Privacy
Privacy statement
Last updated: October 1, 2026
This statement explains which personal data Sitekiln processes when you sign in and work with it, why, who receives it and what your rights are. It covers Sitekiln itself, not the websites you build with it: whoever publishes a website is responsible for that website's own privacy statement.
Who is responsible
The controller for the personal data in this statement is:
- Name
- Sitekiln
- Address
- Helenalei 24, 2018 Antwerpen
- Company number
- BE 0123.456.789
- azomo.tom@proton.me
What we process
Your account
Your user name, your password (only as a one-way hash that nobody can turn back into the password), your role, your model profile and webshop right, and when the account was created and last changed. Accounts are created by the operator; you cannot sign up yourself.
Your projects
Everything you put in a project: your instructions and chat, the generated pages, business details (which can include names, addresses, phone numbers and e-mail addresses), brand colours and fonts, the site address and statistics code, and the files you upload - photos, videos, audio and PDFs - with the descriptions made of your photos.
Websites you read in
When you give a web address, for a redesign or as a source, our server fetches that page and keeps the text and photos you choose in your project.
Generation log
For every call to a model: the time, your account, the project, the model and the host that ran it, the number of tokens, the cost, the duration, the result and any error message; for a project's first generation also the business details, brand kit and any chat service found on the old website it ran with.
Running generations
The text of a generation as it arrives, with your instruction, so that an interrupted generation can be resumed.
Feedback
When you send a report: your user name, the kind of report, your message and the address of the page you were on.
Sign-in attempts
Failed sign-ins are counted per IP address and per user name, only in the server's memory.
Server log
Technical messages in the server's log, such as an error that names a project.
Visit statistics
To see how Sitekiln is used, we count visits with Umami, which runs on our own server. Umami sets no cookies, stores no IP addresses and sends nothing to another company.
It records the page address (without search terms or anything after #), the page you came from, your browser, operating system, device type, screen size and language, and the country, region and city that your IP address points to at the moment of the visit. To tell visits apart, it makes an anonymous code from your IP address, your browser and a value that changes every month.
If your browser sends “Do Not Track”, nothing is counted.
Why, and on what basis
- To let you work in Sitekiln - your account, your projects, your generations: to provide the service agreed with you or your organisation (GDPR article 6(1)(b)).
- To keep Sitekiln secure and working (the sign-in cookie, counting sign-in attempts, the server log) and to keep costs and quality in check (the generation log): our legitimate interest (article 6(1)(f)).
- Visit statistics: our legitimate interest in improving Sitekiln (article 6(1)(f)), without cookies and without storing your IP address.
We do not use your data for advertising, do not sell it and do not build profiles.
Who receives data
To write texts, describe photos and transcribe audio, Sitekiln sends what that task needs - your instructions, project texts, text from pages you read in, the photos to describe, the audio - to the model services the operator has set up:
- OpenRouter (openrouter.ai, United States). OpenRouter passes each request on to the company that runs the chosen model; that company can be outside the European Economic Area.
Your user name and password are never sent along. Put nothing in a project that the website does not need, and certainly no sensitive personal data such as health information.
Stock photos: to find photos for a page, our server sends only search words that describe them, to Pexels and Pixabay.
While you work, the preview of a site runs in your browser. Tailwind CSS and fonts come from our own server, which fetches a font from Google once, without you. Photos from other websites show as a neutral area while a generation runs, and stock photos until our server has stored them. Only what a page itself adds from elsewhere - sometimes a script library, an embedded map or a video - still loads from that service, which then sees your IP address.
When you download a site or export it to WordPress, our server fetches the fonts, photos and icons its pages still load from other websites (such as Google Fonts), so that the exported site loads nothing from elsewhere. Those websites see our server, not you.
Sitekiln and its database run on a server that the operator manages; no hosting company stores your data. Nobody else receives your data, unless the law requires it.
How long we keep it
- Your account: as long as it exists. When the operator deletes it, everything goes with it: your projects with their files, your settings, your feedback, your running generations and your generation log.
- Projects: until you delete them. Deleting a project removes it at once, together with its files, its photo descriptions and the copies of its details in the generation log.
- Files for a new project that you never save: removed within 2 days.
- Running generations: until 24 hours after you received them, or 7 days if they never reached you; they are removed at the next clean-up after that.
- Generation log and feedback: deleted automatically after 2 years. The summary of a project's generations stays as long as the project does. Ask, and we delete what is about you sooner.
- Failed sign-in attempts: at most 15 minutes, in memory only.
- Server log: until the next update of the server software, which replaces it.
- Visit statistics: until the operator removes them.
Your rights
You can ask to see your data, to correct or delete it, to restrict or object to its use, and to receive it in a usable format - you can already download any project as a zip file.
Send your request to azomo.tom@proton.me; we answer within one month.
Not satisfied with our answer? You can file a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be) or with the supervisory authority where you live.
How we protect it
Sitekiln is reached over an encrypted connection (HTTPS). Passwords are stored as a one-way hash, the sign-in cookie cannot be read by scripts, and after too many failed sign-ins further attempts are refused for a while. You see only your own projects; the operator can see all projects, to manage Sitekiln and to help you.
Changes
When this statement changes, the date at the top changes with it.