Privacy
This is a template, and this page is starter copy: true for what the repository does out of the box, and short on purpose. It is not a policy written for any real company, because there is no company behind this starter.
What the public site collects
Nothing. The marketing and knowledge pages set no analytics cookies, load no third-party trackers, and talk to no ad tech. The optional providers the starter can wire up (Sentry, PostHog, Turnstile) ship disabled and stay inactive until a deployment configures them.
What a deployment stores
If you create an account on an instance built from this starter, it keeps what you give it: your email address, hashed credentials, sessions, the workspaces and members you set up, and the audit events those actions produce. All of it lives in that deployment's own Cloudflare D1 database. There is no vendor behind the template receiving any of it.
Local development
The demo seed, its sample users and the starter-lab workspace included, runs entirely inside your own environment: in memory, or in your local D1 if you have one. Nothing it creates leaves your machine.
Before you ship
A real product needs a real policy: your legal entity, the providers you actually enable, retention windows, and the jurisdictions you operate in. Replace this page before your first real user arrives.