Back to home

Privacy Policy

How CopySite collects prompts, URLs, screenshots, project files, credits, AI keys, and delivery data to generate publishable websites.

Last updated: 2026-07-14

Introduction

CopySite helps you turn a prompt, public URL, or screenshot into editable website code, then preview, snapshot, restore, publish, export, or hand it off to GitHub. This Privacy Policy explains what we collect to run that workflow and how we protect it.

Information We Collect

We collect the following types of information to provide and improve the Service:

  1. Account Information — Your name, email address, and other details you provide when creating an account.
  2. Generation Inputs — Prompts, public URLs, uploaded screenshots, reference notes, and any source context captured from those materials so CopySite can generate and iterate on your project.
  3. Project Data — Generated files, chat history, preview state, snapshots, restore points, build logs, publish status, export artifacts, and GitHub delivery metadata.
  4. Credits and Plan Data — Free project allowance, starter credits, credit reservations, refunds after failed runs, subscription status, manual upgrade requests, and admin credit grants.
  5. AI Key and BYOK Data — Provider names, masked key metadata, validation status, and encrypted secret values when you choose to store your own AI keys in CopySite.
  6. Usage Data — Features used, generation counts, error reasons, recovery actions, and operational events that help us improve reliability and abuse prevention.
  7. Device and Cookie Data — Browser, device, locale, session cookies, authentication cookies, and preference cookies needed for account access and localization.
  8. Payment Information — Billing details handled by trusted third-party payment processors. We do not store full card numbers on our servers.

How We Use Your Information

We use the data we collect to:

  • Generate websites from prompts, URLs, and screenshots, then keep your preview, file tree, logs, snapshots, restore actions, publish state, exports, and GitHub handoff available in the workspace.
  • Enforce the free allowance, reserve build credits before runs, refund credits after failed runs, process subscriptions, and route manual upgrade or credit recovery requests.
  • Validate and securely use your BYOK credentials only for the providers and generations you configure.
  • Send technical notices, security alerts, and support messages.
  • Respond to your questions, feedback, and support requests.
  • Detect, prevent, and address fraud and abuse.

Third-Party AI, Sandbox, Payment, and GitHub Providers

To generate and deliver code, CopySite may pass prompts, URLs, screenshots, captured context, and generated files to AI providers, isolated sandbox infrastructure, storage providers, payment processors, email providers, and GitHub when you choose a GitHub handoff. These providers process that data under their own policies. Do not submit confidential material, private third-party websites, or secrets you would not want processed by those services.

Data Sharing

We do not sell your personal information. We may share data only in these limited cases:

  • With service providers who help us operate the Service, under confidentiality agreements.
  • With AI, sandbox, storage, payment, email, analytics, or GitHub providers only as needed to complete the workflow you request.
  • To comply with legal obligations or respond to lawful requests from public authorities.
  • To protect our rights, property, or safety, or that of our users.

Source Rights and Sensitive Inputs

When you submit a URL, screenshot, prompt, or brand reference, you are responsible for having the rights needed to use it. CopySite is designed to generate original editable code inspired by your inputs, not to copy protected third-party assets, trademarks, private pages, or confidential material. Remove secrets, customer data, private tokens, and regulated data before submitting inputs.

Data Security

We implement industry-standard security measures including encryption in transit, access controls, audit-oriented operational logs, and regular reviews. Stored provider keys are encrypted when secret encryption is configured. Generated code runs inside sandboxed environments with the minimum access required. No method of transmission over the Internet is 100% secure, but we work continuously to protect your information.

Data Retention

We retain account, credit, billing, project, snapshot, log, and delivery records while your account is active so you can review history, restore versions, resolve failed runs, and prove credit usage. You may delete projects where the product provides deletion controls. Sandbox environments are ephemeral and expire automatically. Some billing, security, and abuse-prevention records may be retained when required for legal, accounting, or operational reasons.

Your Rights

You have the right to access, update, export, or delete your personal information, including generated projects, subject to legal and operational limits. You can do this through your account settings or by contacting us at the email address below.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the date at the top of this page and, where appropriate, sending a notice through the Service.

Contact Us

If you have questions about this Privacy Policy, please contact us at the email address provided on our website.