1. Who we are
MZED STUDIO LIMITED (the “Operator,” “we”) operates Shortwind Cloud and is the controller of the personal data described here. Contact us at privacy@shortwind.dev.
2. Data we collect
- Account data: your email address, an optional name, and authentication identifiers, so you can sign in and own an account.
- Content you publish: the HTML you publish and its stored, versioned artifacts, page slugs/subdomains, tags, and visibility settings. Published content may itself contain personal data you choose to include — you control that.
- API tokens: we store only a one-way hash of each token secret, never the secret itself, plus its scopes and metadata.
- Custom domains: the hostnames you connect and their certificate/validation status.
- Billing data: if you buy a paid plan, our payment processor collects and processes your payment details; we store a customer and subscription reference and plan status, not full card numbers.
- Usage and operational data: metered usage (such as publish counts and storage), an audit log of actions on your account, recipe-edit events, and server logs used to run, secure, and debug the Service.
- Abuse reports: when someone reports a page, we collect the report details and any contact information the reporter provides.
- Cookies: the dashboard uses a session cookie to keep you signed in. We do not use advertising cookies.
3. How we use data
- To provide, operate, secure, and improve the Service.
- To authenticate you and your API clients and enforce scopes and limits.
- To detect, prevent, and respond to abuse, fraud, and illegal content — including scanning content at publish time and acting on reports.
- To process payments and manage subscriptions.
- To communicate about the Service, security, and legal notices.
- To comply with legal obligations and enforce our Terms.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service you request); our legitimate interests (to secure the Service, prevent abuse, and operate our business); legal obligation (for example mandatory reporting and preservation of CSAM); and, where applicable, consent, which you may withdraw.
5. Who we share data with
We do not sell your personal data. We share it with service providers (processors) who help us run the Service under contract, including:
- Cloudflare: Edge/CDN serving, object storage (R2), key–value routing, and custom-domain TLS certificates.
- Convex: Application backend and control-plane database.
- Stripe: Payment processing for paid plans.
- NCMEC: Receiving mandatory CSAM reports (as required by law).
- Law enforcement or others where required by law, to protect rights and safety, or in a corporate transaction (merger, sale).
6. Retention
- Account and content: kept while your account is active. When you delete content or close your account, we remove it from active serving; backups age out on our normal cycle.
- Preserved (quarantined) material: content removed for a legal or safety reason may be sealed and retained for the period the law requires (for example, CSAM records for at least the statutory preservation window). This retention survives account deletion.
- Tokens: retained (as hashes) until revoked or expired.
- Logs and audit records: retained for a limited period for security and compliance.
7. Your rights
Depending on where you live (for example under the GDPR/UK GDPR or the CCPA/CPRA), you may have the right to access, correct, delete, or export your data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. Shortwind Cloud supports the core rights directly:
- Access / portability: export a machine-readable bundle of your account’s data from the API/CLI.
- Deletion / closure: close your account, which revokes your credentials and takes down your active pages — except material under a legal-hold or preservation obligation, which we must retain.
To exercise a right we don’t automate, contact privacy@shortwind.dev. You may also have the right to complain to your local data protection authority.
8. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
9. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data. Content that sexually exploits minors is strictly prohibited and handled under our Acceptable Use Policy.
10. Security
We use technical and organizational measures to protect data — including hashing token secrets, scoping credentials, and encrypting data in transit. No system is perfectly secure, and we cannot guarantee absolute security.
11. Changes
We may update this policy; material changes take effect on posting with a new effective date, and we will take reasonable steps to notify you.
12. Contact
MZED STUDIO LIMITED — privacy@shortwind.dev, 8 Eastfield Close, Townhill, Swansea, SA1 6SG, United Kingdom (Company No. 15854033).