This Privacy Policy explains how HTMLtoURL ("HTMLtoURL," "we," "us," or "our") collects, uses, stores, and shares information when you use htmltourl.com, dev.htmltourl.com, htmltourl.app, live.htmltourl.com, and related pages, APIs, and account services (the "Service").
HTMLtoURL lets people publish HTML code, an HTML file, or an eligible ZIP package as a browser-accessible URL. It also provides previews, content safety review, URL management, payment, feedback, and usage analytics features.
When you preview, publish, update, restore, or manage a URL, we may process:
Access passwords for password-protected URLs are transformed into a one-way password verifier. We do not need to store the plain-text access password after the verifier is created.
If you register, sign in, or use account features, we may collect:
When you buy a one-time URL extension or an Editable URL subscription, we may process:
Payments are processed by the payment provider shown at checkout, which may include Stripe, PayPal, or Creem. We do not store full payment-card numbers on our own servers.
When you submit feedback or contact support, we may process your message, feedback category, contact email, related URL, optional screenshots, submission time, referring page, IP address, and User-Agent. Feedback and attachments are sent through our email service so that we can reply and, where applicable, arrange a promotional reward.
We may process IP address, User-Agent, browser and device type, operating system, language, timestamps, requested pages, referrer, errors, performance logs, security signals, and rate-limit information.
For eligible account-owned published URLs, visit analytics may include the page and owner identifiers, publication type, whether the request viewed content or a recovery page, country, region, city, referring domain, device category, time, and a pseudonymous visitor hash derived from the page, IP address, and User-Agent. Creators and known bots may be excluded from some visit counts.
We use cookies, browser storage, and similar technologies for functions such as:
You can remove or restrict cookies through your browser. Blocking strictly necessary storage may prevent sign-in, password access, checkout, or other requested functions from working. If a consent control is presented, your selection applies to the non-essential analytics storage covered by that control.
The product site may use Google Analytics, Microsoft Clarity, and Plausible to understand traffic, navigation, product events, checkout conversion, and technical performance. These services may receive online identifiers, device and browser information, approximate location derived from IP address, page paths, referrers, and event properties. We configure product events not to include submitted HTML, file paths, slugs, email addresses, order numbers, payment-session identifiers, or user-content URLs.
Published content hosts do not receive the product site's GA4 script. HTMLtoURL separately uses Cloudflare Analytics Engine for the limited visit analytics described above.
We use information to:
Where data-protection law requires a legal basis, we generally rely on:
We use deterministic checks and Cloudflare-hosted AI models to classify submitted text for security and acceptable-use risks. A submission may be temporarily placed under review, allowed, blocked, or marked as review failed. We record the decision, category, reason code, model information, and limited usage data in moderation logs.
This review protects the Service and its visitors. It is not intended to make a decision that produces legal or similarly significant effects about a person. If you believe content was blocked incorrectly, contact support@htmltourl.com and include the affected URL without sending passwords or other secrets.
URLs are public by default. A public URL may be opened, copied, downloaded, screenshotted, cached, or forwarded by anyone who obtains it. noindex and nofollow directives reduce search-engine discovery but are not privacy or access controls.
Eligible paid Editable URLs can use password protection. Password protection limits access through HTMLtoURL's access gate, but it is not end-to-end encryption, a guarantee against copying by an authorized visitor, or a substitute for removing confidential information before upload.
Your published files may reference external images, fonts, scripts, APIs, embeds, or other services. A visitor's browser may contact those third parties directly and disclose information to them under their own privacy practices. You are responsible for the external resources and tracking technologies included in your content.
We do not sell personal information. We disclose information as needed:
These providers may process information in countries other than yours and under their own terms and privacy notices.
Retention depends on the record and the service selected:
Deleting a URL removes it from normal access and starts the applicable content-cleanup process. Deleting an account or requesting erasure does not require us to delete records that we must retain for payment, tax, fraud prevention, security, dispute resolution, or other legal reasons.
We use reasonable technical and organizational safeguards, including encrypted transport, access restrictions, isolated user-content delivery, sandboxing, private storage identifiers, one-way password verifiers, rate limits, security review, and provider security controls. No system is completely secure. Keep your own backups, protect account credentials and access passwords, and do not upload secrets or unnecessary sensitive data.
Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a portable copy of your personal information. You may also withdraw consent where processing is based on consent and complain to your local data-protection authority.
You can manage published URLs and billing from the account pages, manage some provider subscriptions through the available billing portal, control cookies through your browser settings and any consent control that is presented, or contact us. We may verify your identity before completing a request. We will respond within the period required by applicable law.
If applicable California privacy law covers HTMLtoURL, California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising a right. We do not sell personal information. Contact us to submit a request.
The Service is not directed to children under the minimum age required by applicable law, and we do not knowingly collect personal information from children. If you believe a child submitted personal information, contact us so we can investigate and take appropriate action.
We and our providers may process information outside your country or region. Where required, we rely on recognized transfer mechanisms or contractual and organizational safeguards. Data-protection laws in the destination may differ from those in your location.
We may update this Privacy Policy when the Service or legal requirements change. The updated_at date identifies the latest revision. For material changes, we will make reasonable efforts to provide notice through the Service or another appropriate channel before the change takes effect where required.
For privacy questions or requests, contact:
Website: https://htmltourl.com
Email: support@htmltourl.com