Privacy Policy

What HTML Designer Pro for Windows sends, when, and to whom. The short version: the application edits your site entirely on your own computer; it talks to the network for five things, and four of them happen only because you asked. There is no account, no usage analytics, no advertising and no tracker — in the app or on this page. Your files are never uploaded anywhere except the server you choose to publish to.

Effective 1 October 2026 · applies to HTML Designer Pro for Windows, version 26.1 and later, downloaded from this site or installed from the Microsoft Store.

Overview

In one table

Every network connection the application can make, and what triggers it. Nothing else leaves your computer.

FeatureWhenWhat is sentTo whom
Send FeedbackOnly when you press SendYour text, the images you attach, the app version and build, and an anonymous per-installation id. Not your filesOur feedback server, appsupport-gajv.onrender.com (hosted on Render)
Crash reportAt the launch after a crash, and only if you agree thenThe crash text: exception, call stack, the last window messages, the app version. No file contentThe same feedback server
The assistantOnly when you send a message in the chatYour message, the conversation, and the files you are working on. Not the whole projectWith your own key: straight to that provider. Without one: our own channel on the same server, which forwards it
PublishingOnly when you uploadThe files you sendYour FTP, FTPS or SFTP server. Never ours
Check for UpdatesThe background check and Help › Check for Updates… (direct download only)A plain GET of the update feed. No identifier, no parameter, no cookieThis website, rainbowfactory.uk
External control—Nothing: local only, and off until you switch it on—
Help › Send Feedback…

Send Feedback

The Feedback palette (Ctrl+Alt+F, or Help › Send Feedback…) lets you write to us. Nothing is sent until you press Send. There is no automatic send, no send on quit, and no collection in the background. When you press it, the application posts one report to our feedback server at https://appsupport-gajv.onrender.com, a service we run on Render (Render Services, Inc., USA). The report contains:

  • the text you wrote and the kind you chose (a problem, a request, a question);
  • the files you attached yourself, if any — up to six images, 5 MB each. Nothing is attached unless you attach it, with the paperclip in the palette. A file that is not an image is zipped, and if the app had to convert anything it tells you what it did;
  • the application version and build, and one word saying which copy you have: the direct download, the Microsoft Store one, or a development build;
  • an anonymous per-installation id: a random value created the first time it is needed and kept in the application’s settings file. It is not tied to any account and does not identify a person; our server uses it only to cap how many reports one installation can send in a day, so the service cannot be flooded.

If you are offline the report waits on your own disk, in the application’s data folder, and goes out later. The images are never kept on disk, so a retry after a restart sends the text only — and says so, rather than quietly sending a report with pieces missing.

After a crash

Crash reports

If the application stops unexpectedly it writes a readable report and a memory dump to your own disk. It reads its own symbols to do it: no external service, no analysis machine, and nothing is sent at that moment.

At the next launch the application finds that report and shows it to you, asking permission. Say no and it goes nowhere. The report carries the exception, the call stack, the version, and a short diary of the last window events — the thing that turns a report into something we can reproduce. It does not contain your document, your project paths or the contents of the editor.

Reports written by another one of our applications are refused rather than sent as ours: each one checks that the report says its own name.

The chat

The assistant

Nothing goes out until you write a message and send it. There are two routes, and the difference matters.

With your own key. If you have put a Claude (Anthropic) or Gemini (Google) key into the settings, the request goes straight from your computer to that provider over HTTPS. We do not see it pass and keep no copy. Your key stays in the settings on your machine and is never sent to us. What happens to the request after that is governed by your agreement with that provider.

Without a key. The chat still works, through a channel of ours on the same server as the feedback (appsupport-gajv.onrender.com), which forwards the message to a provider. It exists so the chat can be tried without configuring anything, and it is present in both copies of the app — the direct download and the Store one. The same anonymous per-installation id travels on it, for the same reason: a daily cap. Nothing else: no account, no address, no name.

What goes into a message: your text, the current conversation, and the files you are working on — because “make this table responsive” means nothing without that table. Not the whole project, not a listing of your disk, not files that have nothing to do with it.

