Security & trust

How we protect your data: cookieless analytics, real deletion, one payment processor, no trackers.

Beyond our own systems, just two companies process your data: our host and our payment processor.

That's the whole list (Cloudflare for hosting, Polar for payments — analytics are self-hosted). Most SaaS leak your data across 8–15 subprocessors and a wall of ad pixels. websideproject is built so there's almost nothing to leak.

Infrastructure

Hosted entirely on Cloudflare — Workers for compute, D1 for the database, R2 for files, all behind Cloudflare's network. Hosted in the EU region where available.

Encryption

Encrypted in transit (TLS 1.3) and at rest (AES-256). Sessions use Secure, HttpOnly, SameSite cookies; secrets are never committed to source control.

Cookieless analytics

Analytics are self-hosted and cookieless (Umami). No third-party trackers, no cross-site profiles. Guests can opt out, and identifiers are cryptographically unlinkable after account deletion.

Real deletion

Account deletion is cryptographically real: per-subject keys are shredded so the data becomes permanently unreadable — even in backups — not just flagged "deleted".

Backups

The database is backed up daily to versioned object storage.

Audit trail

A real, append-only audit log records security-relevant actions — and the relevant slice is visible to you in your own settings, not hidden away.

No trackers, ever

No ad pixels, no marketing SDKs, no data brokers. Blog, docs, feedback, roadmap, changelog, newsletter and forms are all built in — not bolted-on third parties that widen the breach surface.

One payment processor

Billing runs through a single merchant of record (Polar). We never see or store raw card data.

Subprocessors

The complete list of companies that may process your data on our behalf.

Hosting, edge compute (Workers), database (D1), object storage (R2), CDN & DNS.

Data: Account data, Application data, IP addresses (transient), Request logs

EU region where available (configurable per deployment)

DPA ↗

Payments, subscriptions & invoicing (merchant of record).

Data: Billing contact, Email, Payment metadata (no raw card data)

United States / EU

DPA ↗

Cookieless, first-party product analytics. No data leaves your infrastructure.

Data: Pseudonymous page/event data (no cookies, no cross-site tracking)

Same region as the app (self-hosted)

Why we don't (yet) have SOC2

SOC2 audits whether you documented a process — not whether your product is actually private. Plenty of SOC2-certified apps still run ad pixels, share data with a dozen subprocessors, and fake account deletion. We'd rather spend the effort on the architecture above.

We'll pursue SOC2 the moment a customer genuinely needs it — at which point it's mostly documenting what you can already read on this page. Until then, the controls are real and independently verifiable in the product (your audit log, your data export, your deletion).

Reporting a vulnerability

Found something? Email security@websideproject.com. We aim to acknowledge within 48 hours. Our machine-readable policy lives at /.well-known/security.txt.