Privacy Policy
What I process, why, and your rights — spoiler: I collect almost nothing.
Last updated ·
This policy explains what personal data uxspot.io processes, why, and what your rights are. The short version: uxspot.io is a free learning site with no accounts, no tracking and no ad networks. For readers, I collect as close to nothing as a website can. The one place I do process real personal data is the sponsorship checkout — because a contract and a payment need it — and that is described honestly below, alongside the little the site's infrastructure sees for everyone else.
Who is responsible
uxspot.io is an independent project, written, built and maintained by Soufiane Chraibi, a product designer, from Morocco. I am the data controller for the site: the person responsible for your data. For anything in this policy, write to me at hello@uxspot.io.
What is stored on your device
A handful of small preferences, all of which stay in your browser and are never sent to me: your checklist progress, your reading preferences (theme, text size, reading font, line spacing, reading width, reduce motion), your Spot Check practice streak, your place in the curriculum (so the homepage can offer "continue reading"), and whether you have seen the "new" badge. Alongside them, your browser keeps an offline copy of pages you have already opened — and, if you ask for it, of the whole Learn UX curriculum — so the site works without a connection; it is a copy of the site's own public pages and holds nothing about you. All of this is described in detail in the Cookie Policy. The site sets no cookies at all.
What the site's infrastructure sees
- Hosting (Cloudflare). The site is served by Cloudflare, which — like any host — processes visitor IP addresses in transient server logs to deliver pages and protect against abuse. Cloudflare acts as my processor; I do not use these logs to identify visitors.
- Analytics. I use privacy-friendly, cookieless analytics to see, in aggregate, which pages are read and roughly how many people visit. No cookies, no fingerprinting, no cross-site tracking, no profile of you.
- The Figma plugin. If you install the uxspot Figma plugin, it does not talk to me at all. Its manifest declares no network access, so Figma itself blocks every outbound request — your designs, and anything the plugin reads from them, never leave Figma. The only thing it stores is your chosen mode (Hybrid or On ask), kept on your device through Figma's plugin storage. Installing it through Figma Community means Figma processes that install (and any usage statistics) under Figma's privacy policy; I see aggregate install counts, never you.
- The MCP endpoint. If you connect your AI assistant to the uxspot MCP server (uxspot.io/mcp), your client sends requests to the site's infrastructure — technically an IP address and the query your assistant makes (for example, a glossary term to look up). The server returns the answer and does not build any record tied to you. It is read-only and requires no key or account.
Third parties your browser talks to
The site header shows a live GitHub star counter for the open-source uxspot MCP server. To fetch that number, your browser contacts api.github.com directly, which means GitHub sees your IP address the same way it would if you visited any GitHub page. GitHub's own privacy statement applies to that request. One more exists in a single place: the payment step of the sponsorship checkout loads PayPal's payment buttons from paypal.com, under PayPal's privacy statement — that script never loads anywhere else on the site. Beyond those two, fonts, search and images are all self-hosted. (The Figma plugin, described above, runs inside Figma and makes no requests to anyone.)
Sponsorship bookings
If you book a sponsorship at /sponsor/book, I process what a business deal needs and nothing more: the company name, contact name and work email you enter, your credit line and logo, the placement and dates you choose, and payment metadata (the amount, and PayPal's order and transaction identifiers). I store this in the site's database (hosted by Cloudflare, acting as my processor) to operate the placement, issue the insertion order and invoice, review the assets, and meet bookkeeping obligations — and I keep it for as long as those purposes require. The payment itself happens entirely on PayPal's side under PayPal's privacy statement; I never see card numbers or account credentials. Booking triggers transactional emails (confirmation, invoice, asset review) sent to the address you gave and to me — they are the record of the contract, not marketing, and you are never added to any list. While you fill in the booking, a draft (including the uploaded logo) is saved in your own browser's local storage so an interruption costs nothing; it expires after seven days or on payment and is only transmitted to me when you actually submit.
If you accept the insertion order at the fourth step, the booking as it stands at that moment is saved to the site's database, whether or not you go on to pay. Accepting the order is the point at which a form being filled in becomes a booking submitted, and it is a deliberate act on your part — up to that tick, everything you have typed is only in your own browser. If you press the payment button but never complete the payment, that record stays as an unpaid one. Because those dates are not held for you and the placement is exclusive, I may send you at most two emails about it — one the day after, one a few days later — each carrying a link that reopens your own booking and a one-click link to stop them. There is no sequence beyond those two and no list to be added to. Any logo attached to an unpaid booking is deleted after thirty days. I rely on my legitimate interest in completing a transaction you started, and you can object at any time using the link in the email or by writing to hello@uxspot.io. Nothing you type before you accept the insertion order ever reaches me.
If you write to me at hello@uxspot.io, I receive your email address and whatever you choose to tell me. I use it only to reply, keep it only as long as the conversation is relevant, and never add you to any list.
What I do not do
No ad networks, no selling or sharing of data, no accounts, no newsletters, no tracking pixels, no cross-site anything. The only commercial content on the site is a single, clearly labeled sponsor placement, sold directly under the sponsorship policy — it carries no tracking, and sponsors get no data about you (there is none to give). If I ever add a feature that changes this, this policy will change first — with the "last updated" date to show it.
Your rights
Depending on where you live (for example under the GDPR or similar laws), you have rights of access, rectification, erasure, restriction, portability and objection over personal data concerning you. In practice, for readers I hold almost nothing: your checklist progress and preferences live only in your own browser (clear them from your browser settings at any time), and beyond that I could only ever hold an email conversation you started with me. If you booked a sponsorship, I additionally hold the order data described above; you can ask me to correct or delete it, subject to what bookkeeping law requires me to keep. To exercise any right, or to complain, email hello@uxspot.io; you also have the right to lodge a complaint with your local data-protection authority.
Changes to this policy
I may update this policy as the site evolves. When I do, I will revise the "last updated" date shown alongside this page.