Privacy policy
Last updated on October 2, 2026
This policy explains what Vissu collects, how it is used, and the choices you have.
What we collect
Account data. When you sign in with Google or GitHub, we receive your name, email address and profile picture from that provider. We store a session token, and the IP address and browser user agent of your sessions. We do not receive your Google or GitHub password.
Page content. What you add to your page: name, bio, avatar, banner, headline, location label and time zone, availability, contact label and email, social handles, and your widgets (projects, images and social links).
Uploaded images. Images you upload are converted to WebP and stored with a public address.
Usage statistics. We use Umami to count page views and product events, such as starting sign-in, completing onboarding steps, and creating, editing, reordering, resizing or deleting widgets. These statistics are not linked to your account.
How we use it
We use your data to sign you in, keep you signed in, show your page, store your uploads, protect the service from abuse (for example, rate limiting), and contact you about your account if needed.
We do not run ads, do not sell your data, and do not use advertising trackers. We use privacy-friendly analytics only to understand how the service is used and to improve it.
Public profile visibility
Your page at vissu.co/your-name is public. Everything you put on it, including your contact email if you add one, your images and your links, can be seen by anyone and may be indexed by search engines or copied by others. Add only what you are happy to share.
Service providers
- Google and GitHub handle sign-in under their own privacy policies.
- Umami (Umami Cloud, cloud.umami.is) receives page views and product events to provide usage statistics. According to Umami, it does not use cookies in its tracking code, does not collect personally identifiable information, and cannot track visitors across websites.
- Cloudflare Turnstile runs a security check against automated abuse before sign-in. It may process technical data such as your IP address and browser signals.
- Cloudflare hosts the app, stores page data in its D1 database, and stores uploaded images in R2.
Cookies and local storage
We use a session cookie to keep you signed in. It is needed for the service to work, so we do not show a cookie banner. Our analytics does not use cookies.
Your browser's local storage holds the address you were claiming (vissu-claim) so you can pick up where you left off after signing in.
Retention and deletion
We keep your data while your account is active. Removing a widget or replacing an image deletes the old image from storage. Deleting a page removes its profile, links and widgets.
There is no self-service account deletion yet. To delete your account and data, message us on X at @0xvargs_. Short-lived backups or caches may keep copies for a limited time.
Security
We use sign-in through established providers, encrypted connections and rate limiting. No system is perfectly secure, so we cannot guarantee absolute security.
Children
Vissu is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your data, and to object to certain uses. You can edit most of your data directly on your page. For anything else, message us on X at @0xvargs_.
Changes to this policy
We may update this policy. When we do, we will change the date at the top of this page.
Contact
Questions about privacy? Message us on X at @0xvargs_.