Privacy

tossithere turns an HTML file into a link other people can comment on. That means we hold your documents, so this page is specific about what is stored, who can reach it, and how to remove it. It describes what the service actually does today, not what it might do later.

What we collect

WhatWhy
Your email address and nameTo identify your account and show who left a comment. If you sign in with Google we receive these plus your Google account id, and nothing else: no contacts, no Drive, no calendar.
Documents you publishThe HTML and any assets you push, every version of them, and the file sizes. This is the product.
Comments and their anchorsThe comment text, and a snippet of the document markup it points at so the comment can find its place again after you republish.
Session and API tokensStored as SHA-256 hashes, never in the clear. We cannot recover a token you lose, only issue a new one.
Product analyticsWhich pages and features get used, via PostHog. Document titles and document content are stripped before any event leaves your browser.

What we do not collect

Who can see your documents

A document is private unless you change it. Private means you and nobody else. A link on its own is not enough, because the URLs the viewer loads are signed, expire after fifteen minutes, and are re-issued only to someone the server has already checked.

Public means anyone with the link can open it. Team means the members of the team the document belongs to, and nobody else. Team admins can see every member’s name and email address, and can change the settings of any document in the team. You choose per document, and separately choose whether that audience may view, comment, or edit. Documents are served with headers that keep search engines out unless you have explicitly made a document public and indexable.

Documents published without an account are deleted automatically after 24 hours, unless you claim them into an account first.

Cookies

We set a session cookie (toss_session) so you stay signed in, and three short-lived cookies during a Google sign-in that hold the one-time state and PKCE values and expire after ten minutes. All are httpOnly. There are no advertising cookies.

Where it lives

The application runs on Vercel. Documents, comments and accounts are stored in Convex. Product analytics go to PostHog (US region). Sign-in with Google involves Google. These providers process data on our behalf; we do not sell your data to anyone, and there is nobody else in the chain.

How long we keep it

Your choices

You can delete any document from its page at any time. To export or delete your account and everything attached to it, email kushdaga1494@gmail.com from the address on the account and we will do it. If you are in the UK, EU, or another place with a statutory right of access, correction, portability, erasure, or objection, that email is how to exercise it. No form, and no charge.

Security

Published documents run inside a sandboxed frame on a policy that blocks them from reaching your session, and tokens are stored only as hashes. No service is perfectly secure, and this one is young. If you find a problem, please tell us at kushdaga1494@gmail.com before telling anyone else.

Children

tossithere is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we collect or who sees it, we will update the date at the top and email account holders before it takes effect.

Contact

Questions, requests, or complaints: kushdaga1494@gmail.com.