html2wp / Data
What html2wp does with your data
A plain description of what leaves your machine, why, and how long we keep it. The README mentions the same things only in passing. This is the version you can point a client at.
The conversion itself
To convert a site, the service has to receive it. When you run stage 3, the skill uploads one archive to api.html2wp.dev:
conversion-manifest.json, the decisions you made about the siteastro-report.json, the inventory of the parts pages share (the chrome) from stage 1astro-project/, includingdist/, which is the built sitechrome-at-rest/,chrome-groups.jsonandstyle-specimens/when they exist
That is your client's website: its markup, styles, scripts and images. There is no way to convert a site without sending it, and any wording suggesting otherwise would be false. SKILL.md lists the exact files under What goes up. If you would rather check than take our word for it, convert-remote.sh is a readable shell script.
What is not in that archive
Your input directory is not in it, since only the built output travels. Neither is node_modules. Nor is anything shaped like a credential: .env and .env.*, *.pem, *.key, id_rsa, credentials.json, .npmrc, .netrc, .ssh/, .aws/, plus any file whose contents contain a private key block or an obvious secret assignment. The filter lists everything it drops by name in astro-report.json, so you can see what did not travel.
AI from your own ChatGPT account drives the work on your computer (measuring, comparing with the original, and fixes). OpenAI processes what the AI works on under your account's terms, the same as when you use ChatGPT any other way.
How long we keep it: we delete the workspace 48 hours after it last changed. What survives is a digest (a hash). That is what lets a re-run of the same site count as a re-run rather than a second conversion.
The gate results
After you verify a conversion locally, the skill reports the outcome. This is required: the next conversion is refused until the previous one has reported. It is also small, and it is a whitelist rather than a filter.
- Sent: gate names, the result (pass, fail or not run), page counts, the worst fidelity percentage, and the page keys that failed. Keys are the short names you chose, like
aboutorpricing. - Not sent: no URL, no domain, no markup, no copy, no screenshots, no file paths, no licence key, no site name.
The command send-verdicts.sh <workspace> --dry-run prints the exact payload and sends nothing.
Why it is required: the gates run on your machine, against a WordPress the service never sees. Without them the service can tell that a conversion did not crash, but nothing whatsoever about whether it was correct. We keep the results 365 days.
The conversion record
One row per conversion: how many pages, how many chrome variants, whether it had a blog or a shop, whether it was a re-run, which stage refused if one did, and the generator's own warnings about itself. The warnings are redacted: page filenames and URLs are replaced before the row is written. We keep the record 365 days. It holds no content, no addresses, no identifiers for the site.
Defect reports
If you send one with POST /v1/report, we store its text exactly as you wrote it and mail it through Resend to a person who reads it. We keep it 90 days. Do not paste anything into it that you would not want kept for that long.
Identifying you
- Without a key: conversions are counted per IP address, as seen by Cloudflare. We store it as a truncated hash, never as the address itself.
- The country that hash was in, as two letters, from the header Cloudflare adds. It sits beside the counter above and nowhere else. In particular, it is not on the conversion record, which holds nothing that locates you. The country tells us which countries html2wp is used in, but not which conversion was yours. Unknown and Tor arrive as
XXandT1and we keep them as such instead of guessing. - Licensed: by the licence key, also stored as a hash. We validate it against UpdatePulse (
updates.designready.studio), which sees the key. - Checking a key or downloading Visual Edit Pro: the download page and the
npx html2wp-licensechecker send the key you enter, and nothing else, to that same licence server to read its status. The answer carries no personal details, and neither the page nor the checker stores the key.
Buying a licence
We sell plans through Paddle. Paddle.com Market Limited is the Merchant of Record, the seller in the transaction. For the payment it is an independent controller, not a processor acting for us. At checkout Paddle collects your name, email address, country and postcode, your payment details and, if you give one, a VAT ID. It processes them under its own privacy notice.
- What Paddle passes to us: your email address, name and country, the transaction and subscription ids, and which product you bought. That is what it takes to issue a key to the right person and to find the order again when you write to us.
- What we store: in UpdatePulse, our licence server at
updates.designready.studio, the licence key, your email address and name, the transaction id, the purchase and expiry dates and the licence status. - The key email goes out through Resend, which only delivers it and does nothing else with it.
