HaveTML

Privacy policy

Last updated: July 16, 2026

What HaveTML is

HaveTML (havetml.com) hosts single-file HTML and Markdown artifacts so you can share them with a link, collect comments, and keep versions. This policy covers the website, the API, and the HaveTML Chrome extension.

What we store

  • Account data — your email address, display name, and authentication credentials, managed by our database provider (Supabase). If you sign in with Google, we receive your email and name from Google; we never see your Google password.
  • Your content — the files you upload, their version history, project names and descriptions, reader notes, and comments (including guest names on comments).
  • API tokens — tokens you create are stored only as cryptographic hashes; the full token is shown to you once and cannot be recovered by us.
  • Billing data — your plan, subscription status, renewal date, and Stripe customer/subscription identifiers. Card and bank details are collected and stored by Stripe, not HaveTML. Stripe processes this information to complete payments, provide invoices, and manage subscriptions.
  • Cookies — session cookies to keep you signed in, and short-lived cookies that remember a password you entered to unlock a protected artifact. If you accept optional Google Analytics, Google may also set analytics identifiers in your browser. We do not use advertising cookies.
  • Usage analytics— which pages are visited, how long artifacts are viewed for, and product events such as uploading an artifact, creating a project, or copying a share link. This includes visits to your artifact and project pages by the people you share links with. We use OpenPanel for this. It sets no cookies; it stores an identifier in your browser's session storage, which your browser clears when you close the tab, and derives a device identifier from your IP address and browser user-agent. There is no cross-site tracking, and we do not use this data for advertising. If you have an account, your user ID, email, and display name are shared with OpenPanel so we can tell accounts apart; if you are just viewing a shared link, you are counted anonymously.
  • Optional Google Analytics — Google Analytics 4 helps us understand aggregate site traffic and navigation. Its script does not load unless you select “Accept” in the analytics prompt. You can decline it and continue using HaveTML, or reset your choice below. We do not enable Google advertising features for this purpose.

The Chrome extension

  • The extension stores your HaveTML API token and your last-used project in Chrome's extension storage, on your device (and in your Chrome sync profile if you have sync enabled).
  • When you drop a file on it, the file's content is sent to havetml.com over HTTPS to create the artifact in your account. Nothing is uploaded without your explicit action.
  • The extension does not read the pages you visit, your browsing history, or anything beyond the files you choose to upload.

Your analytics choice

Optional Google Analytics stays off until you consent. Reset your saved choice to show the preference prompt again.

Who can see your content

Anyone with an artifact or project link can view it (or must enter the password you set). Artifacts are served sandboxed. We do not sell or share your data with third parties; infrastructure providers (Supabase, Vercel, OpenPanel, Google Analytics when you consent, and Stripe) process it solely to run, measure, and bill for the service.

Deletion

You can delete artifacts and projects from your dashboard and revoke API tokens at any time. To delete your account and all associated data, contact us.

Contact

Questions or requests: hassanain.anver@disrupt.com