What Duggie CMS collects, who we share it with, and how long we keep it.
Effective August 16, 2026
Duggie CMS is operated by Duggie Labs, LLC ("Duggie", "we", "us"). This policy explains what personal information the service handles and why. It covers duggiecms.com and the Duggie CMS application and API.
Duggie handles two kinds of information, and the difference matters because your rights differ between them.
If you are subject to the UK or EU GDPR and you store personal information in Duggie, that second relationship normally requires a data processing agreement between us. Contact us and we will put one in place.
The text, HTML, JSON, images and documents you upload to your projects, along with their version history, publication state, and the record of which account made each change.
If you subscribe to a paid plan, payment is handled by Stripe. Card numbers go directly to Stripe and never reach our servers. We pass Stripe your account email address when you start a checkout, so the receipt goes to the address we already hold. We keep a record of what you have bought, which is project slots and storage, with its status and renewal date, any complimentary slots we have given you, and the customer and subscription identifiers Stripe gives us.
Server logs, which include IP address and timestamps. Application logs, which record what the service did and can include the account identifier involved and, in some messages, an email address; these are sent to Better Stack, our logging provider. Activity records for your projects, which store what was done, when, and by whom, and do not include IP addresses. API usage counts used to enforce usage limits. If an error occurs, a diagnostic report is sent to Sentry, which may include the URL and the account identifier involved.
Three pieces of software from other companies run in your browser on this site. None of them advertise to you or follow you elsewhere.
We use no advertising or analytics cookies. What we do use is limited to running the service:
We use a small number of providers to run Duggie. Each receives only what it needs.
| Provider | Purpose | What it receives |
|---|---|---|
| MongoDB | Database | Account information and your stored content |
| Railway | Application hosting | All traffic to the service |
| Cloudflare | Website delivery, file storage, backup storage, security filtering, bot checks, page view analytics | Uploaded files, nightly database backups, and request metadata including IP address |
| Stripe | Payments | Your account email address, and billing details entered directly with Stripe |
| Brevo | Transactional email | Your email address and the message content |
| Sign in with Google, if you use it | Your email address and Google account identifier | |
| Sentry | Error monitoring | Diagnostic reports, which may include an account identifier |
| Better Stack | Application logs, uptime checks and the status page | Log messages, which can include an account identifier and sometimes an email address |
Uploaded files are scanned for malware by software we run ourselves. Your files are not sent to a third party scanning service.
We may also disclose information if the law requires it, or to protect the rights and safety of our users. If Duggie is ever acquired, account information would transfer with the business, and we would tell you before that happened.
Duggie is operated from the United States, and the providers above process information in the United States and other countries. If you are located elsewhere, using Duggie means your information is transferred to the United States.
Whatever your location, you can ask us to give you a copy of your information, correct it, or delete it. You can change most of it yourself in your account settings, and you can delete your account from there at any time.
If you are in the UK, the EU, or a US state with its own privacy law, you may also have the right to object to or restrict certain processing, to receive your information in a portable format, and to complain to your local data protection authority. We do not charge for these requests and we will not treat you differently for making one.
Traffic is encrypted in transit. Passwords are stored as salted hashes and are never recoverable in readable form. Project API keys are stored so that you can view them again in your project settings, and you can revoke or rotate any key at any time. Access to production systems is limited to people who need it. No service can promise perfect security, but if a breach affects your information we will tell you.
To help with a problem, a member of our support team can sign in to the app as it appears to you. This is read-only unless there is a recorded reason to make a change, each session is time-limited and logged with who opened it and when, and the first time one opens a project it leaves a line in that project's activity saying that support viewed it, so the people who work there can see that it happened. Changes our team makes that affect what you can do, such as a suspension, a blocked project, a replaced API key or a complimentary slot, are normally emailed to the account they affect.
Duggie is a tool for professional developers and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact us and we will remove it.
If we make a material change we will update the effective date above and tell account holders by email before it takes effect.
For any privacy question or request, including a data processing agreement, reach us through the contact page.