Privacy
Last updated 24 September 2026
tossithere turns an HTML file into a link other people can comment on. That means we hold your documents, so this page is specific about what is stored, who can reach it, and how to remove it. It describes what the service actually does today, not what it might do later.
What we collect
| What | Why |
|---|---|
| Your email address and name | To identify your account and show who left a comment. If you sign in with Google we receive these plus your Google account id, and nothing else: no contacts, no Drive, no calendar. |
| Documents you publish | The HTML and any assets you push, every version of them, and the file sizes. This is the product. |
| Comments and their anchors | The comment text, and a snippet of the document markup it points at so the comment can find its place again after you republish. |
| Session and API tokens | Stored as SHA-256 hashes, never in the clear. We cannot recover a token you lose, only issue a new one. |
| Product analytics | Which pages and features get used, via PostHog. Document titles and document content are stripped before any event leaves your browser. |
What we do not collect
- No advertising or cross-site tracking, and no third-party ad networks.
- No session replay, heatmaps, or automatic capture of what you click inside a document.
- No payment card details. Payments go through Dodo Payments, our merchant of record, which handles card data and tax information under its own privacy policy. We receive only a customer id, which plan you bought and whether the subscription is active.
Who can see your documents
A document is private unless you change it. Private means you and nobody else. A link on its own is not enough, because the URLs the viewer loads are signed, expire after fifteen minutes, and are re-issued only to someone the server has already checked.
Public means anyone with the link can open it. Team means the members of the team the document belongs to, and nobody else. Team admins can see every member’s name and email address, and can change the settings of any document in the team. You choose per document, and separately choose whether that audience may view, comment, or edit. Documents are served with headers that keep search engines out unless you have explicitly made a document public and indexable.
Documents published without an account are deleted automatically after 24 hours, unless you claim them into an account first.
Cookies
We set a session cookie (toss_session) so you stay signed in, and three short-lived cookies during a Google sign-in that hold the one-time state and PKCE values and expire after ten minutes. All are httpOnly. There are no advertising cookies.
Where it lives
The application runs on Vercel. Documents, comments and accounts are stored in Convex. Product analytics go to PostHog (US region). Sign-in with Google involves Google. These providers process data on our behalf; we do not sell your data to anyone, and there is nobody else in the chain.
How long we keep it
- Documents: until you delete them. Deleting a document removes every version and its comments, immediately and permanently.
- Anonymous documents: 24 hours, then deleted automatically.
- Sessions: 30 days, or until you sign out.
- Account: until you ask us to delete it.
Your choices
You can delete any document from its page at any time. To export or delete your account and everything attached to it, email kushdaga1494@gmail.com from the address on the account and we will do it. If you are in the UK, EU, or another place with a statutory right of access, correction, portability, erasure, or objection, that email is how to exercise it. No form, and no charge.
Security
Published documents run inside a sandboxed frame on a policy that blocks them from reaching your session, and tokens are stored only as hashes. No service is perfectly secure, and this one is young. If you find a problem, please tell us at kushdaga1494@gmail.com before telling anyone else.
Children
tossithere is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects what we collect or who sees it, we will update the date at the top and email account holders before it takes effect.
Contact
Questions, requests, or complaints: kushdaga1494@gmail.com.