- Company details for the invoice (business or trade name, address, optionally a VAT number and the email) go from your browser straight to Paddle's checkout if you choose For a business or freelancer before paying. Paddle then prints them on the invoice. This site does not send them to our servers or store them.
- Card data never reaches us. It goes from your browser to Paddle, and we could not see it if we wanted to.
- Paddle's script, Paddle.js, loads only on the pricing page, from
cdn.paddle.com, because that is where the checkout opens. No other page on this site loads it.
Retention period: for the life of the licence, and after that for as long as accounting law requires us to keep purchase records.
Managing a subscription
You manage a subscription in Paddle's customer portal, on Paddle's own site. Cancelling, changing the card and downloading invoices are between you and Paddle, and we see only the result. To switch Pro from monthly to yearly, the subscription management page sends the email address you enter to Paddle to find your subscription. If there is one, the link goes by email through Resend to the address Paddle holds. We do not store the address you typed.
The contact form
The form you use to write to us is the other place on this site where you type something about yourself. It asks for an email address, which is required, a website or organisation, which is optional, and your message. The form also has a hidden field named company that people never see. It is there so that bots which fill in every field give themselves away.
Before a message is sent, Cloudflare Turnstile checks that a person, not a script, is sending it. It runs only on the pages with a form that uses it: the contact page and the subscription page. It loads from challenges.cloudflare.com. To decide, Cloudflare looks at your IP address, your browser's User-Agent and its TLS fingerprint. Cloudflare says these are strictly necessary for telling people from bots. It does not read what you type into the form. We receive a pass or a fail and nothing else. Cloudflare's Turnstile privacy addendum has the detail.
Your message reaches a person by email, through Resend. It does not go into a CRM or onto a mailing list. We keep it as long as the conversation needs, and delete it within 24 months. Ask sooner and it goes.
Google user data
html2wp uses one Google API, the Google Ads API, and only for our own keyword research: which search terms people use, how often, and how competitive they are. It is an internal tool. Nobody outside our team signs in with Google anywhere on html2wp, and the converter never asks you to.
- What we request: the
https://www.googleapis.com/auth/adwordsscope, granted by a member of our team for Google Ads accounts we own. It is used to read Keyword Planner data: keyword ideas, historical search volume, competition and bid ranges. - What we do not touch: campaigns, ads, audiences, billing, or any Google account other than our own. Nothing is written back to Google Ads.
- Where it is kept: the sign-in token stays in the operating-system keychain of the computer it was granted on. Keyword results end up in our own content planning, as numbers about search terms, not about people.
- Who else sees it: nobody. We do not sell it, share it, or use it for advertising or to train AI models.
- Removing it: you revoke access at myaccount.google.com/permissions. We delete anything derived from it on request sent to hello@html2wp.dev.
html2wp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who else is involved
- Cloudflare (United States) hosts this website and runs its small server-side functions (the contact form, the Visual Edit Pro download and the payment webhook). It also sits in front of the conversion API. It terminates TLS, so it sees each request and the address it came from. On the contact and subscription pages it also runs Turnstile, the bot check described above. For that check Cloudflare is our processor. It is a controller only when it uses the same signals to improve bot detection.
- UpdatePulse on our own server, for licence validation. Since licences are sold, it also holds the customer's email address and name beside the key.
- Paddle (Paddle.com Market Limited, United Kingdom) is the Merchant of Record for every purchase, and an independent controller for the payment data it collects.
- Resend (United States) delivers four kinds of email: licence keys after a purchase, subscription management links, messages sent through the contact form, and converter defect reports.
- Coolify on our own server, for hosting the conversion service and the licence server.
- agentmods.dev serves the small plugin-measurement badge in the footer of every page. Loading that image sends it your IP address and browser details, like any image from another site. Nothing else is shared with it.
- Umami, the open-source analytics tool, runs at umami.agentmods.dev and is used on this website only. It counts page views and a handful of clicks: which button was pressed, not who pressed it. No cookies, no cross-site identifier, nothing stored on your device. That is why this site has no cookie banner to click through.
No advertising, no cross-site tracking, no data sold
The one analytics tool is the cookieless one named above, and it runs on this website. The theme you receive contacts no server of ours at runtime, ever. That claim is about the delivered site, and it is exact. Nothing is sold, and nothing is shared with an advertiser.
