Privacy policy
How we handle your data.
What Sardinia Code Foundry S.r.l. collects when we build you a preview, when you chat with it, and when you become a customer — and how to opt out of any of it.
Last updated 2026-07-24
1. Who we are
Sardinia Code Foundry S.r.l. ("we", "us"), based in Olbia, Italy, is the data controller for the personal data described in this policy. We design and generate redesigned websites for existing businesses, let you preview and chat-edit them before you commit to anything, and host them if you become a customer.
2. What data we collect
About the business we're redesigning
When we build a preview of your site, we crawl your existing, publicly published website: page text, navigation structure, publicly listed contact details (name, address, phone, email), and images already on the site. We never invent facts, reviews, or credentials that aren't already public on your site.
About visitors of a preview link
Opening a protected preview link creates an anonymous session identifier stored in a cookie, so the same browser is recognized on return visits without re-entering the link. We log an IP address in salted, hashed form (not the raw address) together with a coarse, IP-derived location, and basic user-agent details, for abuse prevention and to understand who's looking at a preview.
Chat-to-edit conversations
Messages you send through a preview's chat sidebar, any files you upload there (photos, documents), and the resulting edit history are stored so the conversation can continue across visits and so a human operator can step in when asked.
Account data
If you create an account (free or paid), we store your email address, a securely hashed password (we never store or see your plain-text password), the website(s) linked to your account, and your edit-token usage.
Payment data
Paid plans are processed entirely by Stripe. We never see or store your card number — we only receive confirmation that a payment succeeded, plus a Stripe customer/subscription reference.
3. Why we process it
- To generate and host the redesigned preview of your business's website.
- To let you chat-edit that preview, meter the edit budget your plan includes, and let a human operator take over when you ask for one.
- To run your account (login, dashboard, downloadable source code) if you sign up.
- To process payments and manage subscriptions, via Stripe.
- To send you the initial outreach email showing you the preview, and to honor an unsubscribe request permanently.
- To prevent abuse of preview links and chat, and to keep the service running reliably.
4. Legal basis
Where you're contacted as a representative of a business (B2B outreach to a publicly listed company address), we rely on legitimate interest: we identify ourselves truthfully, explain why we're writing, and give you a working, permanent opt-out in every message. Where you create an account or make a payment, processing is necessary to perform that contract with you. Where local law requires your consent for a specific processing activity, we ask for it separately.
5. Who we share it with
We use a small number of processors to run the service, each bound to only use your data to provide their service to us:
- Stripe — payment processing for paid plans.
- Anthropic (Claude) — the AI model that helps generate copy and carries out chat-to-edit requests you make on a preview; content you send in chat may be processed by this model.
- octa.space — GPU hosting used by one of our two site-generation engines.
- Cloudflare — DNS, CDN, and abuse protection in front of our servers.
- Google Workspace — our outbound email relay, and (separately) the Google Places API we use for our own prospecting, unrelated to your personal data.
We do not sell personal data, and we do not share it with anyone for their own marketing purposes.
7. How long we keep it
We keep preview, chat, and account data for as long as your account or preview is active, or as long as reasonably needed to respond to your inquiry if you never became a customer. We keep an unsubscribe record indefinitely, since its entire purpose is to remember not to email you again. You can ask us to delete your data sooner at any time (see Section 8).
8. Your rights
Under the GDPR, you have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority (in Italy, the Garante per la protezione dei dati personali). To exercise any of these rights, contact us using the details in Section 12.
9. International transfers
Some of our processors (including Anthropic and Stripe) may process data outside the European Economic Area. Where that happens, we rely on the safeguards those providers offer for international transfers, such as Standard Contractual Clauses.
10. Outreach email & unsubscribing
If we've never worked with you before, the first email you get from us is a one-off, personally sent preview of what your business's site could look like — never bulk or automated blasting. Every email we send carries a one-click unsubscribe link that permanently stops any further outreach to that address, with no need to log in or reply. You can also just reply STOP to the same effect.
11. Changes to this policy
We may update this policy as the service evolves. The "last updated" date at the top always reflects the current version, and material changes will be reflected here directly.
12. Contact
Sardinia Code Foundry S.r.l.
Olbia, Italy
[email protected]