics.
- Account acquisition
- If you allow Marketing storage, arrive through a link carrying a source label and optional medium or campaign labels, and then create an account, we store those validated labels with the account once so we can understand where new registrations originated. Later visits do not replace that first-touch record.
How we use information
- To create your account and keep you signed in.
- To generate a website from your description, and to keep it editable and publishable afterwards.
- To host your website and serve it to visitors at the address you publish it on.
- To register, verify and renew domains you buy or connect.
- To take payment, issue invoices, apply the right tax treatment, and manage upgrades, downgrades and cancellations.
- To answer your messages, and to send service email about your account, your websites and your billing.
- To enforce plan limits, detect abuse of the free tier and the public forms, and keep the service working.
- To understand which parts of the product are used and where generation fails, so it can be improved.
- To understand which consented campaigns and directories lead to new account registrations.
- To meet our accounting and tax obligations, and to respond to lawful requests.
We do not use the content of your websites, your descriptions or your messages to advertise to you.
Accounts and authentication
Sign-up, sign-in, passwords, two-factor authentication and social sign-in are handled by Clerk, our authentication provider. Your password is set and stored with Clerk and is never sent to us or visible to us.
Clerk tells us when an account is created, changed or deleted, and when a session starts or ends. From those messages we store your email, username, name, profile image and account creation date, and we write a sign-in log entry containing the session identifier, the IP address, the approximate country and city, and the timestamps.
The country and city are not taken from the browser. We send the IP address to a geolocation service, which returns an approximate location.
The sign-up and sign-in forms, and the careers application form, run a bot check from Cloudflare Turnstile. Completing it sends a challenge token and your IP address to Cloudflare.
AI generation and what you write
Instantsite builds your website by sending what you write to a large language model. The models we use are Anthropic Claude models hosted by Google Cloud on Vertex AI, accessed through our own Google Cloud project.
What is sent to the model:
- The description of your business, exactly as you wrote it.
- Details drawn from it or supplied by you during generation: what you offer, who it is for, where you work, your goal, contact details and any other information you provide.
- Text you ask the editor to rewrite or regenerate.
- The text used to detect which language you wrote in.
The output (your pages, the plan of what was built, the detected industry and the primary goal) is stored on your website record so you can edit and republish it. We also keep a technical record of each generation run: the stage, whether it succeeded, how long it took, the model name, token counts and any error code. That record identifies your account but does not contain your description.
We do not use your descriptions or your website content to train models of our own. What the AI provider does with data sent to its service is governed by the agreement between us and that provider, not by this policy; we cannot make a promise here on their behalf, and we do not.
Websites you publish
A website you publish is public. It typically carries your business name, what you sell, prices, photos, opening hours, an address, a phone number and an email. It may also carry testimonials or details about other people. You decide what goes on it.
You are responsible for the legality and accuracy of what you publish, for having the right to publish it, and for any personal information you collect from your visitors through it, including telling those visitors what you do with it. If your website collects personal information, you are likely to need your own privacy notice on it. The generator does not write one for you.
- Draft and published copies
- We keep the version you are editing and a separate snapshot of what is live. Private settings are removed from the published snapshot: the address your contact form delivers to, for example, is stored on the draft and never included in the public copy.
- Contact form submissions
- When a visitor submits the contact form on your website, the message is emailed to the address you configured. It is not stored in our database. Delivery uses our email provider and the recipient is looked up on our servers, never taken from the request.
- Newsletter sign-ups on your website
- If a visitor subscribes through your website, we store their email address against that website so you can reach them. Those addresses belong to your relationship with your visitors, and you are responsible for how you use them.
- Visitor analytics
- Published websites on the Premium plan are given a Google Analytics property so you can see traffic. When one exists, the website loads Google Analytics and your visitors' data is processed by Google. Websites without one load no analytics tag from us.
Uploads and images
Images, logos and favicons you upload are stored in Google Cloud Storage, filed under your account and the website they belong to, and served from our content delivery network. File type and extension must match and must be on our allow-list, and the file size limit depends on your plan.
Uploaded files are served from a public URL so they can appear on your website. Anyone with the URL can open the file, whether or not the website is published, so please do not upload documents or images you need to keep private.
