Trust & Security

Privacy Policy

Last Revised: October 2026 • Effective for all Dart Host hosted projects and user accounts

Table of Contents
Security Center & Specs

1. Overview & Scope

Welcome to Dart Host ("Platform", "we", "our", or "us"). We provide a zero-configuration static HTML deployment and hosting infrastructure. This Privacy Policy details the types of information we collect from registered developers, visitors, and users who view deployed HTML projects, and how we handle and protect that information.

We believe in privacy by design. We do not sell, rent, or monetize your personal information or uploaded HTML source code to third-party ad networks under any circumstances.

2. Information We Collect

To provide reliable web hosting services, we collect minimal and necessary information:

  • Account Details: When you register, we store your chosen username, email address, and an argon2id/bcrypt cryptographically hashed password. Plaintext passwords are never stored.
  • Hosted HTML Files & Code: HTML source code, CSS, JS, and metadata (title, custom slug, file size) uploaded or pasted by you in the workspace console.
  • Telemetry & Request Metadata: Real-time requests logged for platform telemetry, including timestamp, HTTP request method, requested URI, approximate server response duration (TTFB), and masked IP address for rate-limiting.

3. Hosted HTML Content & Sandbox

Projects hosted on Dart Host are delivered through isolated endpoints. While hosted files are publicly accessible via their assigned URL slugs, your underlying account credentials, draft revisions, and administrative dashboard remain strictly private and isolated.

Zero Malware Sandbox Policy: We scan hosted HTML files for dangerous server execution attempts or known malicious distribution patterns to maintain network hygiene.

4. Telemetry & Session Storage

We only use strictly essential cookies and browser storage:

  • Session Cookie (PHPSESSID): Secure HTTP-only cookie required to authenticate you into your developer workspace console.
  • CSRF Security Tokens: Cryptographic tokens to prevent cross-site request forgery attacks during forms and code uploads.
  • Theme & Local UI Preferences: Light theme and console preferences stored in local storage without identifying personal data.

5. Data Security Standards

We implement enterprise-grade security protocols across all hosting operations:

TLS 1.3 HTTPS Encryption
All data transmitted between your browser and our servers is encrypted in transit.
Prepared PDO Statements
Strict parameterization eliminates SQL injection risks across all database transactions.

6. Your Rights & GDPR Compliance

Under global data protection standards (including GDPR and CCPA), you maintain full control over your data:

  • Right to Access: You can view all hosted files, slugs, view counters, and account profiles anytime in the developer workspace.
  • Right to Deletion: You can delete any hosted HTML project at any moment from your console. Once deleted, the file is unlinked immediately.
  • Right to Rectification: You can edit and update project code, titles, and descriptions dynamically in the in-browser code editor.

7. Privacy Contact & Data Inquiries

If you have inquiries regarding this Privacy Policy, data privacy rights, or need assistance with your data, please contact our trust and security team: