Privacy

Privacy Policy

Simple Host (simple-host.app) · last updated 2026-09-01

Simple Host is a static-website hosting service. This policy covers what data it handles, including when the service is used through an integration such as a ChatGPT GPT, an MCP server, or an AI coding agent.

What we collect

How we use it

Visitor analytics

This section is for people who visit a hosted site — whose loads get counted — not for people deploying one.

When you open a page hosted here, Simple Host counts that visit so the person who published the site can see how many people read it.

The count is taken entirely on the server, from the web server's own access log. Nothing is put on the page you load. There is no analytics script, no beacon, no analytics cookie, and no fingerprint of your browser. Your browser is never touched for this.

The access log line for a request includes the time, which host was asked, the HTTP status, the method, the page path, your IP address, and the User-Agent string. Those log lines are rotated off the server after 30 days.

What we keep in the analytics database is narrower:

The owner of a site can see view and unique-visitor counts for their own sites. The admin of this Simple Host instance can see those counts for every site on it. Neither is shown your IP address or the hash itself.

A hash of an IP is not a person. People on the same office or home network can look like one visitor; a phone moving between wifi and cellular can look like two.

There is no opt-out of being counted. Blocking cookies or sending a do-not-track header does not change a server log.

Separately from page-view analytics: calls to the API (/v1/…) — including when a hosted page saves data, posts a comment, or submits an RSVP — record the raw caller IP, so abuse can be investigated. Those IPs are kept for 30 days. A country/city/organization lookup for each IP is requested from ip-api.com (the IP only, no request data) and cached with no expiry. Only this instance's admin can see that table. Loading a static page is not an API call and is not stored there.

Using Simple Host through a GPT or agent

When you use Simple Host through a shared ChatGPT GPT or agent, requests are made with the API key configured in that integration. Anything deployed is public and belongs to the account whose key is used. Sites and their data are public to anyone with the link.

Retention & your choices

Third parties

We use an email provider to send sign-in codes, Google when you choose that button (Google sees that you signed in here; more providers later), and a hosting provider to run the service. The optional "Create with AI" feature sends your prompt (and any attachments) to xAI's Grok to generate a site. API caller IPs are sent to ip-api.com for a country/city lookup (the IP only). No other third-party sharing.

Contact

Questions or data requests: vineetu@gmail.com.