Privacy Policy
1. Introduction
AllGoodInsp ("we", "us", "our") is a curated design reference gallery. This policy explains what data we collect, how we use it, and your rights regarding that data.
By using AllGoodInsp, you agree to the practices described in this policy.
2. Information we collect
Account data (via Google OAuth)
When you sign in with Google, we receive and store:
- Name
- Email address
- Profile image URL
- Google account identifier
We do not receive or store your Google password. We do not access your contacts, calendar, Drive, or any other Google service data.
User-generated data
Data you create through your account:
- Favorites and collections
- Site submissions
- Credits claimed on featured sites
API keys
If you generate an API key, we store a SHA-256 hash of the key and a prefix for display purposes. The full key is shown only once at creation and cannot be retrieved afterward. We log the last usage timestamp for each key.
Automatically collected data
When you visit AllGoodInsp, we may collect:
- IP address
- Browser type and version
- Pages visited and time spent
We do not use third-party analytics or advertising trackers.
3. How we use your information
- Provide the service — display your profile, manage favorites, collections, credits, and submissions
- Authenticate requests — verify your identity and API key access
- Improve the service — understand usage patterns to make AllGoodInsp better
- Communicate — respond to your inquiries and notify you about changes to your account or submissions
We do not sell, rent, or share your personal data with third parties for their marketing purposes.
4. Cookies
We use essential cookies only:
- Session cookie — keeps you signed in across page visits. Expires when you sign out or after 30 days of inactivity.
We do not use advertising, tracking, or third-party cookies. Disabling cookies in your browser will prevent you from signing in.
5. Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Google OAuth | Authentication | Authorization code exchanged for profile info |
| Cloudflare Workers | Application hosting | Request metadata (IP, headers) |
| Cloudflare D1 | Database storage | All account and application data |
| Cloudflare R2 | Image storage | Site screenshots |
Each service operates under its own privacy policy. We encourage you to review Cloudflare's Privacy Policy and Google's Privacy Policy.
6. Data sharing
We may share your data only in the following circumstances:
- Service providers — third-party infrastructure listed above, solely to operate the service
- Legal requirements — when required by law, regulation, or legal process
- Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice
7. International data transfers
AllGoodInsp runs on Cloudflare's global network. Your data may be processed in regions outside your country of residence. Cloudflare maintains appropriate safeguards for international data transfers.
8. Data retention and deletion
We retain your data for as long as your account is active. You can request deletion of your account and all associated data (favorites, collections, credits, submissions, and API keys) by contacting us. We will process deletion requests within 30 days.
Some data may be retained beyond this period if required by law.
9. Your rights
General rights
Regardless of your location, you may:
- Request access to the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Revoke API keys at any time from your account page
GDPR (European Economic Area)
If you are in the EEA, you additionally have the right to:
- Data portability — receive your data in a structured, machine-readable format
- Restrict or object to processing
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
Our legal bases for processing are: contract performance (providing the service), consent (account creation), and legitimate interest (service improvement and security).
CCPA (California)
If you are a California resident, you have the right to know what personal data we collect, request its deletion, and opt out of any sale of personal data. We do not sell personal data.
10. Children's privacy
AllGoodInsp is not directed at children under 13. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 13, we will delete it promptly.
11. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), hashed API keys, and access controls. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this policy from time to time. Significant changes will be communicated through the site. The "last updated" date at the top reflects the most recent revision.
13. Contact
For privacy-related questions or to exercise your rights, reach out via the contact page.