Last revised: 10 September 2026
Draft for review. Operator details, retention periods and provider arrangements still need confirmation. This policy is not yet in effect.
This Privacy Policy describes the information handled in connection with lovelycode.app and Lovelycode’s static website hosting service (the “Service”). References to “Lovelycode”, “we” and “us” mean the operator of the Service; “you” means a visitor, waitlist subscriber or account holder.
This policy covers information we handle to operate the Service. Website owners are responsible for the information they collect through their hosted websites, as explained in section 4.
1. Information we collect
Information you provide
- Account information, such as your email address, profile details and sign-in information.
- Your waitlist email address and messages you send for support, abuse reports or legal requests, including your contact details and information you include.
- Website files and settings you provide, including domains, access passwords and environment variables.
Information from connected services
When you connect GitHub, we receive connection details and repository content needed to synchronize your site. Sign-in providers supply the account information needed to authenticate you. Stripe processes payment details and supplies billing and subscription records for paid features.
Technical and operational information
Operating the Service involves processing technical information such as IP addresses, request details, errors and account activity. This information is handled by Lovelycode and its infrastructure providers to deliver requests, diagnose failures and protect accounts and hosted websites.
Abuse reports and case records
When you report abuse, we receive the website address, description and contact information you provide. Handling a report or legal request may also involve relevant account identifiers, hosted-file details, available activity records, correspondence and a record of actions taken. Please send a URL and description; do not send suspected child sexual-abuse material or unnecessary personal information.
2. How we use information
We use this information to sign you in, host your websites, connect the services you choose, manage subscriptions and answer support requests. We also use it to investigate abuse, troubleshoot problems and meet applicable legal obligations.
If you join the waitlist, we use your email to contact you about access to Lovelycode.
3. How information is shared
Service providers
Providers support the following parts of the Service: Supabase supplies account and database services; Cloudflare supplies website delivery, storage and security; Vercel hosts the application; and Stripe processes payments. Information is shared as needed for each provider to perform its role.
Features you enable
Publishing files makes them available to visitors, subject to your access settings. Connecting GitHub enables repository synchronization. If you configure a secret environment variable for an external API, the Service sends its value to an allowed host when your website makes a supported request using that variable.
Legal and security purposes
Relevant account information, hosted content and activity records may be disclosed in response to a legally binding request or a mandatory reporting obligation. Information may also be disclosed where legally permitted and necessary to address abuse, legal claims or a serious threat to someone’s safety. A report or request does not by itself entitle the requester to another person’s information.
Abuse reports can contain personal information about reporters and other people. We limit disclosure to what is appropriate for the lawful purpose; we cannot promise that a reporter’s identity will never have to be disclosed. Notice may be withheld where prohibited by law or where it could compromise an investigation or someone’s safety.
Information may be processed outside your country, where privacy laws may differ.
4. Hosted websites and third-party services
Files you make available on an online website can be accessed by visitors. Password protection restricts access to the areas you choose. Only upload information you have permission to host, and keep a separate copy of files you need.
Site owners decide what their pages collect and which analytics or other services they include. We do not add analytics scripts to hosted pages. A hosted site may have its own privacy policy; contact its owner about information collected through it.
External websites and services have their own privacy practices. Connecting to them or following a link does not place their information handling under this policy.
5. Cookies and browser storage
The service uses cookies to maintain sign-in sessions and secure authentication. Password-protected sites use cookies to remember access for the duration chosen by the site owner. Browser storage also remembers interface preferences. Blocking these features may prevent sign-in or cause the site to ask for a password again.
6. Retention and deletion
You can delete websites and request account deletion through the account settings. Deleting an account removes its hosted websites. Some billing, security or legal records may need to be retained separately; deleting a website does not remove copies someone else has already downloaded.
Relevant content, account information and case records may need to be preserved beyond ordinary deletion when required by law or otherwise lawfully necessary for an abuse investigation or legal claim. Taking content offline does not necessarily delete it. The scope and duration of preservation depend on the applicable obligation or lawful purpose; it does not justify keeping unrelated information indefinitely.
Before this draft takes effect, we still need to confirm and publish the ordinary retention periods for account, activity, support and abuse records, and how deletion works in provider logs and backups.
Disconnecting an integration stops its ongoing use but does not necessarily delete files previously copied to a hosted website. Delete those files separately or contact us about the information you want removed.
7. Information security
Access controls and encryption help protect information held by the Service. These measures cannot eliminate every risk of unauthorized access, loss or disclosure. Keep account credentials and deploy keys secure, and avoid including secrets in publicly accessible website files or support messages.
8. Your rights and choices
Contact hello@lovelyco.de to request access to, correction of or deletion of your personal information, or removal from the waitlist. Depending on where you live, you may have additional rights, including the right to complain to a privacy regulator. We may need to verify your identity before acting on a request.
In British Columbia, you can contact the Office of the Information and Privacy Commissioner about a privacy concern. Please contact us first so we can try to resolve it.
9. Changes to this policy
Updates will appear on this page with an effective date. Material changes to how information is used will be communicated as required by applicable law.
10. Contact
Send privacy questions and requests to hello@lovelyco.de. Describe the information or account concerned so we can identify and respond to your request.
For the rules for using the service, see our Terms of Service.