Webhook Widget

Legal

Privacy

There are no accounts or analytics. The app connects to the servers you choose, and this page explains what data stays on your device and what the website receives.

Who runs Webhook Widget

Webhook Widget is made and run by Owen Oclee, working as an individual in the United Kingdom rather than through a company. Under UK GDPR that makes me the data controller for what this page describes. Where the rest of it says we or us, that is one person.

Anything you want to ask about privacy goes to support@webhookwidget.com, which is the quickest way to reach me. Post gets here too:

Owen Oclee
Unit 171699
PO Box 7169
Poole
BH15 9EL
United Kingdom

The app

What it sends, and where

The app fetches the URLs you register as hooks. It does not send them anywhere else, and it does not route them through us. Every request carries a description of the slot the widget is about to fill, appended to your own URL as query parameters:

ParameterWhat it is
family, w, h, scaleThe widget size and screen scale
schemeWhether the device is in light or dark mode
locale, tzYour device's locale and time zone
vThe protocol version the app speaks

locale and tz are there so a server can format dates and times correctly without guessing. They describe your device, not you, but they do narrow down roughly where in the world it is — and the server you are fetching from sees your IP address in any case, as it would for any request from your phone. The full list is documented under the request; nothing else is added.

If a response contains an image node, the app fetches that image from the address the response names, using the same credential as the feed.

What it stores on your device

Your hooks — the name, the URL and any credential — and the last response each one returned, so a widget can show its previous content rather than an empty face when a fetch fails. Both live in the app's own container on your device, shared between the app and its widget extension, sandboxed to the app and encrypted with the rest of the device. Neither is sent to us or to anyone else.

The networking layer is configured to persist nothing of its own: no cookies, no credential store, no response cache beyond the one described above. Deleting the app removes all of it.

What we receive

Nothing, unless you ask for it. The app arrives with no hooks at all and registers none on its own, so every address it fetches is one you put there.

The only way it would contact us is if you take one of the examples — the demos this site documents, offered when you add a hook, which point at webhookwidget.com/demo/…. Those are the only addresses in the app that we run. Taking one registers it like any other hook, and nothing is fetched until you ask; from then on it behaves like any hook you wrote, including on a widget, and those requests reach our server with your IP address and the parameters in the table above. Delete the hook and the requests stop.

Beyond that, the app makes no requests to us. There is no telemetry, no crash reporting and no check-in.

This website

The documentation is static. There are no analytics, no advertising, no tracking pixels and no third-party scripts — the pages load nothing from any other domain. No cookies are set, and nothing is stored in your browser.

The site is served by Cloudflare, which records standard request logs on our behalf — the sort of information any web server receives, including IP address, the page requested, and your browser's user agent. We use them to see whether the site is working.

The playground and the previews run entirely in your browser. A payload you type is rendered on your own machine and is not uploaded to us. Two things are worth knowing: a payload placed in a page's query string is part of the request to our server and so appears in those logs, and pointing a preview at a src URL makes your browser fetch that address directly.

The demo endpoints under /demo/ build their responses at the moment of the request and store nothing about who asked.

Sharing a hook

The QR code or the link the app produces when you share a hook contains that hook's URL and its credential. That is what lets someone add it without typing anything. It is generated on your device and is not sent to us; where it goes afterwards is up to you. It is signed, not encrypted, so treat one like the credential inside it: anyone who can see the code can read the feed.

The signature is made by a key created on your phone the first time you share something. It never leaves the device, and it is not tied to your name, your Apple Account or anything we hold — there are no accounts here for it to be tied to. What the recipient sees is that key's fingerprint and, if you have set one, a display name you chose. Setting a name is optional and it is stored only on your device and inside the codes you make.

There is a second kind of code, the one that adds a hook as your own rather than as a gift from somebody else. Nothing on this site makes one: the tool that built your feed builds it, wherever that tool runs. No page here asks for a hook's address or its credential, which is deliberate — a page that took them could keep them.

Your data

There are no accounts, so there is nothing to log into and no profile to export or delete. What exists is the server logs described above and whatever is on your own device, which deleting the app removes. If you want to ask about either, or want logs relating to your IP address removed, get in touch.

Changes

If this policy changes, the date below changes with it. Last updated 24 August 2026.