↘ SpillwayBack to product

Policy / effective 27 August 2026

Private by construction.

Short version: the documentation site does not collect, transmit, or retain your demo payload. The demo runs in your browser memory and is erased on refresh.

Information we collect

We do not use accounts, analytics, advertising pixels, cookies, or third-party scripts. Our static hosting provider may process ordinary request data such as IP address, timestamp, URL, and user agent for security and delivery logs. The project does not receive a copy of your demo input.

Local processing

The test bench generates temporary encryption keys and encrypted objects using Web Crypto in the current browser tab. It does not use localStorage, IndexedDB, or remote object storage. A service worker may cache public site files for offline use; it does not cache form input.

Library users

The npm library has no telemetry. When you deploy it, you control its object store, keys, retention, logs, and legal basis. Your own privacy notice should describe that processing.

Your choices

Clear the site's cached files with your browser's site-data controls. For repository questions, open an issue on GitHub.