Stock photography comes from Pexels. When you search for a photo in the editor, the search term is sent to Pexels; the results are delivered from their servers and the photos remain subject to the Pexels licence.
Deleting a website deletes the files stored for it.
Contact forms and email
The contact, support and careers forms on this site do not save your message to our database. Each one renders your submission as an email and sends it, through our email provider, to the team mailbox for that kind of request:
- Company inquiries (sales, partnerships, press, feedback) go to hello@instantsite.app.
- Technical support goes to techsupport@instantsite.app.
- Account and billing help goes to accountassistance@instantsite.app.
- Job applications sent through the careers application form go to careers@instantsite.app.
The reply address on that email is yours, so a reply goes straight back to you. The message then lives in that mailbox, and in your own, for as long as we keep our correspondence; we have not set a fixed deletion period for support email, and we do not want to state one we do not enforce. Ask us to delete a thread and we will.
A job application is handled the same way and is worth stating separately. The form at /careers/apply emails us your name, your email address, the role you are applying for, whatever optional details you fill in (location, availability, links to your work) and what you write in the message. It is not stored in our application database, and we use it to evaluate your application and to reply to you about it. The form does not accept file uploads, so please send links rather than attaching a CV.
Feedback submitted through the feedback page is different: it is stored in our database with your name, email, message and rating, so that it can be reviewed and, if you allow it, published.
We send service email: sign-in and account messages from our authentication provider, billing email from our payment provider, and notifications about your websites and domains. Marketing email is separate and always has an unsubscribe link; you can also switch account email off in your dashboard settings.
Payments and billing
Payments are processed by Stripe. You enter your card on Stripe’s own checkout page. We never receive, see or store your card number. What we store is your Stripe customer and subscription identifiers, your plan and billing cycle, your subscription status and period dates, and a record of each invoice.
Stripe calculates the tax that applies where you are, and you can add a business tax ID during checkout. Stripe holds your billing address, your payment method and your tax ID; we see the invoice totals and status, not the card.
When an invoice is paid, we send the details needed to issue an accounting document (your name, email, tax number if you gave one, billing address, country and the amount) to Elorus, our invoicing provider, which issues the invoice or receipt. A refund creates a matching credit note the same way.
Invoices remain available in your dashboard while your account exists, and are held by our payment and invoicing providers under the retention rules that apply to accounting records.
Domains
Domains bought through Instantsite are registered with Name.com, our registrar. We send them the domain name to check availability, to register it and to renew it. Registration and renewal records are held by the registrar and by the registry for that domain ending, and some of that information may appear in public registration records under the rules of the registry.
For a domain you already own and connect yourself, we store the domain name and the DNS records used to verify control of it, and we configure our content delivery network to serve your website at that address. Verifying a domain requires you to add records at your own DNS provider; what that provider records about you is between you and them.
Auto-renew for a domain bought here is handled as a separate subscription with our payment provider, and can be switched off in your dashboard.
Service providers and sharing
We do not sell personal information and we do not share it for anyone else’s advertising. We do use other companies to run the service. Each one only gets what it needs for its part of it.
| Provider | What it does for us | What it handles |
|---|---|---|
| Clerk | Accounts, sign-in, sessions, passwords, two-factor | Email, name, username, profile image, session and device details |
| Google Cloud | Application hosting, database, networking and delivery of published websites | Account data, website data and other information stored by the service |
| Google Cloud Storage | Storing the images, logos and favicons you upload | Your uploaded files and their file names |
| Google Cloud Vertex AI | Generating and rewriting website content using supported AI models | Your description and the business details you supply |
| Stripe | Checkout, subscriptions, invoices, tax calculation | Name, email, billing address, tax ID, payment method, amounts |
| Elorus | Issuing invoices, receipts and credit notes | Name, email, tax number, billing address, country, amount |
| Mailjet | Sending contact, support, notification and marketing email | Your email address, name and the content of the message |
| Name.com | Registering and renewing domains bought through Instantsite | The domain name and its registration records |
| Analytics and advert measurement on instantsite.app, only with your consent; traffic analytics for published websites | Cookie identifiers, pages viewed, approximate location, device, referrer | |
| TikTok | Advert measurement on instantsite.app, only with your consent | Pixel identifiers |
| Cloudflare | The bot check on the sign-up and sign-in forms | A challenge token and your IP address |
| Pexels | Stock photo search and delivery | Your search terms |
| ipapi.co | Turning a sign-in IP address into an approximate country and city | Your IP address |
Each of these companies publishes its own privacy notice covering what it does with the data it holds.
