Privacy policy
Last updated October 3, 2026
This is a starting draft. Have it reviewed by a lawyer before you publish it, and fill in your company's legal name and address.
This policy explains how cmsspot handles personal data. It covers the people who use cmsspot to edit websites. When you connect a client's website, you are the one responsible for the personal data on that site, and a separate data processing agreement covers that relationship.
1. Who is responsible
cmsspot is operated by [your company's legal name], [address], [country]. For questions about your data, write to contact@cmsspot.com.
2. What we store, and why
We keep as little as possible. For each user we store:
- Name, company and email address, so we can identify you and send login links. This is needed to provide the service.
- Which websites your account may access, and whether you are an administrator.
- Your IP address for a short time when you request a login link, to limit abuse. It is deleted once the rate-limit window passes.
There is no password. You log in with a one-time link sent to your email. Login forms carry a hidden field that catches automated submissions; nothing about you is stored from it.
When you connect a website, cmsspot fetches a copy of the site's files to our server so you can edit them. Those files can contain personal data that the website owner is responsible for. The server details you enter (host, user, and a password or key) are stored encrypted.
AI access. If you create a token for an AI assistant, we store a one-way hash of the token (never the token itself), its name, level, expiry and which site and user it belongs to. Each call the assistant makes is written to an activity log for that site: time, which tool was used, the file path, whether it succeeded, the size, and a shortened IP address. The log never contains the content of your files.
Security log. To protect accounts we log security events: failed login requests, rejected or expired login links, rejected tokens, blocked connection attempts, and changes to users or site access. Each entry holds the time, the kind of event, the user if known, and a shortened IP address with the last part removed. Passwords, tokens and links are never written to it. The log keeps the most recent entries and is capped in size, so older entries are discarded as new ones arrive.
The build guide. The public build guide at /build is an MCP server that only returns documentation and checks text you send it. It stores nothing you send. Requests are counted per IP address for a short window to limit abuse, and that counter is discarded when the window passes.
Cookies. cmsspot sets one session cookie when you log in, so the browser stays logged in. There are no analytics cookies, no advertising cookies and no third-party cookies on cmsspot.com.
Email. Login links, invitations and notices are sent through our email provider, whose servers are in the EU. The provider sees your email address and the message.
3. Where the data is
Data is hosted in the EU (Denmark). We do not transfer personal data outside the EU/EEA.
4. How long we keep it
- User accounts: until the account is deleted.
- Login IP addresses: only for the short rate-limit window, then deleted.
- A connected site's files and backups: until you disconnect the site, which removes the local copy and its backups. Backups are limited to the most recent versions per file.
- AI access tokens and their activity log: until the token is revoked or the site is disconnected. The activity log is capped in size per site.
- The security log: capped in size, so the oldest entries are discarded as new ones arrive.
5. Who can see it
Each user only sees the websites their account is given access to. Client users see their own site, not your other clients. Server passwords and keys are stored encrypted and are never shown in the interface, in logs or to an AI assistant. Administrators of the cmsspot installation can see the security log.
An AI assistant you connect with a token sees only the site the token is for, at the level you chose, and never the files you have hidden from it. It cannot see your login, the server details or any other site.
6. Your rights
Under the GDPR you can ask for access to your data, correction, deletion, or a copy of it, and you can object to processing. Write to contact@cmsspot.com and we will handle it. You can also complain to the Danish Data Protection Agency (Datatilsynet).
7. Changes
We update this policy when the service changes. The date at the top shows the latest version.