Privacy policy
Last updated: 25 June 2026.
ShareToWebhook is built around a simple privacy boundary: your webhook payloads are sent directly from your device or browser to the webhook endpoint you choose. They are not relayed through ShareToWebhook servers.
This policy explains what that means in practice, what the website and support channels collect, and what third-party services may receive data when you use the site or the app.
The short version
- Your shared content is not sent to ShareToWebhook servers.
- Your configured webhook URLs, headers, secrets, routing rules, and payload bodies are not stored on ShareToWebhook servers.
- The destination you choose, such as Zapier, Make, n8n, Slack, or your own server, receives the webhook request directly from your device or browser.
- The marketing site may collect normal website analytics, mailing-list signups, contact form messages, and diagnostic events.
- If you contact us for help, only include webhook payloads, endpoint URLs, tokens, or screenshots if you are comfortable sharing them for support.
Webhook data and endpoint settings
When you use ShareToWebhook to send a link, note, screenshot, app share, or other payload, the request is made from the app or browser extension directly to the endpoint you configured. ShareToWebhook does not operate a proxy, relay, queue, or processing server for that payload.
That means ShareToWebhook servers do not receive or store the shared URL, note text, screenshot, source app metadata, webhook URL, custom headers, authentication tokens, delivery response body, or delivery history for the core direct-send workflow.
The receiving webhook provider is different. If you send a payload to Zapier, Make, n8n, Slack, Hermes, a Cloudflare Worker, or your own HTTP endpoint, that provider receives and processes the payload according to its own terms, privacy policy, retention settings, and logs.
Endpoint configuration is intended to stay under your control in the app, browser, or platform storage you use with ShareToWebhook. If your device, browser profile, operating system, password manager, cloud backup, or app-store account syncs that data, that sync is handled by the platform provider, not by ShareToWebhook servers.
Information we collect
The information we collect depends on how you interact with ShareToWebhook.
- Mailing list and email updates: when you subscribe, Buttondown collects your email address and manages subscription status, confirmation, unsubscribe links, and email delivery.
- Contact and support: when you send a contact form or email, we receive the name, email address, enquiry type, message, and any details you choose to include.
- Website analytics: with your consent, we use PostHog to understand page views, signup and contact form events, internal CTA clicks, error events, referrers, device/browser details, approximate location derived from network information, and similar usage data. If you submit a signup or contact form after accepting analytics, analytics may associate that event with the email address you entered.
- Spam and abuse protection: the contact form uses Cloudflare Turnstile and a form processor to validate submissions and reduce spam.
- Billing and app-store records: if paid plans, app-store purchases, or subscriptions are available, the relevant payment processor or app store may process payment details, invoices, subscription status, tax records, and fraud-prevention data. ShareToWebhook should not receive your full card details.
- Support diagnostics: if you voluntarily send logs, screenshots, payload examples, endpoint URLs, headers, or response details while asking for help, we may use that information to investigate the issue.
Information we do not collect from direct webhook usage
For the core app workflow, ShareToWebhook does not collect webhook payload contents, destination endpoint URLs, custom headers, bearer tokens, API keys, routing rules, screenshots, attached files, delivery attempts, delivery results, or downstream automation output.
We also do not sell webhook data, use webhook payloads to train AI models, scan your payloads for advertising, or build a central inbox of your shared content.
How we use information
We use the information we collect to run the website, send product updates, reply to support and privacy questions, understand whether the site is working, diagnose errors, prevent spam and abuse, manage subscriptions or purchases, and improve ShareToWebhook.
We do not use customer webhook payloads to operate the website or product because those payloads do not pass through ShareToWebhook servers in the direct-send workflow.
Third-party processors
ShareToWebhook uses third-party services where they are needed to operate the website, email list, support flow, analytics, spam protection, hosting, payment, or app distribution. Current or expected providers include Buttondown for email subscriptions, PostHog for analytics and error diagnostics, Cloudflare Turnstile and form processing for contact form protection and delivery, hosting/CDN providers for the website, and payment or app-store providers for purchases.
Your configured webhook destination is also a third party from a privacy point of view. When you send data to a webhook, you choose the destination and that destination receives the payload directly.
Security
ShareToWebhook is designed to reduce server-side exposure by avoiding a central payload relay. You should still treat webhook URLs and tokens as secrets. Use HTTPS endpoints where possible, rotate tokens if they are exposed, and avoid sending sensitive content to destinations that are not configured to protect it.
No internet-connected system can be guaranteed perfectly secure. If you believe you have found a security or privacy issue, contact us promptly and include enough detail for us to investigate without unnecessarily sharing secrets.
Retention
Mailing-list data remains until you unsubscribe or ask us to remove it. Contact and support messages are kept while needed to respond, maintain records, and improve the product. Analytics and diagnostic data are retained according to the settings of the analytics provider and our operational needs. Billing and transaction records may be kept for accounting, tax, compliance, and fraud-prevention purposes.
Webhook payloads and endpoint settings used in the core direct-send workflow are not retained by ShareToWebhook servers because they are not sent to those servers.
Your choices
You can unsubscribe from email updates using the unsubscribe link in any mailing-list email. You can reject analytics when the site asks for consent. You can delete endpoint settings and local app data from the app, browser, or device where you configured them. You can ask us to delete or correct contact, support, or mailing-list information we hold about you.
If you use a third-party webhook destination, use that provider's controls to manage retention, logs, access, deletion, and downstream automations.
Children
ShareToWebhook is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy as the product, pricing, app platforms, and support workflows change. If ShareToWebhook ever introduces an optional server-side relay, sync service, hosted delivery history, team account, or similar feature that changes how webhook payloads are handled, this policy and the product interface should make that clear before you use that feature.
Contact
For privacy questions, email [email protected] or use the contact form.