Our roles
SaveKit is a controller for account administration, billing, security, abuse prevention, legal compliance and our own product analytics. For a creator's forms and page visitor data, the creator normally decides the purpose and SaveKit processes the data on the creator's instructions. Contact the creator first for those requests.
Data we collect
We may collect email, display name, password hash, OAuth provider subject and profile fields, sessions, HTML/ZIP/image content and metadata, domains, expiry settings, form submissions, hashed or truncated IP, device category, referer, approximate country, audit events, support messages and billing identifiers.
We do not store full payment-card numbers. Paddle or another payment provider handles payment details under its own notice. Do not place payment-card, government ID, health or children's data in a page or form unless expressly approved.
Purposes and legal bases
We process data to perform the hosting and subscription contract, comply with tax/accounting and lawful-request obligations, secure and prevent abuse, and improve the service under legitimate interests. Optional marketing or non-essential analytics use consent where required.
Cookies
Essential cookies include savekit_session, short-lived savekit_unlock_<site-id> and savekit_locale. If optional analytics or advertising cookies are added, we will update this notice and provide consent controls where required.
Sharing and international transfers
Recipients may include Cloudflare (DNS, CDN, R2 and edge security), hosting/database/queue providers, email, monitoring, moderation and Paddle. We do not sell personal data or use customer content to train a general-purpose model. SaveKit uses a US-primary deployment for validation and initial production, while public pages use a global CDN and some providers may process data in other countries. We do not currently promise US-only or EU-only processing; where required, applicable transfers use adequacy decisions or safeguards such as SCCs.
Retention and your rights
We retain account data while active, sessions for their lifetime, expired content only as long as needed for restoration, analytics/security events for a limited period, and billing records as required by law. The exact schedule is maintained in our data-residency notice.
Depending on your location, you may request access, correction, deletion, restriction, portability or objection. Email [email protected]; we may verify identity and normally respond to GDPR requests within one month.
Security, moderation and children
We use hashed credentials, encrypted transport, tenant checks, isolated user-page origins, least-privilege storage, audit logs and deletion workflows. Malware scanners, rate limits and human review may delay or suspend publication; contact support to request a review.
SaveKit is not directed to children under 16 or the higher local age. Contact us if a child provided personal data.
Contact and changes
Privacy requests: [email protected]. Legal notices: [email protected]. Operator details: [OPERATOR LEGAL NAME] (individual service provider trading as SaveKit) / [SERVICE ADDRESS / COUNTRY] / [COMPANY / REGISTRATION NUMBER, IF APPLICABLE]. We will post changes with a new effective date.