Legal · Privacy
Privacy Policy
Effective and last updated: 20 July 2026
This policy explains how Smolify (“Smolify”, “we”, “us”, or “our”) handles personal data when you visit app.smol.ly, use a Smolify-hosted documentation site, connect an MCP client, import a repository, or use related services (collectively, the “Service”).
1. Scope and our role
For account, website, security, and service-administration data, Smolify decides why and how the data is processed. For repository content that a workspace submits, Smolify generally processes that content to provide the Service at the workspace owner’s direction. Public repository content and documentation may already be publicly available.
This policy does not govern GitHub, your AI or MCP client provider, a customer’s independently operated custom domain, or other third-party services. Their own terms and privacy notices apply.
2. Information we collect
Account information
Name, email address, password-derived verifier, account and session identifiers, and—if enabled and selected—GitHub identity and authorization information.
Workspace and repository information
Project names, visibility, repository URLs, branches and commits, uploaded archives, generated Markdown, source provenance, deployment history, custom-domain settings, and publish-token hashes.
Community content
Documentation ratings, proposed improvements, review decisions, associated account identity, model label, and timestamps.
Technical information
IP address, user agent, request metadata, authentication and security events, cookies, error information, and similar operational logs processed by Smolify or Cloudflare.
Communications
Information you provide in support, privacy, security, or other messages to us.
We receive information directly from you, automatically from your browser or MCP client, from workspace members, and from services you connect, such as GitHub. Please do not upload secrets, credentials, or personal data that is unnecessary for documentation.
3. How we use information
- Provide, authenticate, secure, troubleshoot, and improve the Service.
- Import repositories; generate, search, review, store, and publish documentation; and serve custom domains.
- Operate project-scoped MCP authorization and distinguish public reads from private or mutating operations.
- Prevent abuse, enforce our Terms, investigate incidents, and comply with law.
- Respond to support, privacy, and security requests and send essential service notices.
We do not use your personal data for third-party advertising. Smolify does not run a hosted answer model over your repository content; an AI or MCP client you choose may process information under your separate relationship with that provider.
4. When we disclose information
We disclose information only as reasonably needed to operate the Service, at your direction, or as required by law:
- Infrastructure providers. Cloudflare provides application hosting, network security, D1 database, and R2 object storage services.
- Connected services. GitHub receives repository and API requests when you connect or import from GitHub.
- Workspace members and the public. Workspace members can access workspace content according to their permissions. Public projects expose published documentation, repository provenance, ratings, and review information to anyone.
- Legal and safety disclosures. We may preserve or disclose information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to a valid legal process.
- Business transfers. Information may transfer as part of a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice where required.
We do not sell personal information or share it for cross-context behavioural advertising, and we do not process personal data for targeted advertising.
5. Public and private projects
Choose project visibility carefully. Public projects, their published documentation, source links, and community review activity are intentionally public and may be indexed, copied, or cached by others. Private projects require authentication, but workspace owners control who is invited and what is uploaded or published.
Dashboard session cookies are host-only and are not sent to customer custom domains. Publish tokens are project-scoped, shown once, and stored by Smolify only as SHA-256 hashes.
6. Cookies and similar technologies
Smolify uses cookies and local browser storage that are necessary for authentication, security, OAuth flows, and user-requested functionality. We do not currently use third-party behavioural advertising cookies or third-party analytics cookies. Your browser may let you block cookies, but authentication and private features may stop working.
7. Retention
We retain personal data for as long as reasonably necessary to provide the Service, maintain security and auditability, resolve disputes, enforce agreements, and meet legal obligations. Retention depends on the type of record, project visibility, workspace instructions, active deployments, and legitimate legal or business needs.
When data is no longer needed, we delete it or remove the means by which it can reasonably be associated with an individual. Residual copies may remain temporarily in backups, immutable deployment records, or security logs until their normal expiry, unless longer retention is legally required.
8. Security
We use administrative and technical safeguards appropriate to the nature of the Service, including scoped authorization, prepared database statements, tenant-scoped storage keys, host-only dashboard cookies, hashed publish tokens, HTML sanitization, and encrypted network transport. No system is completely secure, so we cannot guarantee absolute security.
9. International transfers
Smolify and its providers may process information in Singapore, the United States, and other countries where they operate. Where Singapore’s Personal Data Protection Act 2012 (“PDPA”) applies, we take steps intended to ensure that overseas recipients provide a standard of protection comparable to the PDPA, including contractual, technical, and organisational safeguards as appropriate.
10. Your privacy rights
Depending on where you live and subject to legal exceptions, you may ask us to confirm processing; access, correct, delete, or obtain a portable copy of personal data; withdraw consent; restrict or object to certain processing; or appeal a denied request. We may verify your identity and authority before completing a request. We will not discriminate against you for exercising a privacy right.
Singapore
Under the PDPA, you may request access to personal data about you and information about its use or disclosure, request correction, and withdraw consent with reasonable notice. Withdrawal may prevent us from continuing to provide account or private-project features. You may also contact Singapore’s Personal Data Protection Commission.
United States
Residents of states with applicable comprehensive privacy laws may have rights to know, access, correct, delete, or obtain a portable copy of personal data and to opt out of sale, targeted advertising, or certain profiling. Smolify does not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising. Where legally required, we treat a recognised opt-out preference signal, including Global Privacy Control, as a request for the browser or device that sends it.
California notice
In the preceding 12 months, the categories we may have collected are identifiers; account and customer records; internet or other electronic-network activity; professional information supplied through GitHub; communications; and account login information treated as sensitive personal information. We collect these from the sources and for the purposes described above. We may disclose them to infrastructure providers, connected services, workspace members, and legal recipients as described above. We do not use sensitive personal information to infer characteristics about you.
To exercise a right or appeal a decision, email privacy@smol.ly with the subject “Privacy Request” or “Privacy Appeal”. An authorised agent may submit a request where permitted by law, but we may require proof of authority and identity.
11. Children
The Service is intended for adults and professional developers, not children. You must be at least 18 years old or the age of legal majority where you live to create an account. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy to reflect changes to the Service or law. We will update the date above and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
13. Contact and data protection enquiries
Smolify’s Data Protection Contact can be reached at privacy@smol.ly. Please use that address for privacy questions, complaints, access or correction requests, consent withdrawal, and U.S. state privacy requests.