Legal
Privacy Policy
Last updated 18 September 2026
Wondersite ("we") is operated by App Forge Labs LLC. This policy explains what we store, why, who processes it on our behalf, how long we keep it, and how to have it deleted. Questions: [email protected].
What we store and why
- Redesigns. The website address you submit, a screenshot of its homepage, the public text, image addresses and contact details we read from it, the redesign we generate, and a log of the build. We keep these so you can revisit, share and export your redesigns.
- Account details. With Google sign-in we receive your Google account identifier, email address, name and profile picture; with an email link, only the address you enter. We use them to create and recognise your account.
- Pitch branding. If you are on Pro and fill it in: the name, email and website shown on your pitch pages.
- API keys. Only a one-way hash of each key, its name and when it was last used.
- Usage and abuse limits. A one-way hash of your IP address and an anonymous browser cookie, used only to apply the free daily limit and rate limits.
- Payments. Stripe processes card payments; we store your Stripe customer and subscription identifiers and status, never card details. For x402 API payments we store the payer's wallet address, amount and transaction reference.
- Technical logs. Records of errors and operations, kept for debugging and security.
Processors
- OpenRouter and the model provider it routes to (currently Google) receive the public text of the website being redesigned, to write the redesign. They do not receive your account details.
- TypeSafe, through OpenRouter, receives the page title, the start of the homepage text and the site's link labels, to decide whether the site can be redesigned and which pages to read. It does not receive your account details.
- Stripe handles subscriptions and billing.
- Resend sends sign-in emails.
- Google provides optional sign-in.
- Hetzner hosts our servers and database; Cloudflare provides the network in front of them and backup storage.
- x402 facilitator (Dexter, x402.dexter.cash) verifies and settles on-chain API payments on Base.
Generated pages load fonts from Google Fonts, and images from the original website, in your browser.
Cookies
We use a sign-in session cookie and, before you sign in, an anonymous cookie that ties the redesigns made in your browser to you. Both are essential. We do not use advertising or cross-site tracking cookies.
Sharing
A redesign is visible to anyone who has its link; links are long and random, and redesigns are not listed or indexed. We never sell personal data.
Retention and deletion
Redesigns stay until you delete them from the app, or until your account is deleted. Sessions and sign-in links expire automatically. To delete your account and everything in it, email [email protected] from your account's address; we will do so within 30 days. Encrypted backups roll off within 30 days after that.
Website owners
If a redesign of your website was created and you want it removed, email us with the website address and we will delete it.
Changes
We will update this page when our practices change and note the date above.