Privacy

Privacy statement

Last updated: October 1, 2026

This statement explains which personal data Sitekiln processes when you sign in and work with it, why, who receives it and what your rights are. It covers Sitekiln itself, not the websites you build with it: whoever publishes a website is responsible for that website's own privacy statement.

Who is responsible

The controller for the personal data in this statement is:

Name
Sitekiln
Address
Helenalei 24, 2018 Antwerpen
Company number
BE 0123.456.789
E-mail
azomo.tom@proton.me

What we process

Your account

Your user name, your password (only as a one-way hash that nobody can turn back into the password), your role, your model profile and webshop right, and when the account was created and last changed. Accounts are created by the operator; you cannot sign up yourself.

Your projects

Everything you put in a project: your instructions and chat, the generated pages, business details (which can include names, addresses, phone numbers and e-mail addresses), brand colours and fonts, the site address and statistics code, and the files you upload - photos, videos, audio and PDFs - with the descriptions made of your photos.

Websites you read in

When you give a web address, for a redesign or as a source, our server fetches that page and keeps the text and photos you choose in your project.

Generation log

For every call to a model: the time, your account, the project, the model and the host that ran it, the number of tokens, the cost, the duration, the result and any error message; for a project's first generation also the business details, brand kit and any chat service found on the old website it ran with.

Running generations

The text of a generation as it arrives, with your instruction, so that an interrupted generation can be resumed.

Feedback

When you send a report: your user name, the kind of report, your message and the address of the page you were on.

Sign-in attempts

Failed sign-ins are counted per IP address and per user name, only in the server's memory.

Server log

Technical messages in the server's log, such as an error that names a project.

Cookies and storage in your browser

Sitekiln sets one cookie, and no advertising or tracking cookies:

Cookie
sitekiln_session
Purpose
Keeps you signed in. Strictly necessary, so it needs no consent. Scripts cannot read it, and it only goes to Sitekiln itself.
Kept for
12 hours, or 30 days with “Keep me signed in”

Sitekiln also keeps a few things in your browser's own storage. They stay on your device; our server does not read them:

  • your language
  • light or dark mode
  • the model you chose
  • whether you have seen the tour
  • whether the chat panel is folded away, and each project's chat history
  • per project, whether to ask for a website address when you download it
  • until you close the tab: the draft of a new project

Visit statistics

To see how Sitekiln is used, we count visits with Umami, which runs on our own server. Umami sets no cookies, stores no IP addresses and sends nothing to another company.

It records the page address (without search terms or anything after #), the page you came from, your browser, operating system, device type, screen size and language, and the country, region and city that your IP address points to at the moment of the visit. To tell visits apart, it makes an anonymous code from your IP address, your browser and a value that changes every month.

If your browser sends “Do Not Track”, nothing is counted.

Why, and on what basis

  • To let you work in Sitekiln - your account, your projects, your generations: to provide the service agreed with you or your organisation (GDPR article 6(1)(b)).
  • To keep Sitekiln secure and working (the sign-in cookie, counting sign-in attempts, the server log) and to keep costs and quality in check (the generation log): our legitimate interest (article 6(1)(f)).
  • Visit statistics: our legitimate interest in improving Sitekiln (article 6(1)(f)), without cookies and without storing your IP address.

We do not use your data for advertising, do not sell it and do not build profiles.

Who receives data

To write texts, describe photos and transcribe audio, Sitekiln sends what that task needs - your instructions, project texts, text from pages you read in, the photos to describe, the audio - to the model services the operator has set up:

  • OpenRouter (openrouter.ai, United States). OpenRouter passes each request on to the company that runs the chosen model; that company can be outside the European Economic Area.

Your user name and password are never sent along. Put nothing in a project that the website does not need, and certainly no sensitive personal data such as health information.

Stock photos: to find photos for a page, our server sends only search words that describe them, to Pexels and Pixabay.

While you work, the preview of a site runs in your browser. Tailwind CSS and fonts come from our own server, which fetches a font from Google once, without you. Photos from other websites show as a neutral area while a generation runs, and stock photos until our server has stored them. Only what a page itself adds from elsewhere - sometimes a script library, an embedded map or a video - still loads from that service, which then sees your IP address.

When you download a site or export it to WordPress, our server fetches the fonts, photos and icons its pages still load from other websites (such as Google Fonts), so that the exported site loads nothing from elsewhere. Those websites see our server, not you.

Sitekiln and its database run on a server that the operator manages; no hosting company stores your data. Nobody else receives your data, unless the law requires it.

How long we keep it

  • Your account: as long as it exists. When the operator deletes it, everything goes with it: your projects with their files, your settings, your feedback, your running generations and your generation log.
  • Projects: until you delete them. Deleting a project removes it at once, together with its files, its photo descriptions and the copies of its details in the generation log.
  • Files for a new project that you never save: removed within 2 days.
  • Running generations: until 24 hours after you received them, or 7 days if they never reached you; they are removed at the next clean-up after that.
  • Generation log and feedback: deleted automatically after 2 years. The summary of a project's generations stays as long as the project does. Ask, and we delete what is about you sooner.
  • Failed sign-in attempts: at most 15 minutes, in memory only.
  • Server log: until the next update of the server software, which replaces it.
  • Visit statistics: until the operator removes them.

Your rights

You can ask to see your data, to correct or delete it, to restrict or object to its use, and to receive it in a usable format - you can already download any project as a zip file.

Send your request to azomo.tom@proton.me; we answer within one month.

Not satisfied with our answer? You can file a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be) or with the supervisory authority where you live.

How we protect it

Sitekiln is reached over an encrypted connection (HTTPS). Passwords are stored as a one-way hash, the sign-in cookie cannot be read by scripts, and after too many failed sign-ins further attempts are refused for a while. You see only your own projects; the operator can see all projects, to manage Sitekiln and to help you.

Changes

When this statement changes, the date at the top changes with it.

Back to Sitekiln