Privacy policy

Your dashboard is yours.

Widgy is built to work locally first. You can use the free dashboard without creating an account, and we do not use advertising cookies, Google Analytics, tracking pixels or embedded video services.

Effective 10 July 2026 Last updated 14 July 2026 Version 1.2

The responsible organisation

Who we are

Widgy Start ("Widgy", "we", "us") is operated by De Wilde ICT Solutions, based in Ede, the Netherlands, registered with the Dutch Chamber of Commerce under number 98600311. De Wilde ICT Solutions is the data controller for the personal data described in this policy.

For privacy questions or requests, open Widgy and use Support → Privacy or data request. This creates a private service ticket so we can verify and handle your request safely.

What Widgy knows about you

Personal data we process

Local dashboard use

Your canvases, widget positions, notes, preferences, theme and local widget settings are normally stored in your own browser. They are not sent to our server merely because you use the free local dashboard.

Clearing browser storage or using another browser may remove or hide this local data unless you exported a backup or enabled cloud sync.

Account information

When you register, we store your name, email address, password hash, account status, plan or access role, creation and last-seen dates, activation information and secure remembered-login tokens. We never store your password in readable form.

Optional cloud sync

When cloud sync is enabled, we store your dashboard layout, canvases, widget configuration, revision and conflict information, and timestamps needed to keep your saved layout available to your account.

Support and service desk

When you contact support, we store your name, email address, ticket category, subject, messages, ticket status, priority, timestamps and the private access token used to open the ticket page. If you rate a resolved ticket, we store the rating and optional comment.

Security and technical records

We may record login events, security actions, error information, timestamps, IP addresses or one-way IP hashes, and limited request context. These records help prevent abuse, investigate incidents and keep Widgy reliable.

Widget and API activity

Some widgets request information through Widgy's server. Depending on the widget, we may process the widget type, request time, success or error state, account entitlement and usage totals. We avoid storing widget content unless it is required for the feature.

Marine Life Identifier

When you choose Analyze, Widgy resizes the diving photo in your browser, removes embedded metadata and sends the processed image through Widgy to OpenAI for the requested identification. Widgy does not save or log the photo, and requests OpenAI not to store the response request. Optional dive location, depth and date remain in browser memory and are included only when you provide them.

The processed image preview and unsaved dive context remain in browser memory until you clear or replace them, remove the widget, change account/dashboard state or close the tab. The text identification and optional dive context enter local or cloud layout data only after you choose Save result.

Food Photo Analyzer

When you choose Analyze, Widgy resizes and re-encodes the food photo in your browser to remove embedded metadata, then sends the processed pixels and any optional portion context through Widgy to OpenAI. Widgy does not save or log the photo or context, and requests OpenAI not to store the analysis request.

The preview, processed image and portion context remain only in browser memory until you clear or replace them, leave the canvas, remove the widget, replace or reset dashboard state, sign out or close the tab. Portion context is never saved. Only after you choose Save result does the structured text estimate enter local or cloud layout data. Photo-based calories, nutrients, ingredients and allergens are uncertain estimates, cannot establish allergen safety and are not medical advice.

Father & Son TCG widget

When you use this widget, Widgy sends the selected mode, card search term, set filter, stock filter and result limit through a fixed Widgy server proxy to fatherandsontcg.com. The provider API key remains on the Widgy server and is not placed in the canvas or browser.

Widgy normally loads the complete card image URL supplied by fatherandsontcg.com directly in your browser. If that image cannot be loaded, Widgy may use a restricted server-side fallback proxy and temporarily cache the image. Image URLs are never constructed from product shop links. Opening a shop link takes you to fatherandsontcg.com, where the webshop receives the normal technical information sent by your browser under its own privacy practices.

Optional Google connection

Google Search Console data

When you choose to connect Search Console Insights, Widgy uses Google OAuth and requests only the read-only Search Console scope. The connection lets Widgy read the Search Console properties available to your Google account and historical Search Analytics information for the property you choose.

The Google data Widgy may access and display consists of the property address and permission level, date range, search queries, clicks, impressions, click-through rate and average position. Widgy does not receive your Google password, cannot change Search Console properties or settings, and does not request access to Gmail, Google Drive, Google Analytics or unrelated Google account data.

We use this information only to provide the Search Console Insights feature to the connected Widgy account. We do not sell it, use it for advertising, build advertising profiles from it or share it with other customers. Google receives the OAuth and API requests needed to authorize and provide the data under Google's own terms and privacy practices.

Storage and security

Google OAuth access and refresh tokens are encrypted per Widgy account on the server. Search Console responses may be cached to reduce repeated Google requests, normally for six hours and never longer than 24 hours. Tokens are excluded from canvas exports, frontend code, API usage logs and support tickets.

Your controls

You can disconnect Google from the widget settings at any time. Widgy then attempts to revoke the Google token and removes the stored tokens and cached Search Console responses. Deleting your Widgy account also removes this connection data. You can additionally revoke Widgy from your Google Account permissions.

Google API policy

Widgy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.

