The software is still under production — some features may be unstable.

Legal

Privacy policy

How Demofy collects, uses, stores and protects your information.

Last updated: October 2026

1. Information we collect

Demofy collects the minimum personal data required to provide the website demo creation, editing, preview and account-management service:

  • Account information: name, email address, password hash and account preferences at registration.
  • Billing information: customer and subscription records needed for billing. Payment card details are processed by Paddle and are not stored by Demofy.
  • Website and demo data: business names, industry details, logos, colours, services, template selections, demo content, editable element values, preview links and project metadata used to create and manage demos.
  • Usage, security and telemetry: IP address, browser type, device information, operating system, referrer URL, authentication events, plugin usage accounting, quota state, and operational logs needed to keep the service reliable and secure.

2. How we use your information

We use collected data to operate, maintain and improve the Demofy platform:

  • Account and authentication: sign-in, account settings, authentication and password security.
  • Website demo creation and management: processing template choices, business details, content edits and account actions to create, preview, update, list, share and delete demos.
  • Customer support: responding to tickets, inquiries, billing issues and feedback.
  • Platform improvement, quota enforcement and security: monitoring performance, enforcing account limits, preventing fraudulent or abusive usage, and improving feature stability.

3. ChatGPT and connected app integrations

When you choose to connect Demofy through ChatGPT or another connected app, Demofy receives only the information needed to authenticate your Demofy account and carry out the actions you request. Demofy does not receive your entire ChatGPT conversation by default.

  • Data received: Demofy account identity required for authentication, OAuth authorization details, requested template/demo actions, demo content or edits submitted by the authenticated user, and technical or security logs required to operate and protect the integration.
  • Purpose: Demofy uses this information to authenticate your account, execute requested plugin actions, create, edit and manage your demos, enforce quota and security rules, maintain reliability, and prevent abuse.
  • Restricted data: the ChatGPT integration is not designed to collect payment card information, passwords, multi-factor or one-time passcodes, API keys, government identifiers, or protected health information. Payments and billing management take place outside ChatGPT.

4. Cookies and tracking

Demofy uses essential cookies and local storage tokens for core functionality:

  • Authentication: maintaining active login sessions and secure API requests.
  • Preferences: saving interface preferences such as active theme and project state.
  • Performance analytics: aggregate statistics on page performance and load speed.

5. Data security

We apply industry-standard technical and organisational controls to protect user data against unauthorised access, disclosure or destruction. Data in transit between clients and Demofy servers is encrypted with TLS 1.3 and stored in secure data centres.

6. Third-party services

We work with a small set of trusted provider categories to run the platform:

  • Supabase: authentication, database and storage services.
  • Paddle: payment processing and subscription management (PCI-DSS Level 1 compliant).
  • Google Analytics: aggregate telemetry and usage metrics.
  • Cloudflare and hosting providers: application hosting, edge routing, security and operational delivery.
  • Resend: transactional email notifications where email delivery is part of a requested workflow.
  • OpenAI: when you choose to connect Demofy through ChatGPT, OpenAI provides the ChatGPT surface and OAuth client interaction for the connected app.

7. Data retention

Demofy retains personal data only for as long as needed to provide the service, meet legal and billing obligations, protect the platform, or maintain account-level records. Retention depends on the data category:

  • Account information: retained while your account is active and deleted or anonymised after account deletion where Demofy no longer needs it for legal, security or billing records.
  • Demo and project content: retained until you delete the demo, your account is deleted, or the demo reaches its configured retention state. Active temporary projects use 7-day retention by default unless marked Keep or Client closed.
  • Plugin usage and quota records: retained as account-level usage and accounting records for the life of the account or as otherwise required for billing, abuse prevention and support. Deleted plugin demos remain counted toward lifetime creation limits.
  • Billing records: retained as needed for subscription management, tax, accounting, chargeback and legal compliance.
  • Security and operational logs: retained only as needed to maintain reliability, investigate abuse or security events, and operate the service.

8. User rights and control

Depending on your jurisdiction, you have specific rights over your personal information:

  • Access and retrieve your data
  • Correct inaccurate information
  • Request complete account deletion
  • Export your generated project assets
  • Delete demos you no longer want to keep
  • Disconnect or revoke ChatGPT OAuth access from the connected app or account settings where available
  • Contact Demofy about privacy requests, account deletion, or data access questions

9. Contact us

Questions, concerns or data requests regarding this policy can go to our support team:

[email protected]