HTML to URL Privacy Policy

How HTMLtoURL collects, uses, stores, and protects information when you publish and manage URLs.
Updated Sep 9, 2026

Overview

This Privacy Policy explains how HTMLtoURL ("HTMLtoURL," "we," "us," or "our") collects, uses, stores, and shares information when you use htmltourl.com, dev.htmltourl.com, htmltourl.app, live.htmltourl.com, and related pages, APIs, and account services (the "Service").

HTMLtoURL lets people publish HTML code, an HTML file, or an eligible ZIP package as a browser-accessible URL. It also provides previews, content safety review, URL management, payment, feedback, and usage analytics features.

Information We Collect

Content and Files You Submit

When you preview, publish, update, restore, or manage a URL, we may process:

  • HTML, CSS, JavaScript, JSON, text, images, fonts, and other supported files contained in your submission.
  • ZIP entry names, relative paths, file types, file sizes, and validation results.
  • Page titles, original file names, preview images, generated slugs, custom subdomain labels, storage object keys, content hashes, and file manifests.
  • Publication type, ownership, editability, password-protection status, branding status, moderation status, plan, creation and update times, expiration, recovery, and deletion information.
  • A moderation snapshot derived from supported text files so that we can review the submission for phishing, credential theft, malicious behavior, fraud, and other prohibited content.

Access passwords for password-protected URLs are transformed into a one-way password verifier. We do not need to store the plain-text access password after the verifier is created.

Account and Authentication Information

If you register, sign in, or use account features, we may collect:

  • Name, email address, avatar, email-verification status, locale, and account creation time.
  • Sign-in method and information returned by an authentication provider such as Google.
  • Session identifiers, login and expiration times, IP address, browser User-Agent, and security events.
  • URL ownership, subscription entitlements, Editable URL slot assignments, and account activity needed to provide or protect the Service.

Payment and Subscription Information

When you buy a one-time URL extension or an Editable URL subscription, we may process:

  • Product, plan, price, currency, billing period, URL allowance, order number, and order or subscription status.
  • Payment provider, checkout or payment-session identifier, transaction and invoice identifiers, billing URL, and payment callback results.
  • Payer name, payment email, billing details returned by the provider, current subscription period, cancellation status, and the URL or entitlement receiving the purchased service.
  • Limited analytics attribution identifiers associated with checkout so that a completed payment can be measured without using payment records as the source of entitlement.

Payments are processed by the payment provider shown at checkout, which may include Stripe, PayPal, or Creem. We do not store full payment-card numbers on our own servers.

Feedback and Communications

When you submit feedback or contact support, we may process your message, feedback category, contact email, related URL, optional screenshots, submission time, referring page, IP address, and User-Agent. Feedback and attachments are sent through our email service so that we can reply and, where applicable, arrange a promotional reward.

Device, Log, Security, and Usage Information

We may process IP address, User-Agent, browser and device type, operating system, language, timestamps, requested pages, referrer, errors, performance logs, security signals, and rate-limit information.

For eligible account-owned published URLs, visit analytics may include the page and owner identifiers, publication type, whether the request viewed content or a recovery page, country, region, city, referring domain, device category, time, and a pseudonymous visitor hash derived from the page, IP address, and User-Agent. Creators and known bots may be excluded from some visit counts.

Cookies and Similar Technologies

We use cookies, browser storage, and similar technologies for functions such as:

  • Authentication, session security, and Google sign-in state.
  • Locale, theme, interface, and attribution preferences.
  • Remembering recently created URLs, continuing an anonymous-to-account save flow, password-access sessions, and resuming checkout.
  • Fraud prevention, rate limiting, and security checks, including Cloudflare Turnstile.
  • Product analytics and session measurement where enabled and permitted.

You can remove or restrict cookies through your browser. Blocking strictly necessary storage may prevent sign-in, password access, checkout, or other requested functions from working. If a consent control is presented, your selection applies to the non-essential analytics storage covered by that control.

Analytics

The product site may use Google Analytics, Microsoft Clarity, and Plausible to understand traffic, navigation, product events, checkout conversion, and technical performance. These services may receive online identifiers, device and browser information, approximate location derived from IP address, page paths, referrers, and event properties. We configure product events not to include submitted HTML, file paths, slugs, email addresses, order numbers, payment-session identifiers, or user-content URLs.

Published content hosts do not receive the product site's GA4 script. HTMLtoURL separately uses Cloudflare Analytics Engine for the limited visit analytics described above.

How and Why We Use Information

We use information to:

  • Provide previews and create, host, display, update, restore, extend, protect, and delete URLs.
  • Manage accounts, authentication, Editable URL allowances, custom labels, subscriptions, and billing.
  • Review submitted content, investigate reports, enforce our Terms, prevent phishing and abuse, and protect visitors and infrastructure.
  • Provide URL traffic summaries, measure product usage and conversion, troubleshoot errors, and improve reliability and usability.
  • Respond to feedback, support requests, legal requests, disputes, refunds, and security incidents.
  • Maintain payment, tax, accounting, fraud-prevention, and compliance records.

