Privacy Policy
Last updated: September 2, 2026
This policy explains what information Digital Potter collects, why we collect it, and the choices you have. We keep it in plain language on purpose — if anything here is unclear, ask us and we will explain it directly.
1. Who we are
Digital Potter LLC (“Digital Potter”, “we”, “us”) is a United States company. We operate digitalpotter.tech — an AI website builder — and theDavid CMS, the platform that hosts and powers the websites built with it. You can reach us about anything in this policy at hello@digitalpotter.io.
2. Our platform vs. sites built on it
This policy covers the Digital Potter platform: our website, the builder, your account, and our own marketing. It works differently for the websites our customers create with the builder. Each of those sites is controlled by its owner. When a visitor interacts with a customer’s site — fills in a contact form, places an order, books an appointment — we store that data on the site owner’s behalf, as their hosting provider. The site owner decides what to collect and how to use it; visitors to those sites should consult that site’s own privacy practices. Our Terms of Service require site owners to use that data lawfully.
3. Information we collect
- Account information. Your name, email address, and a password. Passwords are stored only as a cryptographic hash — we cannot read them.
- Content you create.The text, images, and settings of the sites you build, and the descriptions and prompts you send to the AI to generate or edit them. A reference screenshot you upload to guide a site’s design is stored privately, readable only by your account, used solely for that purpose, and deleted automatically two weeks after its last use.
- Billing information. Payments are processed by Stripe. We store your subscription state and invoice history; we never see or store your full card number.
- Usage and log data. Standard server logs — IP address, browser and device information, pages requested, and timestamps — used to keep the service secure and reliable.
4. Data from visitors to customer sites
Sites hosted on our platform generate server logs, and their forms, stores, and booking tools submit data that we store for the site owner. We process this information only to provide hosting and the platform features the site owner has enabled. We do not sell it, use it for our own marketing, or build profiles from it. The site owner is responsible for handling it lawfully and for responding to their visitors’ privacy requests; we assist owners with deletion and export when they ask.
5. How we use information
- To provide, operate, and improve the platform.
- To process billing and send transactional email — receipts, email verification, service notices.
- To prevent abuse, fraud, and attacks on the platform.
- To send product updates and marketing email only with the consent you gave at signup. Every marketing email includes an unsubscribe link, and unsubscribing never affects service email.
7. Service providers
We share data with a small set of providers, only as needed to run the service:
- Amazon Web Services — infrastructure and hosting.
- Stripe — payment processing and billing.
- Cloudflare — bot protection (Turnstile).
- Mailgun — email delivery.
- Google Analytics and HeyCatch — product usage analytics (pages visited, features used, and session replays of the builder interface) so we can improve the product.
- Anthropic — the AI model that processes your prompts to generate and edit sites.
8. AI processing
When you generate or edit a site, your prompt and the relevant site content are sent to our AI provider to fulfill that request. We do not use your prompts or your site content to train AI models.
9. Data retention
We keep your data while your account is active. If you cancel a paid plan, your site is unpublished at the end of the billing period and its data is retained for 30 days so you can export it or reactivate; after that it is deleted. Some billing records are kept longer where the law requires it.
10. Your rights
You can access and correct your account information at any time from your dashboard. You can also ask us to export or delete your data by emailing hello@digitalpotter.io — we will verify the request came from you and respond promptly. Depending on where you live (for example, California), you may have additional statutory rights to access, deletion, and non-discrimination; we honor requests under those laws through the same address.
11. Security
All traffic is encrypted with HTTPS, passwords are hashed, sessions use httpOnly cookies, and internal access follows least-privilege practices. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you as the law requires.
12. Children
The service is not directed to children under 13, and we do not knowingly collect their data. If we learn an account belongs to a child under 13, we delete it.
13. Where data is processed
We are a US company and process and store data in the United States. If you use the service from elsewhere, you are transferring your data to the US.
14. Changes to this policy
When we change this policy we will post the update here and revise the date at the top. For material changes we will also notify you by email.
15. Contact
Questions, privacy requests, or concerns: hello@digitalpotter.io.