Skip to content
Hazelsong

Read and decide

Permission that actually stops things

Your customer checks off where you may use their words: website, social media, advertising. Two of those answers are not a note in a field — the website and the social media answers decide what this product will serve, on every request, forever. Advertising has no channel here to decide anything about, so that answer is recorded, exported and handed to you.

PlanEvery plan.

How it works

Permission, step by step

  1. They choose the places, one by one

    Website, social media, advertising — separately, because somebody happy to appear on your site may not want to be in a paid ad.

  2. The sentence and the date are kept

    The exact words they agreed to, with the timestamp, stored beside the testimonial and included in your export.

  3. Every channel here asks before it serves

    A testimonial that did not consent to the website cannot be served by a widget, a hosted wall, or the API, however many times it has been approved. A testimonial that did not consent to social cannot be made into an image or a clip. Hazelsong runs no advertising channel, so there is nothing here for that third answer to stop — you have it, and it is yours to honor.

Your collection page · Permission

Where may they show it?

I give Your Business permission to publish this testimonial — including my name, role, company and photo, as written here. They may not reword it.

on their websiteon their social mediain their ads and printed material

The sentence they check off is stored with the date. A place they have not checked off is a place where it cannot appear — the widget, the wall and the API all check.

Send testimonial
Drawn from the product's own markup and labels, with example words — not a real customer.

Safe by design

The rule that makes it safe to have

Clear boundaries

What it will not do

Every capability page ends with this list. It is the part that says what you are actually buying.

  • It will not let an approval override a refusal.
  • It will not put an author's email address in any public answer, ever.
  • It will not treat silence as permission.
  • It will not enforce the advertising answer for you. There is no ad served from here to withhold, so that answer is stored, shown to you and included in your export — and honoring it in your own ads and printed material is your job, not ours.

Where it lives in the code: lib/consent.ts · app/api/v1/testimonials/route.ts

Questions

Asked about this

From Help, where every answer is written from the product as it runs.

Where is the consent kept?

Beside the testimonial: the exact sentence your customer agreed to, the scopes they checked off, and the date. All of it comes out in your CSV export, which is the form you would want it in if anybody ever asked you to show it.

Which of the three permissions does Hazelsong actually enforce?

Two of the three, and the difference is worth knowing before you rely on it. Your website and your social media are places Hazelsong itself publishes, so those answers are enforced on every request: a testimonial that did not allow your website is not served by a widget, a wall or the API, on any plan, however many times it is approved, and the same goes for a social image or a clip. Advertising is not a channel Hazelsong has — ads and printed material are made by you — so that answer is recorded and handed to you rather than enforced. The collection form tells your customer exactly that, in those words, before they check anything.

They checked off website but not ads. What happens if I use it in an ad?

Nothing here stops you, because nothing here places ads. What the product does is keep the answer where you can find it: the consent sentence on the card names only the places that person allowed, and your CSV export lists what they checked off — which is the form you would want it in if they, or anybody else, ever asked what they had agreed to. The decision, and the responsibility for it, are yours. If you want a permission that holds on its own without you having to remember it, that is the website and social media permissions.

Does the API respect the website permission too?

Yes, and that is on purpose: an integration reading your testimonials is a publishing pipe. /api/v1/testimonials filters on website permission and says in its own answer that it did.

More on permission

This is running now

Open a project and use it. Nothing on this page is a roadmap.