Privacy at Homespun
Plain language, no legal padding. Last updated October 3, 2026.
Who runs this
Homespun is built and run by an independent developer. The controller responsible for your data under the GDPR is Lalit Singh, trading as Homespun (sole proprietor), Friedrich Str. 3, 15537 Erkner, Germany. For anything about your data, email privacy@homespun.dev.
What we store
- Your email address, to sign you in and match you to your account.
- A display name, only if you set one yourself in Settings. Signing in with Google gives us your email; it does not pull a name from your Google profile.
- One-time sign-in links and sign-in sessions, so a link works once and you stay signed in on your device.
- The content you and your agents create inside your apps: rows of data, uploaded files, and activity feed entries.
- A stamp on every row recording who created it and who last wrote it: an account holder, one of your agents, someone using an access link, or an anonymous visitor.
- How your account was created, for example from the sign-in page or by connecting an AI assistant. If you connected one, we also keep the name it registered under.
- Whether you agreed to product-update email, and when, if you ticked that box. You can turn it off in Settings.
- Your answer to "How did you hear about Homespun?", if you choose to answer it. We ask once, on your home page just after you sign up, so we know which places people actually find us through. It is optional: you can close the question instead, and either way we never ask again. If you pick "Something else" we store the short note you type. Nothing here is linked to any advertising or third party, and your answer is deleted along with the rest of your data when you delete your account.
- A count of visits to our own public pages, so we can tell whether anyone is finding us. We record the page, the country your network address maps to, the site that linked you, any campaign tag in the link, and a coarse device and browser type (such as "mobile" and "Safari"). We do not set a cookie, we do not store your IP address, and none of it is linked to your account or to any advertising or third party. To count returning visitors without identifying anyone, we keep a one-way scrambled fingerprint of your network address that changes every day and on every page, and we delete those after two days. Everything that remains is a plain total.
- Short-lived counters that cap anonymous uploads and writes on apps that turn that limit on. They are keyed to a shortened network range, never the full address, and we delete them after two days.
- If you upload a file to an app without signing in, the shortened network range of your connection, kept with the file. Shared file links also record the shortened network range of the first and the latest download.
- Records of the email, in-app, push and webhook notifications that apps send, including the message or payload, and the reply a webhook received.
- Problem reports and short design notes that an AI assistant writes and sends to us.
- Operational logs and telemetry (requests and errors) that keep the service running and let us debug problems.
Why we use it
- Signing you in: your email address, sign-in links and sessions.
- Running your apps: your content, the author stamps and your display name. This is the service you asked for.
- Sending the email you trigger: we use your email address to send sign-in links, invitations to an app, notices that you were added to an app, app ownership transfers, and the notifications your own apps are set up to send.
- Other email: if you sign up on the console and have not connected an AI assistant, we send up to three short plain-text emails from the founder, about 1 hour, 1 day and 3 days after you sign up. Each one has a link that stops them. We send product updates only if you ticked the box for them.
- Security and abuse prevention: we use your network address briefly to rate-limit requests, and the short-lived counters described above to limit anonymous abuse of apps.
- Operating and debugging the service: operational logs and telemetry, the count of visits to our public pages, and alerts that tell us when something breaks.
- Understanding how people find us: your optional "How did you hear" answer, and how your account was created.
- Improving Homespun: problem reports your agents send us, and internal dashboards of account activity.
We do not use your data for anything else.
Why the law lets us
- Contract: running the service you asked for, which covers sign-in, your apps and content, and the email you trigger.
- Legitimate interests: security and abuse prevention, logs and telemetry, counts of visits to public pages, onboarding emails, alerts to us, and improving Homespun. You can object to any of these. See "Your rights".
- Consent: product-update email. You can withdraw consent in Settings at any time.
Who processes it for us
These service providers handle data on our behalf, only to run Homespun.
- Microsoft Azure hosts the service. It runs the application, the database, file storage and logs, and its Communication Services delivers the email we send. The hosting is in the North Europe region, and the email service is set to a European data location.
- Cloudflare runs our DNS. It sits in front of the apps people publish on homespunapps.com, custom domains and our documentation site, so it sees those requests, including network addresses. It also routes mail sent to our @homespun.dev and @homespunapps.com addresses to our mailbox, which Google hosts.
- Telegram delivers internal alerts to us. When an AI assistant files a problem report about Homespun, the report's text, the agent's id and the app's id are sent to our Telegram chat.
These parties act under their own privacy policies, not as our processors:
- Google, only if you choose to sign in with Google. We ask Google only for your verified email address.
- Apple, Google and Mozilla push services, only if you turn on push notifications for an app. They carry the notification to your device. The notification holds the app name, the collection name and a link, and never the contents of a row.
- The AI provider you connect, described in the section on AI assistants.
Transfers outside Europe
Microsoft Azure keeps your data in the North Europe region. Some other parties may process data outside the European Economic Area: Cloudflare, Google, Telegram, the browser push services, and the AI provider you choose to connect. Their handling of that data is covered by their own terms and privacy policies.
AI assistants such as Claude or ChatGPT
When you connect an AI assistant to Homespun, the assistant sends requests to Homespun on your behalf, using access you granted. Each request is a tool call: the name of a tool and the details the assistant fills in. Files for a deploy can also arrive as a direct upload from the assistant's environment instead of inside a call. We store them the same way.
Whatever those calls and uploads contain, such as the data for a row or the files for an app, is stored as described on this page. If you ask the assistant to save part of your conversation into an app, that text reaches us as content and we store it.
