---
url: /en/docs/privacy.md
description: >-
  Review Sveltia CMS privacy practices, data handling policies, and GDPR
  compliance.
---

# Privacy

We don’t have a privacy policy because our product doesn’t collect any personal data. That said, here is some information about our basic privacy practices across the platform. This information is provided for transparency purposes only.

## Application Data Handling

Sveltia CMS is not a service but a client-side application that runs in the web browser. No account is needed to use the app, but users do need to authenticate with their Git hosting provider to read and write remote data. All content is stored in the Git repository. No data is sent to any server operated by us.

Depending on your CMS configuration, you will need to use an OAuth application hosted by the site owner or a third party, such as Netlify or Cloudflare, to retrieve an access token from GitHub. Alternatively, users can provide an access token directly on the CMS’s sign-in page. In any case, the token is stored in the browser’s local storage, and subsequent API requests are made directly between the browser and the Git hosting provider.

The CMS also integrates with various third-party services, including stock photo providers and translation services. These are “bring your own key” (BYOK) features that are entirely optional. Users provide their own API keys for these services, which are stored in the browser’s local storage, and API requests are then made directly between the browser and the relevant service providers.

Since we don’t even collect any analytics data, we don’t have a privacy policy. For third-party services, please refer to their respective privacy policies.

## Content Delivery Networks

The CDN builds of Sveltia CMS load some files from public content delivery networks (CDNs) as needed: fonts from [jsDelivr](https://www.jsdelivr.com/), and the app itself, admin interface translations, additional libraries, image decoders and syntax highlighting definitions from [UNPKG](https://unpkg.com/). The CMS also checks UNPKG periodically for a new version. These requests contain no content or credentials, but like any web request, they reveal the user’s IP address to the CDN provider.

If you’d rather not rely on third-party CDNs, for example to avoid listing them in your site’s privacy policy under the GDPR, use the NPM package instead. It serves all these files from your own site, and doesn’t check for updates. See [CDN or NPM Package](/en/docs/releases#cdn-or-npm-package) for the differences between the builds.

Either way, the CMS contacts other services only when the configuration requires them: the Git hosting provider, [GitHub Status](https://www.githubstatus.com/) with the GitHub backend, [OpenStreetMap](https://www.openstreetmap.org/) and [Nominatim](https://nominatim.org/) for the [Map field](/en/docs/fields/map), the media storage provider, and the optional services mentioned above.

## GitHub Repository Monitoring

Although Sveltia CMS does not have built-in analytics, we constantly monitor public GitHub repositories to understand how the CMS is being used. This involves analyzing configuration files, API usage patterns, commit history, and other public data. We use this information to improve the product and expand the [showcase](/en/showcase).

## Web Analytics

We use [Cloudflare Web Analytics](https://www.cloudflare.com/web-analytics/) to collect anonymous statistics about site visitors. This service does not use cookies and complies with GDPR regulations. No personal data is collected or stored.
