Last updated: October 1, 2026
Privacy Policy
Saytkor.uz is a service for creating websites with artificial intelligence: the saytkor.uz platform and the saytlarim.uz addresses where users' websites are hosted. This page explains what data we collect, why we use it, where we store it and how you can request its deletion.
Data controller: the owner of the Saytkor.uz platform — self-employed individual A. Q. Omonov, Tashkent. Contact: support@saytkor.uz, Telegram: @Saytlarim_uz_Bot (💬 Help).
1. What data we collect
- Account data: your name, email address and password. Your password is stored encrypted — no one, including us, can see it.
- Google profile: if you sign in with Google — the name, email address and profile picture from your Google account. Google does not give us your password, and we cannot access your emails, files or contacts.
- Website data: the description you wrote about your website, your conversations with the AI, the website files and their versions, and the images and files you upload.
- Your ratings of AI answers and usage events: if you press 👍 or 👎 under an AI answer — your rating and the reason you picked; important actions in the editor and dashboard (for example, opening the editor, “Undo”, a publish attempt and its result, a “not enough credits” notice) — only the action name, time and website/account ID. The text you write, passwords and phone numbers are not recorded.
- Submissions: data that visitors to your website send through forms (usually a name, phone number and message). This data belongs to the website owner: we store it and deliver it to the website owner via Telegram.
- Customer account (Pro and Business): when a customer of your site signs in to the account — their Telegram ID and name, and the phone number if they shared it in Telegram themselves. These are used only to show their own orders and bookings on that site and to send status updates and reminders; the customer enters no password and sign-in codes are not stored.
- Connected services: if you connect the Telegram bot — the chat ID and name; if you connect your own bot on the Pro or Business plan — the bot's name and its encrypted token; if your site is opened inside Telegram (Mini App) and a form is submitted — the customer's Telegram name, @username and ID: they are passed only to the site owner; if you connect GitHub — your GitHub username and an encrypted access key.
- Payment data: the payment amount, date and status, the plan or pack chosen; if you entered a phone number so that an invoice can be sent to your Click app — your phone number. Card details (number, expiry, code) never reach us: they are entered only on the Click page.
- Technical data: credit history, service logs and a hash of your IP address for spam protection; the IP address itself is not stored in our database.
- Device identifier: a long random string of letters and digits (a UUID) created in your browser; it is not derived from your device, IP address or browser characteristics. It is kept in browser storage and in the
saytkor_devcookie for 2 years, is sent to the server and, when your account is first set up, is stored together with it. Its purpose is to prevent abuse of gift credits through many accounts opened from one device (if several accounts are opened from one device within 24 hours, gift credits are held until a review). It is not used for advertising or for tracking you on other websites, and is not shared with anyone. If you clear your browser storage and cookies, a new identifier is created. If you arrived through an invitation link, the invitation code is remembered in thesaytkor_refcookie for 30 days. The link through which you first came to Saytkor (UTM tags — for example, an Instagram ad — and the previous site's domain) is kept in thesaytkor_srccookie for 30 days and saved to your account when you sign up; the answer to the optional question after sign-up, “Where did you hear about Saytkor?”, is stored the same way. This is used only in overall statistics — to see which ads and channels are useful.
2. What we use the data for
- signing you in to your account and protecting it;
- creating, storing and publishing your website on the internet;
- delivering submissions from your website to you;
- preventing fraud, spam and unlawful websites (automated checks and moderation);
- sending service messages: email confirmation, password reset and the like;
- improving the service and helping you: finding where the AI misunderstood a request or made a mistake, improving the AI and, when needed, replying to you as the “Saytkor team” or refunding credits.
Your data is not used for advertising. No advertising or tracking cookies are used. The platform stores in your browser only what is necessary: your sign-in session, convenience settings (language, light/dark mode and the like), the invitation code, the first-visit source and the device identifier described above.
3. Where data is stored
- Supabase — accounts and the sign-in system, website files and versions, submissions (database).
- Cloudflare — published websites, uploaded images and files, and the network that makes websites load quickly. If you connect your own domain, the domain name is passed to Cloudflare for the connection and the SSL certificate.
The servers of these services are located outside Uzbekistan. All connections are encrypted over HTTPS. In the database, each user can see only their own data.
4. Service providers
For the platform to work, some data is shared with the following providers solely for that purpose:
- Anthropic (Claude AI) — the text you write and the website files when a website is created and edited; the website text before publishing, for automated checks.
