Summary: SimpleDashboard collects only the data necessary to provide its service (account email for authentication, and messages you send to generate dashboards). Your data is never sold or used for advertising. SimpleDashboard requires an active Claude subscription (claude.ai) to function. AI conversations run through your own Anthropic account — meaning your data is governed by Anthropic's privacy policy and terms directly.
The following table describes each category of data SimpleDashboard collects, its purpose, and legal basis under GDPR:
| Data | Source | Purpose | Legal basis (GDPR Art. 6) | Storage |
|---|---|---|---|---|
| Google account email and display name | Google Sign-In (OAuth 2.0) | User authentication and account identification | Performance of a contract (Art. 6(1)(b)) | Stored on our server linked to your dashboard workspace; retained until you delete your account |
| AI chat messages (prompts you type to generate or modify your dashboard) | You, via the chat interface | Processed by Anthropic Claude via your own Claude subscription. SimpleDashboard requires an active claude.ai account — your prompts are sent through your personal Anthropic account, so Anthropic's own privacy policy and data processing terms apply directly to AI processing. | Performance of a contract (Art. 6(1)(b)) | Transmitted to Anthropic under your Claude account (see Section 5); conversation history stored on our server for continuity; deletable via account deletion |
| Isolated workspace container (created on first sign-in) | Automatically provisioned upon registration | A private Linux container with Claude CLI and dashboard templates is created for each user. It contains only the files you generate — no personal data beyond what you produce in the chat. | Performance of a contract (Art. 6(1)(b)) | Stored on our EU servers (Hetzner, Finland); deleted upon account deletion |
| Dashboard content (layouts, widgets, data source configurations you create) | You, via AI chat or direct edits | To render and serve your dashboard at d[number].wpmix.net |
Performance of a contract (Art. 6(1)(b)) | Stored on our server; retained until you delete your workspace |
| Web3 keypair (cryptographic key pair used as a session token) | Generated locally on first launch | Session authentication for guest access (no Google Sign-In) | Legitimate interest (Art. 6(1)(f)) — secure authentication without storing a password | chrome.storage.local on your device only; never transmitted to our servers |
| JWT session token | Issued by our server after authentication | Maintains your login session | Performance of a contract (Art. 6(1)(b)) | localStorage in your browser; expires after 30 days |
| Uploaded data files (CSV files, Google Sheets URLs you provide) | You, as data sources for your dashboard | To populate dashboard charts and tables | Performance of a contract (Art. 6(1)(b)) | Processed server-side to generate the dashboard; raw files are not permanently stored |
| IP address (from server access logs) | Automatically from your browser when you access our service | Security monitoring and abuse prevention | Legitimate interest (Art. 6(1)(f)) | Server access logs retained for up to 14 days, then automatically deleted |
We do not collect: browsing history, content of web pages you visit, location data, microphone or camera data, financial information, or health information.
SimpleDashboard does not use tracking cookies or advertising cookies. We use only:
No analytics cookies, advertising cookies, or third-party tracking scripts are present on simpledashboard.wpmix.net or in the Chrome Extension package.
We do not use Google Analytics, Mixpanel, Amplitude, or any other third-party analytics service. No analytics code is embedded in the extension or the web application. We do not track individual user behaviour beyond what is necessary to operate the service (e.g., server access logs with IP addresses, retained for up to 14 days for security purposes).
d[number].wpmix.net).We do not use your data to serve personalized advertising, build behavioural profiles, or for any purpose beyond operating the SimpleDashboard service.
SimpleDashboard uses the following third-party services that receive your data. Anthropic and Google are US-based companies. Data transfers to the US are covered by Standard Contractual Clauses (SCCs) as defined under GDPR Art. 46(2)(c), which these providers have implemented as part of their Data Processing Agreements.
| Service | Data Shared | Purpose | Location | Transfer basis | Their Privacy Policy |
|---|---|---|---|---|---|
| Anthropic (Claude) | Your chat messages (prompts). Important: SimpleDashboard requires a Claude subscription — AI processing runs through your own Anthropic account. Anthropic processes your data as a data controller under their own terms, not as our processor. | AI-powered dashboard generation via user's own Claude account | USA | Not applicable — data is processed under the user's direct agreement with Anthropic, not transferred by us | anthropic.com/privacy |
| Google OAuth | Email address and display name (from Google account) | Authentication via Google Sign-In | USA | SCCs + Google DPA | policies.google.com/privacy |
| Google Fonts | IP address (standard web request) | Font rendering on the dashboard web app | USA | SCCs | policies.google.com/privacy |
| Hetzner (hosting) | All data stored on our servers | Infrastructure and hosting | Finland, EU | Within EEA — no transfer | hetzner.com/legal/privacy-policy |
We do not share your data with advertising networks, data brokers, or any other third parties not listed above.
The SimpleDashboard Chrome Extension requests the following permissions and uses them strictly as described:
*.wpmix.net pages only, to enable Web3 keypair session authentication. No scripts are injected into any other domains.*.wpmix.net) — grants access only to wpmix.net subdomains (your dashboard). The extension does not have access to any other websites you visit.chrome.storage.local; deleted when you uninstall the extension.If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. As OnOut OÜ is registered in Estonia, the lead supervisory authority is the Estonian Data Protection Inspectorate (aki.ee). You may also contact the supervisory authority in your country of residence.
SimpleDashboard is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
We may update this policy to reflect changes in our practices or legal requirements. The "Last updated" date at the top will reflect any changes. We will make reasonable efforts to notify registered users of material changes (e.g., via an in-app notice or email where technically feasible).
Data controller: OnOut OÜ
Trading name: NoxonThemes
Country of registration: Estonia, EU
Email: [email protected]
Website: onout.org