Privacy policy
Effective 21 September 2026. This policy covers the One Click for ChatGPT preparation service and its information pages. The operator and controller is AYOBAMI JOHN HAASTRUP, United Kingdom. Contact: john@tailwaggingwebdesign.com.
One Click uses the website details you choose to provide to prepare a brief and return it to your chat. It does not save that brief in an account or project database. Small operational events are kept for three months. Creating a website through Lovable is a separate action that you review and authorise.
1. Data we process and why
Website requirements and generated output
The preparation tool receives the specific fields that ChatGPT, Codex or your MCP client sends for your request. These can contain personal data if, for example, you choose a sole trader's name as a business name. The tool requires only an industry and a primary website goal; every other field is optional.
| Field | Purpose and limit |
|---|---|
Industryindustry | Required. Business type used to shape the brief; up to 120 characters. |
Primary goalprimary_goal | Required. The outcome the website should support; up to 240 characters. |
Business namebusiness_name | Optional. Names the draft; up to 100 characters. A generic label is used if omitted. |
Brand directionbrand_vibe | Optional. Describes the desired tone and style; up to 160 characters. |
Headlineheadline | Optional. Supplies headline direction; up to 180 characters. |
Call to actioncall_to_action | Optional. Describes the main visitor action; up to 80 characters. |
Layoutlayout | Optional. Selects a layout from the tool's fixed list. |
Servicesservices | Optional. Lists services to include; up to 12 items of 120 characters each. |
We validate these fields, normalise their text and return a structured brief, a generated build prompt and a reminder to review it before authorising external project creation. The output includes the supplied website details. One Click does not fetch files, browse reference URLs, call an AI model, or contact Lovable while preparing this response.
Do not send passwords, API keys, payment card details, government identifiers, health information, private customer records or unrelated conversation history. There are no fields for files, account credentials, location or full chat transcripts. Unknown fields are rejected. Text fields cannot reliably detect every kind of sensitive information: only include business information needed for the brief.
Operational events
To measure reliability and aggregate usage, a tool attempt may record: the event type, a fixed tool label (or unknown_tool), success or error outcome, rounded processing time, numeric response status, release version and a coarse client family (ChatGPT, Codex or other MCP). Cloudflare Analytics Engine also assigns an event timestamp and sampling metadata.
The client family is determined from the User-Agent and Origin headers; the raw values are not saved in the event. We do not put brief content, generated prompts, business names, URLs, IP addresses, raw request headers, error details, arbitrary tool names, account IDs or persistent user identifiers into these events. We do not use them to identify users, profile behaviour, advertise, sell data or train AI models.
Hosting and support
Cloudflare processes network information such as IP addresses, request headers, request paths and transport metadata to receive, route and protect HTTPS requests. This processing is distinct from the minimal operational events above. Stored Worker request logs, invocation logs, tracing and log export are disabled for this release; our application does not write request content to console logs.
If you email support, we receive your email address, message, attachments you choose to send and our correspondence. We use these only to answer the request, investigate a reported problem or handle your privacy rights. Please send a short description and a redacted example; a full chat transcript is not needed.
2. Who receives the data
- Cloudflare: hosts the preparation service and stores the minimal Analytics Engine events on our behalf. Its separate processing for network security and service administration is described in Cloudflare's privacy policy.
- OpenAI or your chosen MCP client: sends the selected inputs and receives the brief and build prompt. Chat history, client-side copies and OpenAI's use or retention of that data are controlled by that service and your settings, not by One Click. See OpenAI's privacy policy.
- Lovable, only after a separate action: if you authorise ChatGPT to create a project using the separately installed Lovable service, ChatGPT may send the reviewed handoff and any files you separately select to Lovable. One Click's preparation tool does not perform that transfer. See Lovable's privacy policy.
- Support recipients: the operator and email service providers handle support correspondence. We do not ask you to post privacy requests on public GitHub issues.
These providers may process data outside the UK, including in the United States. Applicable provider data-processing terms and transfer safeguards govern processing they perform for us. Contact us for information about the safeguards applicable to your request. Data you send through a separate OpenAI, MCP client or Lovable account is also subject to that provider's terms.
3. How long data is kept
| Data | Retention and deletion |
|---|---|
| Website inputs and generated brief | Processed in memory for the request and returned to the calling client. One Click does not persist them, create saved projects, or maintain a brief history or backup to retrieve or delete later. The service does not promise deletion of copies kept by your client. |
| Operational analytics | Cloudflare Analytics Engine retains events for three months, after which they expire. We do not export them to a separate long-term store. This is the provider's documented period, not a claim that three months always equals 90 days. See Analytics Engine retention. |
| Worker logs from earlier releases | New stored Worker logs are disabled in this release. Previously collected logs may remain in Cloudflare for up to seven days from collection before expiry. Disabling logging does not erase existing logs. See Workers Logs retention. |
| Cloudflare network/service records | Cloudflare controls records it processes for its own network security and service administration. Its privacy policy describes retention according to the purpose, security needs and legal requirements. The three-month event limit above does not describe all provider-held records. |
| Support correspondence | Kept while resolving your request and for up to 90 days after closure, then deleted from our active support mailbox. If a specific legal duty or unresolved dispute requires longer retention, we limit the retained material to that purpose, explain the reason when applicable, and delete it when that need ends. Email providers may retain residual backups under their own policies. |
| ChatGPT, other clients and Lovable | The relevant provider's retention rules and your account settings apply to its copies. Deleting or disconnecting One Click does not automatically delete a chat or a separately created Lovable project. |
4. Your choices and controls
- Provide only the required industry and goal, use a generic business label and omit optional details. Review the fields that your client proposes to send and decline the tool call if you do not want them processed. Without the two required fields, One Click cannot prepare the brief.
- Review and edit the returned handoff before any external project creation. You can stop after preparation and decline the separate Lovable action.
- Disconnect or stop using One Click in your client to prevent future calls. Use that client's chat deletion and privacy settings for copies in the conversation.
- Direct MCP clients can suppress the operational event for an individual request by sending
DNT: 1orSec-GPC: 1. The brief still works. This choice is read for that request only and creates no cookie or stored identifier. ChatGPT may not expose custom request headers; One Click does not claim that an in-chat analytics toggle exists. - Ask us to access, correct or delete support correspondence, or to restrict processing where applicable. Operational events contain no persistent user identifier, so we cannot reliably find an individual user's events; we do not collect extra identity data just to link them. They expire after three months.
These information pages set no cookies, use no browser storage and include no third-party tracking scripts. This statement covers this plugin service, not the separate One Click website or other linked services.
5. Privacy requests and rights
Email john@tailwaggingwebdesign.com with the subject One Click privacy request. Describe what you want us to do and provide only enough information to locate the relevant correspondence. We may ask for proportionate verification before disclosing personal information; do not send identity documents or secrets with your first message.
Where UK data protection law applies, we process information necessary to provide the service you request (performance of our service contract), rely on legitimate interests for proportionate reliability monitoring and ordinary support, and comply with legal obligations when handling applicable rights requests. We do not make automated decisions that have legal or similarly significant effects on you.
You may have rights to access, correction, erasure, restriction and portability, depending on the circumstances. You can object to processing based on legitimate interests by emailing the privacy contact. We consider requests individually and explain any applicable limits, including data we do not hold. You may also complain to the UK Information Commissioner's Office or your local data protection authority.
6. Changes to this policy
We update this page when the service's data handling changes and show the effective date above. Any future account storage, new recipient or expanded tool input requires a fresh disclosure before it is introduced.