Last updated 2026-09-09 · htmlimport · Switzerland
This explains what htmlimport (operated by htmlimport) collects, why, and what happens to it. Short version: we keep the minimum needed to run accounts and billing, we do not track you across the web, and page captures are processed and then discarded.
Account data. Your email address; for paid plans, the Stripe customer and subscription identifiers. We never see or store card numbers — Stripe does.
License keys. Only a cryptographic hash of each key, its first characters, an optional label you give it, and when it was created, last used and revoked.
Usage records. For each capture: the URL you captured, the widths, how long it took, whether it succeeded, and a timestamp. This is what your monthly credits are metered from and what you see on your account page.
Captures. The rendered page — its layout, text, images and styles — is held on the server only while the job runs and for up to 15 minutes afterwards so the plugin can fetch the result; then it is deleted. Reference screenshots and pixel diffs are handled the same way. Bookmarklet captures are made in your own browser and are never uploaded unless you paste them into the plugin, which sends nothing to us.
Sign-in links. One-time links are signed tokens containing your email and an expiry; we keep a short-lived, in-memory count of requests per address to limit abuse.
Server logs. Standard request logs (time, path, status, IP address, user agent) kept by our hosting provider for a limited period for security and debugging.
No advertising trackers, no analytics cookies, no fingerprinting. The website sets no cookies at all.
To provide the Service you asked for (contract): accounts, keys, metering, billing, sign-in emails. To keep the Service secure and prevent abuse (legitimate interest): logs, rate limits, the private-network block. To send you the emails the Service needs — sign-in links, receipts, notices about changes — which are not marketing.
Processors that run parts of the Service: Railway (hosting and database, United States), Stripe (payments), Resend (transactional email), Cloudflare (DNS). Each processes data only to provide its service to us. Web pages you capture are fetched from their own servers, which see a request from our infrastructure, not from you. We do not sell or share personal data for advertising.
Account, key and usage data: for as long as you have an account, then deleted within 30 days of a deletion request (invoices are kept as long as tax law requires). Captures: minutes, as described above. Logs: the hosting provider's retention window, typically days to weeks.
You can ask for a copy of your data, correct it, or have your account and data deleted by emailing hello@htmlimport.com. Under the Swiss Federal Act on Data Protection and, where it applies to you, the GDPR or similar laws, you also have rights to object to or restrict certain processing and to complain to your local data-protection authority. We answer within 30 days.
Our servers are in the United States. Where data moves from Switzerland, the EU or the UK, the processors above rely on recognised safeguards (standard contractual clauses or equivalent). Ask us if you want details.
Keys are stored hashed; secrets are held in the hosting environment, not in code; all traffic is encrypted in transit. No system is perfectly secure, and if a breach affects you we will tell you without undue delay.
The Service is for professionals and is not directed at children under 16.
We will post changes here and, for material ones, email account holders. Contact: hello@htmlimport.com.