Privacy Policy
This policy explains what personal data DisplayWord collects, why, who else sees it, and what you can do about it. It covers both the website displayword.com and the DisplayWord software.
We have tried to write it as a description of what actually happens rather than as a list of everything we might one day do.
1. Who is responsible
The data controller is David Willart, an individual entrepreneur registered in Israel (osek patur), trading as DisplayWord.
Contact for any privacy question or request: [email protected]
We have not appointed a Data Protection Officer; the law does not require one for an operation of this size.
2. The short version
- You can use the Software without giving us anything at all. No account, no registration and no payment card is needed — including for the 60 days of full access to a paid edition. If you never subscribe, we never learn who you are.
- When you do create an account, we collect very little: an email address, and a few details about your congregation when you request a licence key.
- There is no analytics on this website. No Google Analytics, no tracking pixels, no advertising cookies, no third-party trackers of any kind.
- One cookie, strictly technical, set only after you sign in.
- The Software does not phone home. It contacts us to activate a licence and to check for updates. That is all.
- Your songbooks, service plans and settings never leave your computer. We cannot see them.
- We do not sell personal data. We do not share it for advertising. There is no advertising.
3. What we collect on the website
3.1 Creating an account
Two things: your email address and a password. Nothing else — no name, no telephone number, no organisation.
Your password is stored as a cryptographic hash. It is not stored in readable form anywhere and cannot be recovered by us.
We also generate an internal identifier and record the date the account was created.
3.2 Requesting a licence key
When you apply for a key, we ask for:
| Field | Required |
|---|---|
| Name of your congregation or organisation | yes |
| City and country | yes |
| Country code (pre-filled from your connection, editable by you) | yes |
| Edition requested | yes |
| Contact details — phone or messenger | no |
| Approximate number of members | no |
| Free-text message | no |
3.3 Newsletter
If you subscribe, we store your email address and nothing else.
3.4 What we do not collect
- We do not store your IP address. What is stored instead is the two-letter country code of your connection — country only, not city, not address.
- We do not record your browser's user agent.
- We do not use analytics, counters, pixels or advertising tools of any kind. This was verified across the whole site.
One narrow exception, for honesty: when an administrator performs an action on a licence key — issuing it, resending it, revoking it — we record that action, who did it, and the administrator's IP address, in an internal audit log. This concerns our own staff actions, not visitors.
3.5 Error logs
When something fails — an email does not go out, a third-party service returns an error — a technical message is written to our hosting provider's system log. We deliberately do not print email addresses into these messages. The text of a third-party error response may occasionally contain one. Retention of these logs is governed by the hosting provider's own policy.
4. What the Software collects
4.1 Activation
When you activate a licence key, the Software sends us the key and an installation fingerprint.
We want to be precise about what the fingerprint is, because vague wording here is how privacy policies become untrue.
The fingerprint is produced by taking three values from your computer — the computer name, the Windows user name, and the hardware address of the first active network adapter — combining them, applying a SHA-256 hash, and keeping the first half of the result.
What this means in practice:
- The original values cannot be recovered from the fingerprint. The hash is one-way and is additionally truncated. Your computer name, user name and hardware address are never transmitted or stored by us in readable form.
- We do not treat the fingerprint as anonymous data. It is stable and its purpose is precisely to tell one installation from another. Under the GDPR this is pseudonymised personal data, not anonymous data, and we treat it accordingly.
Its only purpose is to enforce the number of installations a key permits.
We also record the two-letter country code of the activation request.
4.2 Updates
The Software periodically asks our release server whether a newer version exists. This is a request for a file. No information about your computer, your installation or your usage is attached.
4.3 What stays on your device
Your songbooks, service plans, settings, backgrounds and any media you add are stored locally on your computer. They are never uploaded to us. We cannot read them, and we cannot recover them for you.
4.4 No usage tracking
The Software contains no analytics, no usage statistics and no crash reporting. We do not know which features you use or how often you run it.
