← Back to most.

Privacy Policy

Last updated: June 25, 2026

This Privacy Policy explains how most. ("most.", "we", "us") collects, uses, stores, and shares information when you use the most.tools web application and the most. Webflow Designer Extension (together, the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR) and applies to all users of the Service.

1. Who is responsible (Data Controller)

The data controller responsible for your personal data is:

[INSERT LEGAL ENTITY NAME / ADDRESS]
Contact: vitalii@most.tools

This placeholder must be replaced with the operator's full legal name and postal address before this policy is relied on for live, production use — this is a legal requirement under GDPR Art. 13 and, if the operator is based in Germany, under the Digital Services Act/TMG provider-identification rules (Impressum).

2. What data we collect

  • Account data: email address, hashed password, display name, account role, and credit balance, when you register for most.tools.
  • Webflow connection data: when you connect your Webflow account (via OAuth or a manually-entered API token), we store the resulting Webflow access token and the connected Site ID/name, so the Service can read and write content on your behalf.
  • Content you generate: prompts, generated page/CMS content, project and keyword data you create or import while using the Service.
  • Usage data: login timestamps, generation/credit usage, and basic application logs needed to operate and secure the Service.
  • Communications: if you contact us for support, we retain that correspondence.

We do not knowingly collect special categories of personal data (Art. 9 GDPR), and the Service is not directed at children under 16.

3. How we use your data

  • To provide, operate, and maintain the Service (Art. 6(1)(b) GDPR — performance of a contract).
  • To authenticate you and keep your account secure.
  • To generate landing page and CMS content on your behalf using your prompts and connected Webflow data.
  • To meter and enforce credit usage.
  • To send account-related emails (e.g. email verification, password reset) — never marketing email without separate consent.
  • To diagnose technical issues and prevent abuse (Art. 6(1)(f) GDPR — legitimate interest).

4. Who we share data with

We use the following third-party processors to operate the Service. Each only receives the minimum data needed to perform its function:

  • Webflow, Inc. — to read/write site, page, CMS, and asset data on the site you explicitly connect.
  • Anthropic, PBC — to generate page and CMS content from your prompts (Claude API).
  • DataForSEO — to retrieve keyword and local-SEO data you request.
  • Resend — to deliver transactional emails (verification, password reset).
  • Vercel Inc. — application hosting.
  • Neon, Inc. — managed PostgreSQL database hosting, where your account and connection data is stored.

We do not sell personal data, and we do not share your data with third parties for their own marketing purposes. Some of these processors are located in the United States; where required, transfers rely on Standard Contractual Clauses or an equivalent GDPR Art. 46 safeguard.

5. Data retention

We retain account and connection data for as long as your account is active. If you delete your account or disconnect Webflow, the associated token and site information are deleted from our database. You may request deletion of your account and associated data at any time by contacting us (see Section 9).

6. Security

All traffic to the Service is encrypted in transit (HTTPS/TLS). Passwords are stored only as salted bcrypt hashes, never in plain text. Access to the database and third-party API credentials is restricted to what the Service requires to operate.

7. Cookies

The Service uses a single strictly-necessary session cookie to keep you signed in. We do not use third-party advertising or analytics cookies.

8. Your rights (GDPR)

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Correct inaccurate data (Art. 16).
  • Request erasure of your data (Art. 17).
  • Request a copy of your data in a portable format (Art. 20).
  • Object to or restrict certain processing (Art. 18, 21).
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local data protection supervisory authority.

9. Contact

For any privacy request or question, contact: vitalii@most.tools

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

This document is a template generated to describe the Service's actual current data practices. It is not a substitute for legal advice — have it reviewed by a qualified lawyer (particularly to fill in the data controller's legal name/address) before relying on it for compliance purposes.