- Telegram — to deliver submissions to you (on the Pro and Business plans — through your own bot and the Mini App).
- Click — to accept payments. Card details never reach us: they are entered on the Click page; we are told only the payment amount and status.
- Resend — to send service emails (confirmation, password reset, plan reminders): your email address and the text of the message are passed to it.
- Cloudflare Turnstile — for the bot and spam protection check when you sign in or sign up: during the check, your browser data and IP address are sent to Cloudflare.
- Google Fonts — to load fonts: when the platform and websites open, your browser fetches fonts from Google's servers (your IP address is visible to Google).
- Yandex Maps and OpenStreetMap — for maps: if a website has a map, the visitor's browser loads the Yandex map; when you search for an address in the editor, the search text and the map point are sent to OpenStreetMap.
- Google — if you choose to sign in with Google.
- GitHub — if you choose to push your website to your own repository.
- Pexels — when you search for stock images, only the search terms are sent; no personal data is sent.
5. Who we do not share data with
We do not sell your data, rent it out or give it to advertising companies. It is not shared with anyone other than the providers listed above. The only exception is an official request from an authorized government body in cases provided for by the legislation of the Republic of Uzbekistan.
6. Staff access
The platform owner and authorized staff (administrator, moderator) may view your data only to provide support, for moderation (checking unlawful websites) and for security (combating abuse). No one can see your passwords or your bot tokens: the password is irreversibly encrypted, the bot token is stored encrypted, is not shown in the admin panel or in logs, and is used only by the server itself to send messages.
To improve the service and help you, our team may view your conversations with the AI (your requests, the AI's answers, attached screenshots) and the events listed above. This is done in a protected section available only to administrators and opened with two-step verification (2FA); emails and phone numbers are hidden in lists, and every full view is recorded in the log. This data is never shared with anyone. Data about students and children (AI Ustoz) never appears in this section.
7. Retention and deletion
- Data is kept for as long as your account is active (except submissions — see below).
- Submissions sent to websites through forms are kept for 90 days and then deleted automatically.
- AI request texts and usage events kept to improve the service are stored for 90 days and then deleted automatically; only overall statistics not linked to any person (for example, the number of requests) remain. Your own chat history in the editor is kept together with your website.
- If you delete a website yourself (editor → Settings → Delete site), its files, versions, uploaded images and submissions are deleted.
- To delete your account and all your data, send an email from the address you registered with to support@saytkor.uz with the subject "Delete my data". We will complete the request within 30 days and reply to you.
- If you submitted a form on a website and want your data deleted, write to the owner of that website or to us.
- If you signed in with Google, you can revoke the access you granted to Saytkor.uz at any time in your Google account settings (myaccount.google.com → Security → Third-party apps & services).
8. CRM: student and parent data
The “CRM” section on the Pro and Business plans is for learning centres: it holds data about leads, students, parents, attendance and payments.
- The operator is the site owner. The site owner (the learning centre) is the operator responsible for the data entered into the CRM — students, their parents, phone numbers, birthdays, attendance and payments. Saytkor.uz stores and processes this data only on the owner's behalf; it does not use it for its own purposes, sell it or share it with third parties.
- Minors. Students are often minors. Obtaining the consent of parents or legal guardians to collect their data is the responsibility of the learning centre (the site owner).
- Who can see it. Only the site owner and the staff they invite (manager, teacher) can access the data; a teacher cannot see students' phone numbers or payments. Platform staff may access it only for the purposes listed in section 6.
- Retention and deletion. CRM data is kept while your account is active (the 90-day limit for submissions does not apply to it). The site owner can delete single records or all CRM data at any time via “CRM → Settings”; when a site is deleted, its CRM data is deleted too.
- No artificial intelligence. The CRM does not send student or parent data to artificial intelligence and does not spend credits.
- “AI Ustoz” (optional, Pro and Business). It works only if the site owner switches it on: a question a student types into the site's “AI Ustoz” window is sent to Anthropic (Claude AI) to get an answer. The question text is not stored; the log keeps only the time, an anonymous device tag and the credits spent, and answers to identical questions are cached. AI Ustoz does not ask for personal details and reminds students not to share them; the cost comes from the site owner's credits.
9. Age restriction
The service is intended for users over 16 years of age. Persons under 16 may use it with the consent of a parent or legal representative.
10. Changes and contact
If this policy changes, we will show the updated date on this page; we will notify you of significant changes on the platform or by email. For questions: support@saytkor.uz.
See also: Public offer.