When the assistant writes files for you, a copy of every file it replaces is put aside first and Edit › Undo Replace in Files undoes all of it in one step. A file whose copy could not be written is left untouched, and the chat says which one.

FTP, FTPS, SFTP

Publishing to your server

When you publish, the files go to the server you configured. They do not pass through us, we never hold a copy, and there is no address of ours anywhere on that path.

  • Passwords and passphrases are kept by Windows, in the same place it keeps your other credentials — never in a project file, never in the clear on disk. In memory they are wiped after use.
  • An SSH server’s key is remembered the first time you connect, and you are told if it changes: a silent change is exactly what checking it is for.
  • The transfer log stays on your disk.
Help › Check for Updates…

Check for Updates

Only in the copy downloaded from this site. It is a single GET of https://www.rainbowfactory.uk/html-designer/updates/appcast-windows.xml, a static XML file. There is nothing of yours in that request: no identifier, no parameter, no cookie, no body. The server sees what any server sees for any file downloaded — an IP address and the request line — and we do not cross it with anything.

If a new version is there, the application downloads the package and verifies its signature against a key compiled into the copy you are running before installing. Nothing unsigned is ever installed, and there is no fallback on “trust the website”. The check at startup can be switched off in Settings › Updates.

The Microsoft Store copy does not do this at all: the menu item is not there and the startup check never runs. Inside the Store, updating is the Store’s job.

Settings › MCP

External control

So that an AI assistant you choose can work inside the project with you, the application can act as a server for the Model Context Protocol. This is not something that goes out: it is something that comes in, and it has four locks.

  • Off until you switch it on.
  • It binds to 127.0.0.1 and explicitly to that, not to every address: from the network it cannot be reached. The socket is taken for exclusive use, so another process on the same machine cannot take the port and receive the requests instead.
  • Any request that does not come from this machine is refused, and no reply ever carries a cross-origin header — a web page open in your browser cannot talk to it.
  • The usual transport is the application’s own standard input and output (htmldesigner.exe --mcp-stdio), which opens no port at all.
On your disk

What stays on your computer

Your projects, your files, your snippets, your settings, the session you left open, the list of recent projects, the transfer log, the remembered server keys, and the queued feedback if you were offline. All of it is on your own disk and none of it is mirrored anywhere.

The preview serves your page from a small web server on your own machine, on the loopback address, so that links, fonts and scripts behave as they will online. It serves only what is inside the project folder: one function decides that, and every request goes through it. Nothing leaves the machine.

One honest note: a page you preview is a web page. If your own HTML loads a font, a script or an image from an address on the internet, the browser engine fetches it exactly as any browser would. That is your page’s decision, not the application’s. A PHP page, if you preview one, is run by your server — the one you publish to — not by us.

Not there

What there is none of

  • No account. There is no sign-up, no login and no profile.
  • No usage analytics and no telemetry. Nobody counts how often you open a menu, measures a session, or sends an “event”.
  • No advertising and no third-party measurement SDK. No cookies in the application.
  • No in-app purchases, so no payment data: none passes through, because there is no till.
  • No files uploaded on any route other than “publish to my server” and “send this attachment with my feedback”.
  • No diagnostic log sent in the background.
Your rights

Retention, your rights, contact

There is no archive to erase yourself from, because there is no account. The concrete things you can do:

  • send nothing: feedback, crash reports and the chat only go out on a gesture of yours;
  • reset the anonymous id by clearing it in the application’s settings file — a new one will be created when it is next needed;
  • switch off the update check in Settings › Updates (direct download only);
  • leave external control off — it already is;
  • ask us to delete a report by writing to support@rainbowfactory.uk and quoting the number the application showed you after sending.

Feedback and crash reports are kept while the problem they describe is open, and are deleted when the tracker entry is closed and the release that fixes it has shipped. They are not used for anything else and are not shared with anyone.

The controller is Rainbowfactory Ltd, London, United Kingdom — support@rainbowfactory.uk. Support and news also on Discord.