Last updated 28 September 2026
Privacy policy
SiteSpring is a platform that lets AI agents build, edit and publish websites. This policy covers sitespring.app, the console at app.sitespring.app, the SiteSpring API and MCP server, and the websites SiteSpring hosts for its customers.
SiteSpring is operated by Writeflow ApS, Gassehaven 98, 2840 Holte, Denmark (CVR 43460870). For anything in this policy, write to pe@writeflow.com.
Two roles
For the people who use SiteSpring itself (account holders and members of an organisation), we are the controller: we decide what we collect and why.
For the visitors to websites our customers build on SiteSpring, the customer is the controller and we are their processor. If you filled in a form on one of those sites, the site's owner decides what happens to it, and your requests about it go to them first. We act only on their instructions.
What we collect from account holders
| Data | Why | Kept |
|---|---|---|
| Name and email address | To identify you and let you sign in. Your email address is what grants you access to an organisation. | Until you ask us to delete your account |
| A hash of your password, if you use one | To check your password. We never store the password itself. | Until you delete your account or change it |
| Your Google account ID, if you sign in with Google | To recognise you when you sign in with Google again. | Until you delete your account |
| Session records: IP address and browser | To keep you signed in and to spot misuse of your account. | Until the session ends or expires, then deleted within a day |
| Organisation memberships and roles | To decide what you may do. | Until you are removed or the organisation leaves SiteSpring |
| API keys you create | So your agents can act for you. We store only a one-way hash of each key. | Until the key is revoked; the record stays so past actions remain traceable |
| An audit trail of changes (who did what, and when) | Security, and answering "who changed this site". | For the life of the organisation's account. If the organisation leaves, the record is kept without names. |
The legal basis is the contract with you or your organisation (to provide the service), and our legitimate interest in keeping it secure.
Signing in with Google
If you choose "Sign in with Google", we receive your name, email address, whether Google has verified that address, and your profile picture if you have one. We use them only to sign you in and show who is signed in. We do not request access to your Gmail, Drive, contacts or anything else. The sign-in tokens Google gives us are stored encrypted.
SiteSpring's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Visitors to sites we host
- Form submissions are stored in a database that Cloudflare keeps within the EU, for as long as the site owner sets (365 days unless they choose otherwise), then deleted automatically. We do not store the sender's IP address or browser with a submission. A site owner can also have submissions sent to their own tools, such as a CRM or email.
- Cookie choices. If a site shows our cookie banner, your choice is kept in a first-party cookie on that site for 180 days. Nothing optional is set until you choose.
- Protected pages. If a page asks for your email to send you a code, we use the address only to send that code and to let you in. The code expires after ten minutes and is deleted within a day. Once you are in, a cookie on that site holds your email address for as long as the site owner sets, so you are not asked again on every page.
- Request logs. We record which page was requested, when, and whether it worked, to run and debug the service. These logs do not include your IP address.
Requesting access
If you request access to SiteSpring, we receive your name, work email, company, and anything else you choose to tell us. We use it only to consider your request and to reply. It is kept for 180 days and then deleted automatically; if we let you in, the details your account needs are kept as described above. The legal basis is your request: steps you asked us to take before a possible contract. The form is checked by Cloudflare Turnstile to keep out automated spam.
This website
sitespring.app sets no cookies and runs no analytics or advertising scripts. The request access page loads Cloudflare Turnstile, which checks that a person is sending the form. The console at app.sitespring.app sets a cookie that keeps you signed in and, while you sign in with Google, a short-lived cookie that stops anyone else completing your sign-in. Both are necessary for it to work.
Who else handles it
- Cloudflare hosts SiteSpring: its servers, databases, file storage and email sending. Account data is stored with its primary copy in Western Europe; form submissions stay within the EU.
- Google, only if you sign in with Google, as described above.
We do not sell personal data, and we do not use it to train AI models. Where a provider processes data outside the EEA, it does so under the European Commission's standard contractual clauses or an adequacy decision.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. Write to pe@writeflow.com and we will answer within a month. You can also complain to your data protection authority; in Denmark that is Datatilsynet.
Security
Connections are encrypted. Passwords and API keys are stored only as one-way hashes. Each organisation's data is kept apart from every other's and checked on every request.
Changes
If we change this policy we will update the date at the top, and tell account holders by email when the change matters to them.