Purposes and legal grounds

Why we use personal data

PurposeExamplesLegal basis
Provide the serviceCreate and manage accounts, log users in, synchronize layouts, provide widgets and answer support tickets.Necessary to perform our agreement with you.
Keep Widgy securePrevent fraud and abuse, enforce rate limits, investigate incidents and maintain audit records.Our legitimate interest in operating a secure and dependable service.
Send service messagesActivation, password reset, ticket updates, security notices and important service changes.Necessary to provide the service or meet our legitimate interests.
Meet legal obligationsAccounting, tax records, lawful requests and handling data-protection rights.Compliance with legal obligations.
Optional communicationsFuture newsletters or non-essential product updates, if introduced.Your consent, which you may withdraw.

How long information remains

Retention

We keep personal data only for as long as needed for the purpose for which it was collected, for security, or to meet legal obligations. In practice:

  • Local dashboard data: remains in your browser until you delete it, reset Widgy or clear browser storage.
  • Accounts and cloud layouts: remain while your account is active. Following a valid deletion request, active records are removed unless retention is legally required; residual backup copies may remain for a limited backup cycle.
  • Activation links: expire after 48 hours. Password-reset links expire after one hour and are deleted after use.
  • Remembered-login tokens: normally expire after 30 days or sooner when you log out or change your password.
  • Google Search Console connection: encrypted OAuth tokens remain until you disconnect Google, delete your Widgy account or the connection becomes unusable. Cached Search Console responses normally expire after six hours and never remain longer than 24 hours; disconnecting clears them immediately.
  • Marine-life photos: are processed transiently for the requested analysis and are not retained in Widgy widget, layout, log, cache or backup storage. Saved text identifications remain with the local or cloud layout until you clear them.
  • Food photos and portion context: are processed transiently for the requested analysis and are not retained in Widgy widget, layout, log, cache or backup storage. Only explicitly saved structured text estimates remain with the local or cloud layout until you clear them.
  • Support tickets and ratings: are retained as needed to handle the request, improve support and document agreements. You may ask us to delete or anonymise them where no legal reason requires retention.
  • Financial records after payments launch: will generally be retained for the period required by Dutch tax and accounting law.
  • Security and audit records: are retained only as long as reasonably needed to investigate abuse, maintain integrity and demonstrate security actions.

Browser storage

Cookies and local storage

Widgy currently uses only strictly necessary or functional browser storage. We do not use Google Analytics, advertising cookies, tracking pixels or embedded video cookies.

Because the current cookies are necessary for login, security and user-requested functionality, Widgy does not currently show a consent banner. This policy still explains their use. If we later add non-essential analytics, advertising or embedded third-party media, we will ask for consent before those technologies are activated.

Other organisations

Processors, providers and sharing

We do not sell personal data. We share data only where needed to operate Widgy, comply with law or protect the service. This may include our hosting provider, email-delivery provider, future payment provider, Google when you connect Search Console Insights, Father & Son TCG when you use its card widget, and other API providers used by widgets you choose to activate.

Each provider receives only the information reasonably needed for its task. Where a provider processes personal data for us, we seek appropriate contractual and security safeguards. Some API providers may act as independent controllers under their own privacy terms, especially when you connect your own external account or service.

If personal data is transferred outside the European Economic Area, we will use an approved transfer mechanism where required, such as an adequacy decision or standard contractual clauses.

Planned commercial features

What changes when payments launch

Widgy does not currently process live payments.

When paid plans become available, checkout will be handled by a selected payment provider. We expect to store the information required to manage the customer relationship, such as your Widgy account, chosen plan, subscription status, customer or transaction reference, billing country, invoice details, payment status, renewal and cancellation dates, and support history.

Your card details stay with the payment provider.

Widgy does not intend to store full card numbers or card security codes. The payment provider will process those details under its own privacy and security obligations. Widgy may receive limited payment information, such as payment method type, the last digits of a card, payment outcome and fraud or chargeback status.

Before payments are activated, we will update this policy with the selected provider, relevant international transfers, exact billing information, retention periods and customer rights. Where required, we will also update our terms and obtain consent for any optional marketing communication.

Protection

How we secure data

Widgy uses measures designed to protect personal data, including password hashing, secure and HttpOnly cookies, session renewal, access controls, CSRF protection, rate limiting, server-side API credentials, AES-256-GCM encryption for supported connection tokens, audit logging, protected storage paths and encrypted HTTPS transport. No internet service can guarantee absolute security, but we review and improve these measures as Widgy develops.

If we discover a personal-data breach that creates a risk to people, we will assess it and notify the Dutch supervisory authority and affected users when legally required.

Your control

Your privacy rights

Depending on the circumstances, you may ask us to:

Access your personal dataCorrect inaccurate dataDelete your dataRestrict processingObject to certain processingReceive portable account dataWithdraw consentComplain to a regulator

Submit a request through Support → Privacy or data request in Widgy. We may ask for reasonable information to verify your identity. We aim to respond within the period required by applicable law.

You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch data-protection authority.

Additional information

Children and policy changes

Widgy is not directed at children under 16 and we do not knowingly collect their personal data. A parent or guardian who believes a child has provided personal data should contact us through the Service Desk.

We may update this policy when Widgy changes, when new providers or paid features are introduced, or when legal requirements change. We will publish the updated date on this page and provide an additional notice when a change materially affects registered users.

Questions or requests

Talk to us about your data

Open Widgy and choose the privacy category in the Service Desk. Your request and our replies stay together on a private ticket page.

Open Widgy Support