Where data-protection law requires a legal basis, we generally rely on:

  • Contract to provide the features, account, hosting, and paid service you request.
  • Legitimate interests to secure the Service, prevent abuse, measure basic operations, support users, and improve the product, after considering the rights of affected people.
  • Consent, when requested, for the non-essential analytics cookies or similar technologies covered by that request.
  • Legal obligations for tax, accounting, law-enforcement, dispute, and regulatory requirements.

Content Review and Automated Processing

We use deterministic checks and Cloudflare-hosted AI models to classify submitted text for security and acceptable-use risks. A submission may be temporarily placed under review, allowed, blocked, or marked as review failed. We record the decision, category, reason code, model information, and limited usage data in moderation logs.

This review protects the Service and its visitors. It is not intended to make a decision that produces legal or similarly significant effects about a person. If you believe content was blocked incorrectly, contact support@htmltourl.com and include the affected URL without sending passwords or other secrets.

Public and Password-Protected URLs

URLs are public by default. A public URL may be opened, copied, downloaded, screenshotted, cached, or forwarded by anyone who obtains it. noindex and nofollow directives reduce search-engine discovery but are not privacy or access controls.

Eligible paid Editable URLs can use password protection. Password protection limits access through HTMLtoURL's access gate, but it is not end-to-end encryption, a guarantee against copying by an authorized visitor, or a substitute for removing confidential information before upload.

Your published files may reference external images, fonts, scripts, APIs, embeds, or other services. A visitor's browser may contact those third parties directly and disclose information to them under their own privacy practices. You are responsible for the external resources and tracking technologies included in your content.

How We Share Information

We do not sell personal information. We disclose information as needed:

  • To Cloudflare for edge hosting, storage, security, Turnstile, queues, analytics, and AI-assisted moderation.
  • To our database, authentication, email, analytics, and operational providers, including Supabase, Google, Microsoft Clarity, Plausible, and Resend, when their services are enabled.
  • To the payment provider selected at checkout, such as Stripe, PayPal, or Creem, for billing, tax, fraud review, refunds, disputes, and subscription management.
  • To visitors when you publish content through a public URL, or to people who successfully pass an enabled password gate.
  • To advisers, authorities, courts, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or handle a legal claim.
  • In connection with a merger, financing, acquisition, reorganization, or transfer of all or part of the Service, subject to appropriate notice and safeguards.

These providers may process information in countries other than yours and under their own terms and privacy notices.

Data Retention

Retention depends on the record and the service selected:

  • A newly published Temporary URL is normally online for 1 hour. Its content is normally recoverable for 30 days after expiration, unless it is deleted earlier, blocked, subject to a payment hold, or must be retained for a legal or security reason.
  • A free Editable URL currently has no fixed expiration while its free entitlement remains active. A paid Editable URL follows the covering subscription period. If paid coverage ends or capacity is reduced, affected URLs may receive a 7-day grace period and then enter the current recovery lifecycle.
  • Fixed-term Editable URL content may be retained for up to 60 days after its effective paid expiration or qualifying last visit, subject to the current lifecycle rules. Access activity can move the recovery deadline but does not extend the paid online period.
  • Replaced file versions and content marked for deletion are placed into storage cleanup and removed after ownership and safety checks complete. Backups, caches, and failed cleanup tasks may take additional time to expire.
  • Content-moderation logs are normally removed after 30 days. Shorter operational caches may be used to avoid duplicate review.
  • Feedback email and attachments are retained for as long as reasonably needed to respond, arrange any stated reward, prevent abuse, and maintain support records.
  • Account, order, subscription, invoice, payment, tax, security, and dispute records are retained as needed to provide the Service, meet legal obligations, enforce agreements, and maintain business records.
  • Analytics data is retained according to the applicable service configuration and provider settings.

Deleting a URL removes it from normal access and starts the applicable content-cleanup process. Deleting an account or requesting erasure does not require us to delete records that we must retain for payment, tax, fraud prevention, security, dispute resolution, or other legal reasons.

Security

We use reasonable technical and organizational safeguards, including encrypted transport, access restrictions, isolated user-content delivery, sandboxing, private storage identifiers, one-way password verifiers, rate limits, security review, and provider security controls. No system is completely secure. Keep your own backups, protect account credentials and access passwords, and do not upload secrets or unnecessary sensitive data.

Your Choices and Rights

Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a portable copy of your personal information. You may also withdraw consent where processing is based on consent and complain to your local data-protection authority.

You can manage published URLs and billing from the account pages, manage some provider subscriptions through the available billing portal, control cookies through your browser settings and any consent control that is presented, or contact us. We may verify your identity before completing a request. We will respond within the period required by applicable law.

If applicable California privacy law covers HTMLtoURL, California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising a right. We do not sell personal information. Contact us to submit a request.

Children

The Service is not directed to children under the minimum age required by applicable law, and we do not knowingly collect personal information from children. If you believe a child submitted personal information, contact us so we can investigate and take appropriate action.

International Transfers

We and our providers may process information outside your country or region. Where required, we rely on recognized transfer mechanisms or contractual and organizational safeguards. Data-protection laws in the destination may differ from those in your location.

Changes to This Policy

We may update this Privacy Policy when the Service or legal requirements change. The updated_at date identifies the latest revision. For material changes, we will make reasonable efforts to provide notice through the Service or another appropriate channel before the change takes effect where required.

Contact Us

For privacy questions or requests, contact:

Website: https://htmltourl.com
Email: support@htmltourl.com