Draft for legal review. This page has not been reviewed by an attorney and is not final. Do not rely on it as legal advice.

Privacy Policy

Effective date: 2026-09-13 · Governing law: State of Nevada

1. What this covers

This policy explains what Atomic Falls collects and stores when you use our dashboard, generate a site, and publish it, and how we handle data submitted through sites your account creates. It applies to the platform itself; sites you build may collect additional data from their own visitors, which is your responsibility as the site owner to disclose to them.

2. What we store

  • Account data — username, email, password (hashed, never stored in plain text), and account preferences.
  • Sites you build — page content, design settings, and the generated site source.
  • Uploads — images and files you add to a site (profile pictures, backgrounds, artwork).
  • Form submissions on your sites — when a visitor to a site you publish submits a form (contact, newsletter, etc.), that submission is stored so you can retrieve it from your dashboard.
  • Usage counters — plan limits like storage and bandwidth used, so we can enforce your plan and show you your usage.

3. Generation on your own device or API key

If you choose to generate a site using your own hardware (a local model on your device) or your own API key for a third-party model provider, your design mockups and prompts are sent directly from your device or key to that provider — not through a platform-operated model, and not visible to us. If you instead use a platform-hosted model, the prompt content needed to generate your site is sent to that model provider on your behalf, as part of the generation request.

4. Hosting keys and bring-your-own-key (BYOK) credentials

If you connect your own API key or hosting/deployment credentials, they are stored encrypted at rest. We don't display a stored key back to you in plain text after you save it, and access to decrypt a stored key is limited to the specific operation that needs it (for example, making a generation call on your behalf with your key).

5. How we use what we store

We use account and site data to operate the platform: to authenticate you, render and host your sites, deliver form submissions to your dashboard, enforce plan limits, and provide support when you ask for it. We use aggregated, non-identifying usage information to understand how the product is used and to improve it.

6. What we don't do

We do not sell your data, your site visitors' data, or your form submissions to third parties. We do not share your account or site content with third parties except where necessary to operate the service (for example, a hosting or email-delivery provider acting on our behalf, or a model provider you've chosen to generate through) or where required by law.

7. Data retention and deletion

We keep your account and site data for as long as your account is active. You can request deletion of your account and its associated data at any time by contacting us at the address below; we'll delete what we can and retain only what we're legally required to keep (for example, billing records), for no longer than necessary.

8. Cookies and sessions

We use a small number of cookies required to keep you signed in (an HTTP-only session cookie) and to remember basic preferences like light/dark theme. We don't use third-party advertising trackers on the platform's own dashboard.

9. Changes to this policy

We may update this policy as the product evolves. If we make a material change, we'll update the effective date above and, for significant changes, notify accounts by email.

10. Governing law

This policy is governed by the laws of the State of Nevada, without regard to its conflict-of-laws principles.

11. Contact

Privacy questions, including deletion requests, can be sent to sysop@atomicfalls.com.

Terms of Service · Privacy Policy