Privacy policy

Last updated October 3, 2026

This is a starting draft. Have it reviewed by a lawyer before you publish it, and fill in your company's legal name and address.

This policy explains how cmsspot handles personal data. It covers the people who use cmsspot to edit websites. When you connect a client's website, you are the one responsible for the personal data on that site, and a separate data processing agreement covers that relationship.

1. Who is responsible

cmsspot is operated by [your company's legal name], [address], [country]. For questions about your data, write to contact@cmsspot.com.

2. What we store, and why

We keep as little as possible. For each user we store:

There is no password. You log in with a one-time link sent to your email. Login forms carry a hidden field that catches automated submissions; nothing about you is stored from it.

When you connect a website, cmsspot fetches a copy of the site's files to our server so you can edit them. Those files can contain personal data that the website owner is responsible for. The server details you enter (host, user, and a password or key) are stored encrypted.

AI access. If you create a token for an AI assistant, we store a one-way hash of the token (never the token itself), its name, level, expiry and which site and user it belongs to. Each call the assistant makes is written to an activity log for that site: time, which tool was used, the file path, whether it succeeded, the size, and a shortened IP address. The log never contains the content of your files.

Security log. To protect accounts we log security events: failed login requests, rejected or expired login links, rejected tokens, blocked connection attempts, and changes to users or site access. Each entry holds the time, the kind of event, the user if known, and a shortened IP address with the last part removed. Passwords, tokens and links are never written to it. The log keeps the most recent entries and is capped in size, so older entries are discarded as new ones arrive.

The build guide. The public build guide at /build is an MCP server that only returns documentation and checks text you send it. It stores nothing you send. Requests are counted per IP address for a short window to limit abuse, and that counter is discarded when the window passes.

Cookies. cmsspot sets one session cookie when you log in, so the browser stays logged in. There are no analytics cookies, no advertising cookies and no third-party cookies on cmsspot.com.

Email. Login links, invitations and notices are sent through our email provider, whose servers are in the EU. The provider sees your email address and the message.

3. Where the data is

Data is hosted in the EU (Denmark). We do not transfer personal data outside the EU/EEA.

4. How long we keep it

5. Who can see it

Each user only sees the websites their account is given access to. Client users see their own site, not your other clients. Server passwords and keys are stored encrypted and are never shown in the interface, in logs or to an AI assistant. Administrators of the cmsspot installation can see the security log.

An AI assistant you connect with a token sees only the site the token is for, at the level you chose, and never the files you have hidden from it. It cannot see your login, the server details or any other site.

6. Your rights

Under the GDPR you can ask for access to your data, correction, deletion, or a copy of it, and you can object to processing. Write to contact@cmsspot.com and we will handle it. You can also complain to the Danish Data Protection Agency (Datatilsynet).

7. Changes

We update this policy when the service changes. The date at the top shows the latest version.

← Back to the front page