Last updated August 28, 2026

Privacy

HTML2WEB stores the HTML or Markdown you publish so it can provide the temporary link you requested. Do not publish secrets, credentials, sensitive personal data, or anything you do not have permission to share.

What we process

We process the original HTML or Markdown source, original filename when available, file extension, content type, MIME type, exact byte size and coarse size range, input method, link settings, coarse service logs, hashed rate-limit identifiers, and—if you sign in—your account identifier, sign-in provider, provider account identifier, name, email, email-verification status, profile image when supplied, OAuth token records, account sessions, and linked-account history. Passwords for protected shares and private management tokens are not stored in plaintext. If you contact us through the inquiry form, we also process the message, optional subject, optional share ID, locale, and optional reply email you submit. The inquiry is also delivered to our private Discord channel for review.

If you buy a paid product, we process the payment provider’s checkout, order, customer, product, price, currency, tax, refund, subscription, and entitlement references together with the account and link needed to deliver and support the purchase. The provider may also send the purchaser name, email, country, and other transaction fields needed for receipts, fraud prevention, support, or legal compliance. Full payment-card details are handled by the payment provider and are not stored by HTML2WEB.

HTML2WEB verifies signed payment notifications and retains only the transaction and entitlement data needed for delivery, reconciliation, refunds, fraud prevention, customer support, accounting, and legal obligations. We do not use payment data to build advertising profiles or sell it to third parties.

Google and GitHub sign-in

When you choose Google sign-in, HTML2WEB requests only the OpenID Connect scopes needed for sign-in: openid, email, and profile. Google may return a stable account identifier, name, email address, email-verification status, profile image, ID token, and short-lived access token. HTML2WEB uses this data only to create or recognize your account, link your shares and paid entitlements, secure your session, and provide account support. It does not request access to Google Drive, Gmail, Calendar, contacts, or posting permissions.

GitHub sign-in is used for the same account-identification purposes and requests only the profile and verified-email access needed for sign-in. OAuth token records are protected in account storage and are not exposed to viewers or payment providers. HTML2WEB does not use Google or GitHub account data for advertising, marketing lists, or unrelated provider API access. Linked sign-in data is not sold. It is shared only with infrastructure providers needed to operate the service, when you direct a connected feature, or when required by law.

Product measurement and viewer sessions

The publisher keeps a random product-measurement session in your browser’s local storage for up to seven days. The isolated viewer uses a strictly necessary, HttpOnly session cookie for up to seven days so repeated opens can be counted consistently and abuse can be limited. A password-protected preview also uses a strictly necessary, HttpOnly unlock cookie for up to 30 minutes.

Measurement records may include the action name and time, pseudonymous HMAC-derived session and share identifiers, locale, landing or input type, selected expiry, whether a password was enabled, a coarse content-size range, referral channel, and a bounded result code. These product records do not contain published content, raw share URLs, passwords, management tokens, email addresses, or full IP addresses.

Google Analytics

HTML2WEB pages use Google Analytics 4 for audience, acquisition, and product-funnel measurement. Google Analytics loads whenever an application page is opened and may set first-party measurement cookies. Google Signals and advertising personalization remain disabled, and HTML2WEB does not send a user ID.

Analytics events include a canonical page path and bounded product labels such as locale, landing type, input method, expiry option, password-enabled status, coarse size range, referral channel, and result code. Query strings, URL fragments, published content, share slugs, management tokens, email addresses, and account identifiers are not included. Standard browser communication may expose the user agent, screen size, referrer, and IP address to Google at collection time; Google states that GA4 discards IP addresses before logging them.

Why and for how long

Data is used to create, protect, operate, understand, and improve temporary links and to prevent abuse. The selected expiry ends public access; it does not automatically delete the submitted source or file metadata. Source and file metadata may remain after link expiry until the creator deletes the share, a signed-in user deletes the account, or retention is no longer necessary for the stated service, security, or legal purpose. HTML2WEB does not rely on a blanket five-year rule for all uploaded content. First-party product-measurement events currently have no automatic fixed deletion window and are retained while needed to understand and operate the service; this retention is reviewed periodically. Browser sessions expire after seven days, while rate-limit identifiers rotate or expire with their bounded quota windows. Security, order, customer, refund, subscription, and entitlement records may remain after content or account deletion where needed to preserve a purchase, prevent fraud, resolve a transaction, provide support, or satisfy accounting and legal obligations. Inquiry messages and reply addresses are retained while needed to review, respond to, and improve the service, then removed when they are no longer needed for those purposes.

Service providers

Cloudflare provides the application runtime, database, DNS, and delivery network. Google provides aggregate analytics for public pages. The sign-in provider you choose currently provides Google or GitHub OAuth. The payment provider identified at checkout processes payment, tax, receipt, subscription, and refund information under its own privacy policy and buyer terms. We update this notice when a new category of provider materially changes how personal data is handled.

Your choices

Use the private management link to update or delete a share and its retained source. You can block or clear Google Analytics cookies, local storage, and iill cookies in your browser at any time; doing so starts a new pseudonymous session and may require you to unlock protected previews again. Signed-in users can manage linked accounts and request account deletion from the account page. For an account access or privacy request, emailcontact@iill.dev.