Last updated: July 29, 2026
Swebsy is a local-first, browser-based website builder. This policy explains how Swebsy handles information when you visit swebsy.com, use Swebsy Studio, connect an AI service or coding agent, or deploy a website.
Swebsy Studio stores most project and app data on your device through browser storage, including PouchDB and IndexedDB, localStorage, and sessionStorage. This lets the core editor work without a server-side user account.
Local data may include:
This information leaves your device only when you choose an action that requires another service, such as an AI request, coding-agent task, image search, or deployment. Browser storage can be cleared or evicted, so export a project backup before clearing site data or changing browsers or devices.
When you visit Swebsy’s public site, documentation, or app, our hosting and security providers, including Cloudflare, may process standard request data. This can include your IP address, browser and device headers, requested URL, request time, and security signals.
This information is used to deliver the service, prevent abuse, diagnose failures, and protect Swebsy and its users. Swebsy does not use it to build advertising profiles.
When product analytics are configured, Swebsy Studio uses PostHog to collect limited usage and reliability data. Capture remains off until you accept the analytics notice. Swebsy also honors supported Global Privacy Control and Do Not Track signals.
General click and page autocapture and session recording are disabled. The analytics SDK stores an anonymous identifier and your preference in localStorage and a session identifier in sessionStorage.
Analytics may include:
Swebsy’s analytics event allowlist is designed not to send project or page content, generated HTML or CSS, component trees, uploaded asset names, AI prompts or responses, deployment tokens, repository names, or custom code. We do not intentionally put that content into analytics events.
You can turn product analytics off at any time in Global settings → App preferences. Turning analytics off stops new capture; it does not delete data already processed.
If you use Swebsy’s built-in AI, requests are sent from your browser to the provider you configure, such as Anthropic, OpenAI, or an OpenAI-compatible service. Your API key is stored locally. A request may include your prompt, relevant site or page context, selected content, recent chat history, and any image or screenshot you attach.
The optional PII sanitizer replaces some obvious email addresses, phone numbers, and similar text patterns before a request, but it cannot guarantee removal of all sensitive information. Text inside attached images is sent as-is. Do not submit personal, confidential, or regulated data unless you are comfortable sending it to your selected provider. That provider’s terms, privacy policy, and retention practices apply.
When you pair a coding agent, a local bridge on your device relays commands to the open Studio tab. The agent can receive the non-secret site content, settings, screenshots, and exports needed for the tasks you request. Your coding-agent provider may process that information under its own privacy policy.
Studio removes AI API keys, deployment tokens, AI chat history, and analytics settings from agent-visible settings. Agents are also blocked from changing credentials, deployment configuration, analytics scripts, security headers, and raw code-injection settings.
If you configure an Unsplash access key for AI-assisted image search, Swebsy sends the descriptive image query and access key to Unsplash. The selected image is then downloaded and stored with your local project. Unsplash’s terms and privacy policy apply.
If you deploy through GitHub Pages or Cloudflare Pages, Swebsy uses the credentials and configuration stored in your browser to call the service you selected. Those providers receive the files and account or repository details needed to complete the deployment. Their terms, privacy policies, security practices, and retention rules apply. Swebsy does not include deployment tokens or repository names in product analytics.
Swebsy lets you export static websites and add analytics tags, tracking scripts, pixels, embeds, forms, custom code, or other third-party services. You control those additions. They are separate from Swebsy’s product analytics, and you are responsible for the privacy notices, consent controls, and other legal requirements that apply to the websites you publish.
Swebsy does not sell personal data. Information is shared only as needed for the service or action you choose, including with:
Local project data remains in your browser until you delete it, clear browser storage, or the browser removes it. Data sent to a provider is retained under that provider’s settings and policies. Swebsy may retain optional analytics and infrastructure logs for product improvement, security, troubleshooting, and legal obligations; retention periods vary by data type and provider.
Swebsy uses technical and organizational safeguards intended to limit unauthorized access, disclosure, or loss. No browser storage, transmission, or third-party service can be guaranteed completely secure.
You can control much of the information described in this policy by:
Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to certain processing. Contact us to make a request. We may need enough information to verify the request, and pseudonymous data may not always be linkable to you.
We may update this policy as Swebsy, its providers, or applicable requirements change. We will revise the date above and provide an additional notice in the site or app when a change is material.
Questions or privacy requests can be sent to support@swebsy.com.
made with swebsy