Privacy Policy
Last updated: 11 October 2026
This policy explains what personal data Ginta collects when you use ginta.app, the websites we host (on ginta.page and on connected domains) and the Ginta connector for Claude and ChatGPT, and what we do with it. We keep it short and collect as little as we can.
Who we are
Ginta is run by [Business name], [Address], company/registration number [Company/registration number] ("Ginta", "we"). For anything about your data, write to [Email].
For your Ginta account and the use of ginta.app we are the controller. For data that visitors leave on websites made with Ginta (for example a message sent through a contact form), the website's owner is the controller and Ginta processes it on the owner's behalf (see our Data Processing Addendum).
What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Account: email address, password (stored only as a salted hash), plan, credits, when you signed in | To give you an account, keep your websites in it, sign you in, send you account emails (confirm your email, reset your password) | Contract (Art. 6(1)(b)) |
| Your websites: the text, pages, images and settings you or your AI assistant create, your chat messages to Ginta's builder, images you upload | To build, publish and host your websites, keep their version history and let you undo changes | Contract (Art. 6(1)(b)) |
| Messages from your visitors (form submissions) | To deliver them to your inbox and, if you turn it on, to your email | Contract with you; we act as your processor |
| Network data: your IP address, browser type, the time of a request | Security, abuse prevention and rate limits. We never store IP addresses in plain form: we store a keyed one-way hash | Legitimate interests (Art. 6(1)(f)): keeping Ginta safe |
| Page-view counts for each website | To show fair-use numbers and protect the service. Counts per site and day only: no visitor profiles, no IP addresses, no cookies | Legitimate interests (Art. 6(1)(f)) |
| Payments (when available) | Paddle, our reseller and merchant of record, processes payments and invoices. We receive your plan, a customer number and the payment status, never your card details | Contract (Art. 6(1)(b)), legal obligations (Art. 6(1)(c)) |
| Abuse reports: the report and, if you give it, your email | To handle the report and tell you what we decided | Legal obligation (Digital Services Act), legitimate interests |
| Support emails you send us | To answer you | Legitimate interests (Art. 6(1)(f)) |
We do not use advertising, tracking or analytics tools, we do not sell your data and we do not use it to train AI models.
AI processing
When you use Ginta's builder, your messages, the content of your website and images you attach are sent to Anthropic (the maker of the Claude AI) so the AI can write and change your website. Anthropic processes this data on our behalf and does not use it to train its models. Don't put sensitive personal data (health, passwords, ID numbers) into your messages.
When you use Ginta from Claude or ChatGPT, your AI assistant's company processes your conversation under its own privacy policy; Ginta receives only what your assistant sends to Ginta's tools (for example the pages of your website).
Who else processes data for us
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, databases, file storage, content delivery, email sending, screenshots for the AI's design check | Worldwide network; company in the USA |
| Anthropic, PBC | The AI that builds and changes websites | USA |
| Pexels (Canva Germany GmbH) | Searching free stock photos; visitors' browsers load those photos from Pexels | Germany / EU |
| Paddle.com Market Ltd | Payments, invoices and taxes (as reseller), once payments are switched on | United Kingdom |
| Stripe | Only if a website owner connects their own Stripe account to take payments; Stripe then acts for the owner | USA / EU |
Where data goes outside the EU/EEA, the transfer is protected by the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework.
How long we keep it
- Account and websites: while your account exists. When you delete a website, its pages, history and messages are deleted at once. When you delete your account, everything in it is deleted.
- Websites made without an account: online for 24 hours, then deleted within a few days, together with photos added to them.
- Images you uploaded but never used: deleted after 14 days.
- One-time links (confirm email, reset password): valid for 1 hour to 7 days, deleted a week after they expire.
- Security counters (hashed IP addresses): 2 days.
- A record that an email was sent (type and outcome only, no address and no content): 13 months.
- Abuse reports: up to 2 years, longer only if needed for legal claims.
- Payment records: as long as tax law requires (kept by Paddle and, for invoices, by us).
Your rights
You can ask us to show, correct, export or delete your personal data, to restrict or object to its use, and you can withdraw a consent at any time. Most of it you can do yourself: change or delete websites in Ginta, and delete your whole account on your account page. For anything else write to [Email]; we answer within one month. You also have the right to complain to a data protection authority, for example the one in the country where you live.
Children
Ginta is not meant for children under 16. If you are under 16, ask a parent or guardian to create the account.
Security
Passwords are hashed, sessions use secure cookies, every website runs on its own address separated from your account, and we keep data in as few places as possible. If a breach ever affects your data, we will tell you and the authority as the law requires.
Changes
If we change this policy in a way that matters, we'll tell you by email or in Ginta before it applies.