Information Sidebox stores
Sidebox stores account and workspace information you provide, including project names, descriptions, links, brand references, and private assets. None of it is included in product analytics.
Connected providers supply bounded, read-only snapshots needed for the features you use. Sidebox does not retain payment-customer personal information from Stripe or Polar in its product snapshots.
Connected services and credentials
Provider connections are read-only. Sidebox requests narrow permissions and encrypts stored provider credentials. Disconnecting stops future refreshes; cached provider data follows the product's documented deletion behavior.
Service providers that process information for Sidebox include Cloudflare, Neon, Polar, transactional email providers, Sentry (error reports from the web app, with identifiers, query strings, and contact details removed), PostHog (product analytics, only with your consent), and any provider you choose to connect, including GitHub, Vercel, Google Search Console, PostHog, and Stripe.
Product analytics and cookies
With your permission, Sidebox uses PostHog to understand how the product is used. Nothing is loaded or stored for analytics until you choose Allow in the consent banner. If you decline, or your browser sends a Global Privacy Control signal, analytics stay off.
When allowed, Sidebox records page views as page types (for example, "a project's Revenue page", never the address itself) and a fixed list of actions: account creation and sign-in (including which sign-in method was used), checkout started, project created or imported, link added, asset uploaded, provider connected or mapped, the kind of external service opened, command palette use, date range changes, and digest preference changes. Signed-in events are linked to a random account identifier, never your name or email address.
Events never include project names, URLs, or descriptions, link labels, filenames, search queries, payment records, credentials, asset contents, or data from connected providers. Session recording and automatic click capture are off. PostHog stores a cookie and local storage entry to recognize your browser between visits.
You can change your choice at any time in Account → Privacy, or with Privacy choices in the site footer. Withdrawing consent stops collection and deletes PostHog's cookie and local storage from your browser.
Retention and your choices
Workspace information is retained while your account is active. You can delete your account from Account Settings. Account deletion removes account-owned database records and schedules private object cleanup; object cleanup runs every three hours and may require retries.
You can download individual private assets. For requests to access, correct, delete, or receive your personal data, contact contact@sidebox.dev. There is no self-service bulk export. See Data Handling for more detail.
How we use your information
We use account and workspace information to provide the service, manage subscriptions, and respond to support requests. Where applicable, we rely on performing our agreement with you, legal obligations, and legitimate interests in keeping the service secure. Optional product analytics relies on your consent.
Our service providers may process information outside your country, including outside the European Economic Area. Where required, appropriate safeguards must apply to those transfers. You can contact us about your privacy rights or complain to your local data protection authority.
Contact
Privacy questions: contact@sidebox.dev.
Contact support · contact@sidebox.dev