Your assistant may also, without being asked, send us problem reports about Homespun itself and save short notes about your design preferences. These are free text the assistant writes, so they can reflect your conversation.
Homespun does not receive your chat history. It receives only what the assistant chooses to send. Our logs record which tool was called and which assistant made the call, never what the call contained.
How the assistant's provider handles your conversation is governed by that provider's own privacy policy.
Apps you build or use
Apps are built by the people who publish them. When an app collects data from its users, Homespun hosts that data on the app owner's behalf. The owner decides what the app collects and who can see it.
If you use someone else's app, contact that app's owner first about the data you gave it. You can also write to privacy@homespun.dev.
Data sent elsewhere on your instruction
- Webhooks: an app can be set up to send row data to web addresses its owner chooses. We keep each delivery, with what was sent and the reply, for the period listed under "How long we keep it".
- Connections: if an owner stores a credential for a service, we keep it encrypted and attach it only to the web address it is bound to. The app's webhooks and fetchers use it.
- Inbound webhooks: an app can receive data that other services send to it. We store what arrives.
- Third-party resources: an app that declares a CDN or external hosts can make its visitors' browsers load scripts, styles or data from those parties, which then see the visitor's network address.
What other people see
Inside a shared app, other members see display names only. The app's owner, and any AI assistant the owner connects to the app, can see the email addresses of the app's members and the data members put into the app.
Public content
Your publisher profile (handle, display name, bio and link), community templates you publish and reviews you write are public.
Deleting your account does not unpublish them straight away. When we purge the account, your profile is removed, a template you published stays with its publisher link removed, and your reviews stay. To take a template down first, unpublish it. To remove a review, email privacy@homespun.dev.
What we don't do
- No advertising.
- We never sell your data or share it for anyone else's own use. The service providers above process it to run Homespun. Google, for sign-in, and the browser push services act under their own privacy policies.
- No cross-site trackers.
- No third-party analytics. Everything we count, we count ourselves, on our own servers. This site ships no tracking scripts of any kind.
- No profiling and no automated decisions about you. Nothing you tell us feeds an advertising or scoring system.
Where your data lives
Homespun runs on Microsoft Azure, in the North Europe region.
Cookies and local storage
We set only the cookies Homespun needs to work. There are no tracking or advertising cookies.
- homespun_login keeps you signed in to the console.
- homespun_ml_nonce and homespun_google_oauth are short-lived. They tie a sign-in to the browser that started it.
- __Host-homespun_session keeps you signed in to an app. __Host-homespun_linkpass, __Host-homespun_grantpass and __Host-homespun_visitor hold a share link, an access link or an anonymous visitor identity for one app.
Apps also keep a session token, access links and display preferences in your browser's local storage. All of this is strictly necessary for the service you asked for.
How long sign-ins last
- A sign-in link works once and expires after 15 minutes.
- A console sign-in lasts 30 days.
- An app sign-in lasts 30 days.
- The access an AI assistant gets lasts 30 days. You can disconnect it sooner at any time.
How long we keep it
- Your account: when you delete it, your apps go offline, you are signed out and your agents stop working at once. We purge your account and the data it owns 30 days later. A few records stay: rows you wrote in other people's apps (without your name), public reviews and community templates you published, problem reports your agents filed, and deletion records.
- An app you delete: it goes offline at once and stays in Recently deleted on your Apps page for 30 days, so you can bring it back. After that we purge it automatically with all its data. You can purge it sooner yourself, which destroys it immediately and cannot be undone.
- A row you delete: a row deleted in an app can be restored by the app's owner or its agent for 30 days, then it is removed. The owner or agent can also remove a row for good at once. In both cases the activity feed keeps a copy of the row as it was until that feed entry expires, at most 90 days after the change.
- Files you delete: we purge them 30 days after deletion, and the stored bytes go with them.
- Agents: revoking an agent stops it at once. Its record stays on your account until you delete your account, and is purged 30 days after that.
- Activity feed entries: 90 days.
- Network ranges on anonymous uploads: for as long as the file exists.
- Email and webhook delivery records, including the data a webhook sent and the reply it got: 90 days. We keep the one-time confirmation records for external submitters longer, so nobody is emailed twice.
- In-app notifications: up to 180 days. Push subscriptions: removed after 180 days unused.
- Data received through an app's inbound webhooks: 30 days.
- Operational logs: 30 days. Performance and error telemetry (request timings and error reports, with network addresses masked): 90 days.
- Database backups: they are kept for 7 days, so purged data can sit in a backup until then.
- Deletion records: we keep them indefinitely. They hold the record type, ids, the time and the reason, and no content.
Deleting your data
You can delete an app from the Apps page, and you can delete your account and all your apps from Settings. Both are self-service and take effect immediately, on the schedule above. Until the account purge finishes, your email cannot sign in again or start a new account.
Rows you wrote in apps owned by other people stay, because those people rely on them. Your name is removed from them, and they show a generic "a member" label.
Your rights
Under GDPR you can ask to see the data we hold about you, have it corrected, or have it erased. You can also ask us to restrict how we use it, object to uses based on our legitimate interests, ask for a copy in a portable format, and withdraw consent you gave. You can erase your account and your apps yourself, as described above, and you can turn off product-update email in Settings.
There is no self-service data export yet. To get a copy of your data, or to use any other right, write to privacy@homespun.dev any time.
You also have the right to complain to a data protection supervisory authority, for example the one in your country of residence.
Children
Homespun is not directed at anyone under 16, and you must be at least 16, or the age of digital consent where you live, to use it. See the terms of service.
Changes to this policy
We may update this policy from time to time. Changes are reflected by the "Last updated" date at the top of this page.