What we know about you.
An email address, the strokes you drew, and which fonts you bought. No tracking cookies, no advertising, no profiling, and nothing sold to anybody.
- IN EFFECT
- 6 September 2026
- WHO
- DAN BILLSON, TRADING AS POTHOOKS
- WHERE
- UNITED KINGDOM
- CONTACT
- dan@dnbls.com
01WHO IS RESPONSIBLE
Dan Billson, trading as Pothooks, is the data controller for everything described here. There is no data protection officer — the operation is one person — so requests and complaints go straight to dan@dnbls.com and are answered by that person.
02WHAT WE COLLECT
- EMAIL ADDRESS
- Only if you sign in. It is the account — there is no password, no name field and no profile.
- YOUR STROKES
- The pen paths you draw, plus the settings of the font they belong to. Held as raw coordinates, not as images.
- LICENCES
- Which fonts you have bought, and the reference of the order that bought them.
- SESSIONS
- A sign-in cookie, so you stay signed in, and a record of when a code was sent so it cannot be brute-forced.
- ANALYTICS
- Aggregate page views through Vercel Analytics — cookieless, and never joined to your account.
We do not collect payment details. When you buy, you are handed to Polar Software Inc., who takes the payment and tells us only that an order was paid and which font it was for. Your card number never reaches us.
03WHY, AND ON WHAT BASIS
- RUNNING YOUR ACCOUNT
- Performance of our contract with you — syncing your work and recording what you own is the service.
- SENDING SIGN-IN CODES
- Performance of our contract. It is the only way in.
- KEEPING IT UP
- Legitimate interests: rate limiting, blocking abuse, and understanding roughly how many people use which page.
- TAX AND ACCOUNTING
- Legal obligation, discharged mostly by our merchant of record, who keeps the invoices.
No part of this relies on consent, so there is no consent to withdraw — and no cookie banner, because the only cookie is the one that keeps you signed in and analytics does not set one. If you object to the legitimate-interests processing above, say so and we will look at it on its own facts.
04WHO ELSE TOUCHES IT
Four processors, each doing one job under contract, none of them permitted to use your data for their own purposes:
- VERCEL
- Hosting and privacy-friendly analytics — privacy notice
- NEON
- The Postgres database behind your account — privacy notice
- POLAR
- Payments, invoicing and tax, as merchant of record — privacy notice
- RESEND
- Delivering sign-in codes — privacy notice
Some of these are outside the UK, so your data may be transferred abroad. Those transfers are covered by the UK International Data Transfer Addendum or the equivalent standard contractual clauses in each provider’s terms.
Beyond that, nobody. We do not sell data, share it with advertisers, or hand it over to anyone except where the law actually requires it.
05HOW LONG WE KEEP IT
Your account and your work stay until you delete them. A font you delete is marked as deleted rather than erased on the spot — the app syncs across devices, and a row that simply vanished would reappear the next time another device pushed. The mark is what stops that, and it is cleared with the rest of your data when the account goes.
Ask us to delete your account and we remove the account, the strokes and the sessions. Records of what was bought and paid have to outlive that: Polar Software Inc. keeps order and tax records for as long as tax law requires, which is typically six years, and we keep the minimum needed to know a licence was validly issued.
06YOUR RIGHTS
Under UK GDPR you can ask us to:
- 01Give you a copy of what we hold about you, in a portable form.
- 02Correct anything wrong — in practice that means your email address.
- 03Delete your account and everything in it, subject to the tax records above.
- 04Restrict or object to processing we do on legitimate-interests grounds.
Email dan@dnbls.com. We answer within one month, free. If you are unhappy with how we handled it you can complain to the Information Commissioner's Office, the UK supervisory authority — though we would rather you gave us the chance to fix it first.
07SECURITY, AND WHAT WE WOULD DO IF IT WENT WRONG
Traffic is encrypted in transit, the database is encrypted at rest, sign-in codes expire in ten minutes and die after three wrong guesses, and nobody holds a password because there are none to hold.
If there were a breach that put you at risk, we would tell you, and tell the regulator within 72 hours. We would rather say that here than discover we had never thought about it.
08CHANGES
If this notice changes materially we will say so on the site before it takes effect. The date at the top is the version you are reading.