5. Why we are allowed to process this (legal bases)
For readers in the EU, EEA and UK, the GDPR requires us to state a legal basis for each purpose.
| What | Purpose | Legal basis |
|---|---|---|
| Email and password | Operating your account | Performance of a contract (Art. 6(1)(b)) |
| Licence application details | Assessing and issuing your key | Performance of a contract, and steps taken at your request before entering one |
| Installation fingerprint | Enforcing the installation limit of your licence | Legitimate interests (Art. 6(1)(f)) — protecting the licensed product against unlimited copying, using the least identifying method we could design |
| Country code | Statistical understanding of where the Software is used; fraud prevention | Legitimate interests |
| Administrator audit log | Accountability for actions on licence keys | Legitimate interests |
| Newsletter | Sending you the newsletter | Consent (Art. 6(1)(a)) — withdrawable at any time |
6. How long we keep it
We keep personal data only as long as it serves the purpose it was collected for.
We will describe what actually happens rather than what sounds reassuring.
| Data | Retained |
|---|---|
| Account and its licence applications | for as long as the account exists |
| Licence keys and activation records | for as long as the key exists, so that the installation limit can be enforced |
| Administrator audit log | for as long as the account exists |
| Newsletter address | until you unsubscribe |
| Sign-in session | 30 days, then it expires automatically |
| Email confirmation token | 24 hours, then it expires automatically |
We do not currently delete accounts automatically after a period of inactivity. Sessions and confirmation tokens expire on their own; everything else stays until you ask us to remove it.
You can have your data deleted at any time by asking — write to [email protected] and we will delete it within 30 days. See section 9.
We intend to introduce automatic deletion of long-dormant accounts. When we do, this section will be updated with the periods, and we will not state them here before the deletion actually runs.
7. Who else sees your data
We use a small number of service providers. They process data on our instructions.
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare | Website hosting, database, file storage, DNS, email forwarding | Global network |
| Brevo | Sending transactional email and the newsletter | European Union |
Our source code is hosted on GitHub, but it contains no personal data.
We do not sell personal data, do not share it for advertising, and do not transfer it to anyone else except where required by law.
Where your data is processed
Our database runs on Cloudflare's global network and is not restricted to a particular jurisdiction: no regional limitation was set when it was created, and replication is disabled. Your data may therefore be processed outside the European Economic Area.
Where that happens, the transfer is covered by the standard contractual clauses in Cloudflare's data processing agreement, which we have accepted as their customer. We will not tell you that your data stays in the EU, because it may not.
Brevo, which sends our email, processes data in the European Union.
Once payments are enabled, purchases will be handled by Paddle.com Market Limited (and affiliated companies of the Paddle group) acting as merchant of record. They will process the data necessary for your purchase, including your billing details, which reach them directly and never pass through our systems. Their privacy policy is published at paddle.com/legal/privacy.
8. Emails we send
| Contains | |
|---|---|
| Email confirmation | A one-time link, valid 24 hours |
| Licence application approved | Your congregation's name, a download link, and your licence key in the body of the message |
| Licence application declined | Your congregation's name and the reason |
| Newsletter | Marketing content; unsubscribe link in every message |
We want to be explicit about the second one: your licence key is sent to you in plain text inside an email. Email is not a secure channel. Treat the message as you would a password, and delete it once you have stored the key somewhere safe.
9. Your rights
If you are in the EU, EEA or UK, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent where consent is the basis. Similar rights exist under other privacy laws, and we apply them to everyone regardless of where you live — it is simpler and fairer than sorting people by jurisdiction.
How to exercise them: write to [email protected]. We will respond within 30 days.
Being straightforward about the mechanics: there is no self-service delete button in the account interface. Requests are handled manually by a person. This is a small operation; a request by email reaches the same person either way.
You also have the right to complain to a supervisory authority in your country.
10. Cookies and local storage
One cookie:
| Name | Purpose | Properties | Duration |
|---|---|---|---|
dw_session | Keeps you signed in | HttpOnly, Secure, SameSite=Strict | 30 days |
It is set only after you sign in. It is strictly necessary for the account to work.
We also store your chosen interface language in your browser's local storage. It never leaves your browser and is not readable by other websites.
There are no advertising cookies, no analytics cookies and no third-party cookies. We do not display a cookie consent banner because we do not set anything that requires consent.
11. Children
DisplayWord is intended for use by congregations and organisations, and accounts are meant to be held by adults. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.
12. Security
Passwords are stored hashed. Traffic to the website is encrypted. Access to the administrative interface is restricted.
We will not claim more than that. This is a small operation without a dedicated security team, and you should weigh that when deciding what to entrust to any service, including this one.
If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify you directly.
13. Changes to this policy
We may update this policy. The current version, with its effective date, is always at displayword.com. Where a change materially affects you, we will give notice by email at least 30 days beforehand.