Leaving the EU
Our servers are in the EU. Cloudflare and Resend are US companies. Traffic to this website and to the API passes through Cloudflare's infrastructure, as does the Turnstile check on the forms. Key emails, subscription management links, contact-form messages and defect reports pass through Resend's infrastructure. Both can involve a transfer outside the EU. Those transfers run on the European Commission's Standard Contractual Clauses. Paddle is in the United Kingdom, which the European Commission recognises as providing adequate protection, and it handles the payment data under its own privacy notice. The footer badge and the analytics script both come from agentmods.dev, a site served through Cloudflare's global network. So where those requests are answered is not something we control. Nothing else in this list leaves the EU.
Legal basis
Under the GDPR every one of these needs a lawful basis. Here is which one applies to each:
The conversion service
- Receiving and converting your site: performance of a contract (Art. 6(1)(b) GDPR). You asked for a conversion, and it cannot happen without the upload.
- Counting conversions against an IP address: legitimate interests (Art. 6(1)(f) GDPR). A free tier that cannot be counted gets drained, and a truncated hash is the least we could identify it with.
- Recording which country that address was in: legitimate interests (Art. 6(1)(f) GDPR). Knowing where a product is used decides what it supports. Two letters beside an already-pseudonymous counter is the coarsest form that answers that question. It adds nothing to what the hash alone could identify.
- Validating a licence key: performance of a contract (Art. 6(1)(b) GDPR).
- Gate verdicts and the conversion record: legitimate interests (Art. 6(1)(f) GDPR). Knowing which stage fails on which shape of site is the only way the converter improves. Before we write them, we strip out everything that identifies the site.
- A defect report you send: legitimate interests (Art. 6(1)(f) GDPR). You decide whether to send one at all.
Licence purchases
- Issuing and managing a purchased licence: performance of a contract (Art. 6(1)(b) GDPR).
- Keeping purchase records: legal obligation (Art. 6(1)(c) GDPR). Accounting law says how long.
This website
- The contact form: steps taken at your request before a contract, or legitimate interests in answering the person who wrote to us (Art. 6(1)(b) or (f) GDPR).
- The bot check on the contact and subscription forms: legitimate interests (Art. 6(1)(f) GDPR). The point is to keep automated spam out of a form that a person reads. It uses only the signals Cloudflare needs for that, nothing more.
- Counting page views on this website: legitimate interests (Art. 6(1)(f) GDPR). This is defensible precisely because the tool stores nothing on your device and cannot follow you off this site.
Automated decisions
The service refuses a conversion automatically when the conversion allowance is spent or a site is too large. That is only arithmetic on a counter, and it has no legal effect on anyone. If you write to us about it, a person answers. We do no profiling.
Your rights
Under the GDPR you can ask us for any of the following, and one email to hello@html2wp.dev is enough.
- Access: you get a copy of what we hold about you (Art. 15).
- Rectification: if the data is wrong, we correct it (Art. 16).
- Erasure: we delete the data (Art. 17).
- Restriction: we keep the data but stop using it while something is in dispute (Art. 18).
- Portability: you receive what you gave us in a machine-readable form (Art. 20).
- Objection: you can object to anything we do on the basis of legitimate interests, including the analytics (Art. 21). We stop unless we can show grounds that override yours.
We answer within one month. There is no charge. We do not ask you to prove who you are beyond what it takes to be sure we are not handing your data to somebody else.
One limit: most of what the service holds is hashed or aggregated and cannot be traced back to a person, even by us. So for those rows there is nothing to hand over, correct or delete. The uploaded site is gone after 48 hours by itself.
If we get it wrong
You can complain to the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk. If you live in another EU country you may go to your own authority instead. Writing to us first is faster, but it is not a condition.
Vulnerability reports go to the address on the security page, not to a public issue.
Who is responsible
The data controller is BELNEM s.r.o., Beckovská 5, Bratislava, Slovakia, IČO 53713486. Email: hello@html2wp.dev. We are not large enough to be required to appoint a data protection officer and have not appointed one. The address above reaches the people who decide these things.
Giving us data is never a statutory requirement. It is simply that a conversion needs the site, and a licence needs an address to send a key to.