We may also disclose information where the law requires it, to enforce our Terms of Service, to investigate abuse or fraud, or to protect someone’s safety. If the business is ever sold or merged, account information would transfer with it, and we would say so here first.
International transfers
The providers listed above operate internationally, so information about you is processed in more than one country, including outside the country you live in. We do not claim that your data stays in a single country or region, because it does not.
Where a transfer needs a legal mechanism, we rely on the terms and safeguards each provider offers for that purpose.
How long we keep things
We keep your information while your account exists. Rather than quote a number of days we do not enforce, here is what actually triggers a deletion.
- Unpublish a website
- It comes off its public address immediately. The content stays in your account so you can republish it.
- Delete a website
- The website, its content, its published snapshot and the files uploaded for it are deleted.
- Delete your account
- From Settings in your dashboard, after typing a confirmation phrase. Active subscriptions are cancelled, your account record is deleted along with your websites, domains, invoice records and feedback, and your account at our authentication provider is deleted too.
If you want your uploaded files gone as well, delete your websites before you close your account; that is the path that clears the file storage.
Security
Concretely, and only what is true:
- Traffic to instantsite.app, to the dashboard and to published websites is served over HTTPS.
- Passwords and two-factor secrets are held by our authentication provider. We never receive them.
- Card details are entered on our payment provider’s pages and never reach our servers.
- Incoming webhooks from our authentication and payment providers are signature-verified before we act on them.
- Uploads are checked for type, extension and size before they are stored, so a renamed file cannot be served as something else from our domain.
- Private settings (such as the address your contact form delivers to) are removed from the published copy of a website.
- The public forms carry bot checks and rate limits, and the contact-form recipient is resolved on our servers so nobody can redirect it.
- Paid features are re-checked against the plan in our database on every request, not trusted from the browser.
None of this makes a system perfectly secure, and we will not claim it does. If you find a vulnerability, please tell us at techsupport@instantsite.app before disclosing it publicly.
Your rights and choices
Most of what you might want, you can do yourself:
- See and change your details
- Settings in your dashboard, and your profile with our authentication provider.
- Turn account email off
- A single switch in Settings, plus the unsubscribe link on any marketing email.
- Change or withdraw cookie consent
- Cookie Settings, at the bottom of any page. Withdrawing a category stops it loading again and deletes the first-party cookies it set (see the Cookie Policy).
- Take a website offline
- Unpublish it from the dashboard; it stops being reachable straight away.
- Delete a website and its files
- Delete it from the dashboard.
- Close your account
- Delete account, in Settings.
- Manage billing
- Invoices, payment method, plan changes and cancellation are all in Billing.
Depending on where you live, local data-protection law may also give you the right to ask for a copy of the information we hold about you, to have it corrected or erased, to restrict or object to how it is used, or to complain to your data-protection authority. Write to accountassistance@instantsite.app and we will handle the request. We may need to confirm who you are first, and we will tell you if there is something we are required to keep.
This policy makes no claim about certification or compliance status under any particular regime, and you should not read one into it. Privacy and data requests can be sent to accountassistance@instantsite.app.
Children
Instantsite is a business tool and is not directed at children. You need to be old enough to enter into a contract where you live in order to have an account (see the Terms of Service).
We do not knowingly collect information from children. If you believe a child has given us personal information, write to accountassistance@instantsite.app and we will delete it.
Changes to this policy
We update this policy when the product changes: a new provider, a new kind of data, a new way of handling it. The date at the top is the date of the current version.
For a change that materially affects how your information is handled, we will tell account holders by email or in the product before it takes effect, rather than relying on you noticing a new date.
Contact us
- Privacy, data and account requests
- accountassistance@instantsite.app
- Anything else about the company
- hello@instantsite.app, or the contact form.
- Problems with a website or the editor
- Contact support
Terms of Service
The rules of the service itself: plans and renewals, cancellation, what happens to your websites, domains and who is responsible for what.
Read the Terms of Service