What HTML Designer Pro for Windows sends, when, and to whom. The short version: the application edits your site entirely on your own computer; it talks to the network for five things, and four of them happen only because you asked. There is no account, no usage analytics, no advertising and no tracker — in the app or on this page. Your files are never uploaded anywhere except the server you choose to publish to.
Effective 1 October 2026 · applies to HTML Designer Pro for Windows, version 26.1 and later, downloaded from this site or installed from the Microsoft Store.
Every network connection the application can make, and what triggers it. Nothing else leaves your computer.
| Feature | When | What is sent | To whom |
|---|---|---|---|
| Send Feedback | Only when you press Send | Your text, the images you attach, the app version and build, and an anonymous per-installation id. Not your files | Our feedback server, appsupport-gajv.onrender.com (hosted on Render) |
| Crash report | At the launch after a crash, and only if you agree then | The crash text: exception, call stack, the last window messages, the app version. No file content | The same feedback server |
| The assistant | Only when you send a message in the chat | Your message, the conversation, and the files you are working on. Not the whole project | With your own key: straight to that provider. Without one: our own channel on the same server, which forwards it |
| Publishing | Only when you upload | The files you send | Your FTP, FTPS or SFTP server. Never ours |
| Check for Updates | The background check and Help › Check for Updates… (direct download only) | A plain GET of the update feed. No identifier, no parameter, no cookie | This website, rainbowfactory.uk |
| External control | — | Nothing: local only, and off until you switch it on | — |
The Feedback palette (Ctrl+Alt+F, or Help › Send Feedback…) lets you write to us. Nothing is sent until you press Send. There is no automatic send, no send on quit, and no collection in the background. When you press it, the application posts one report to our feedback server at https://appsupport-gajv.onrender.com, a service we run on Render (Render Services, Inc., USA). The report contains:
If you are offline the report waits on your own disk, in the application’s data folder, and goes out later. The images are never kept on disk, so a retry after a restart sends the text only — and says so, rather than quietly sending a report with pieces missing.
If the application stops unexpectedly it writes a readable report and a memory dump to your own disk. It reads its own symbols to do it: no external service, no analysis machine, and nothing is sent at that moment.
At the next launch the application finds that report and shows it to you, asking permission. Say no and it goes nowhere. The report carries the exception, the call stack, the version, and a short diary of the last window events — the thing that turns a report into something we can reproduce. It does not contain your document, your project paths or the contents of the editor.
Reports written by another one of our applications are refused rather than sent as ours: each one checks that the report says its own name.
Nothing goes out until you write a message and send it. There are two routes, and the difference matters.
With your own key. If you have put a Claude (Anthropic) or Gemini (Google) key into the settings, the request goes straight from your computer to that provider over HTTPS. We do not see it pass and keep no copy. Your key stays in the settings on your machine and is never sent to us. What happens to the request after that is governed by your agreement with that provider.
Without a key. The chat still works, through a channel of ours on the same server as the feedback (appsupport-gajv.onrender.com), which forwards the message to a provider. It exists so the chat can be tried without configuring anything, and it is present in both copies of the app — the direct download and the Store one. The same anonymous per-installation id travels on it, for the same reason: a daily cap. Nothing else: no account, no address, no name.
What goes into a message: your text, the current conversation, and the files you are working on — because “make this table responsive” means nothing without that table. Not the whole project, not a listing of your disk, not files that have nothing to do with it.
When the assistant writes files for you, a copy of every file it replaces is put aside first and Edit › Undo Replace in Files undoes all of it in one step. A file whose copy could not be written is left untouched, and the chat says which one.
When you publish, the files go to the server you configured. They do not pass through us, we never hold a copy, and there is no address of ours anywhere on that path.
Only in the copy downloaded from this site. It is a single GET of https://www.rainbowfactory.uk/html-designer/updates/appcast-windows.xml, a static XML file. There is nothing of yours in that request: no identifier, no parameter, no cookie, no body. The server sees what any server sees for any file downloaded — an IP address and the request line — and we do not cross it with anything.
If a new version is there, the application downloads the package and verifies its signature against a key compiled into the copy you are running before installing. Nothing unsigned is ever installed, and there is no fallback on “trust the website”. The check at startup can be switched off in Settings › Updates.
The Microsoft Store copy does not do this at all: the menu item is not there and the startup check never runs. Inside the Store, updating is the Store’s job.
So that an AI assistant you choose can work inside the project with you, the application can act as a server for the Model Context Protocol. This is not something that goes out: it is something that comes in, and it has four locks.
Your projects, your files, your snippets, your settings, the session you left open, the list of recent projects, the transfer log, the remembered server keys, and the queued feedback if you were offline. All of it is on your own disk and none of it is mirrored anywhere.
The preview serves your page from a small web server on your own machine, on the loopback address, so that links, fonts and scripts behave as they will online. It serves only what is inside the project folder: one function decides that, and every request goes through it. Nothing leaves the machine.
One honest note: a page you preview is a web page. If your own HTML loads a font, a script or an image from an address on the internet, the browser engine fetches it exactly as any browser would. That is your page’s decision, not the application’s. A PHP page, if you preview one, is run by your server — the one you publish to — not by us.
There is no archive to erase yourself from, because there is no account. The concrete things you can do:
Feedback and crash reports are kept while the problem they describe is open, and are deleted when the tracker entry is closed and the release that fixes it has shipped. They are not used for anything else and are not shared with anyone.
The controller is Rainbowfactory Ltd, London, United Kingdom — support@rainbowfactory.uk. Support and news also on Discord.