Skip to content
Hazelsong

Legal · Last updated October 2026

Privacy Policy

This policy explains what Hazelsong stores and why, for both project owners and the people who submit testimonials through a Hazelsong collection form.

Hazelsong was called Kudobox until October 5, 2026. Nothing about what is stored, where, or who can see it changed with the name, and the earlier address, getkudobox.com, belongs to the same service.

Project owners

We store the email address, project name and website you provide when creating a project, and your subscription status if you upgrade. Billing details (card, address) are collected and processed directly by Paddle.com, our merchant of record — Hazelsong never sees or stores your card number.

When you subscribe, Paddle is told one thing about the project the subscription is for: its public address — the same one your collection form and your wall already answer on. That is what comes back to us when the payment completes, and it is how the plan reaches the right project. Your dashboard link is not part of it. That link is the whole of logging in, and a payment record kept by another company is no place for it.

When we look at your account

There is no password. You log in with a one-time link sent to your address, and your dashboard's own link works as a bookmark until you replace it. That means two things, and both are said here rather than left to be discovered. If you lose access to that address, we can still help you: write us and we will check that the project is yours. And because we can do that, we can also open your dashboard ourselves. We do it to answer a request you made, to investigate a fault you reported, or where the law requires it — not otherwise, and never to read your testimonials for our own purposes. Nobody outside Hazelsong is given that access, and deleting your project removes the link along with everything else.

Deleting everything

There is a button in your dashboard that removes the project and everything in it: every testimonial, every video and photograph your customers recorded, the forms, the walls, the keys, the seats and the address it answered on. The recordings are deleted from storage, not hidden. It cannot be undone, by you or by us, and it does not cancel your subscription — that is held by Paddle, and you cancel it from the link on any receipt.

Testimonial submitters

When someone submits a testimonial, we store what they gave the form, on behalf of the project owner who collected it: their name, and their role and company where they filled them in; their email address, where the form asked for it; the words themselves; an optional star rating; a photograph of themselves, a picture attached to the testimonial, and a video — either a recording or a file they uploaded, held in our storage, or a link to a video on another platform. We also store the exact permission sentence they agreed to, which places they allowed it to be shown, and the date and time they agreed; the answers to any extra questions the owner's form asked; and, where the owner's plan includes them, a transcript of the recording and translations of the text, both kept alongside the original rather than replacing it. The project owner controls whether a submitted testimonial is approved and shown publicly, and is responsible for having the submitter's consent to publish it. If you submitted a testimonial and want it removed, contact the business you gave it to, or reach us directly and we will forward the request.

Visitors to this site

The home page asks one question — where your testimonials live today. Answering it adds one to a counter for that answer: no name, no cookie, and no way to tell one answer from another. One thing is done with your network address, and it is said here rather than left out: so that a script cannot drive those counters, the answer is counted against a one-way hash of it, which holds nothing readable and is dropped after an hour. A count of that kind — a one-way hash, a short window, a number — is also what stops a flood of sign-ups, of testimonials through a collection form, and of requests for a login link. Nothing else about you is kept in any of them. Not answering costs you nothing.

That counter is not the only thing counted here. Every page served by this application loads Vercel Web Analytics, which counts page views — including the pages a project owner's own address answers on, such as a hosted wall, or a collection form at a subdomain or a domain of their own. What it records for each view is the page, the address you arrived from, an approximate location worked out from your network address, and the kind of device, browser and operating system you are using. It sets no cookie, reads nothing that was already in your browser, and does not follow you to other sites: Vercel tells one visit from another by deriving a value from the request itself, and changes the way it does so each day, so today's visit cannot be joined to yesterday's. Nothing you type into a collection form — the words, the name, the rating, the permission — is part of it. We see the counts, never the visitors.

A project owner's dashboard address is never sent to that counter. It has to be said plainly, because that address is not merely private: it is the whole of logging in, there is no password, and anyone holding it can open the project. So the pages whose address carries a key of that kind, or names one person, are dropped before anything leaves the browser. There are seven of them, and this is all seven: a dashboard and every tab of it; a login link being completed; the checkout page; the page that receives whatever you selected on another site with the Save to Hazelsong bookmark; a collection form at our own address, the /r/… link an owner sends out — every view of it, and not only one opened from an invitation, because an invitation's address names the person it was sent to; one of an owner's own named forms, at its own /f/… address; and the page a thank-you recording plays on. Not the address with the key taken out of it: the whole view, counted nowhere. Those same seven are also the pages whose address is withheld from other sites, by the referrer policy they are served with. What that costs is real and small — those pages do not appear in our figures at all — and it is the right way round.

What happens to a testimonial, and where it goes

We don't sell personal data, we don't train anything on testimonial content, and we don't use it to market Hazelsong. It is not, however, only stored and displayed: it is sent to the services below to be read, transcribed or translated, and that is set out here rather than left to be discovered.

Testimonials — whether they arrive through a form or are imported — are sent to Anthropic and read for risk before the owner decides what to do with them: a promised result, a named third party, a regulated claim, a private detail. Two cases are not sent at all, and are named here rather than left to be assumed: a testimonial that arrives after the day's allowance of readings for that project is used up, and one that arrives while no reading service is configured. Those are stored unread and the dashboard says so; nothing about them goes to Anthropic. A reading that is attempted and then fails is not one of those two cases: the text had already been sent. The same service is used, at the owner's request, to propose which span to remove, to draft a short pull quote, to write the reports and case studies drawn from testimonials already collected, and to translate a testimonial while keeping the original. Audio and video sent for transcription go to whichever speech service is configured — Deepgram, OpenAI's Whisper, or Google — and the name of the one that produced a transcript is stored with it. Each of these is sent only what the task needs, and only to perform it for you.

The companies that hold or process this data for us:

  • Vercel — hosting, the storage that holds videos and photographs, and the page-view counting described under “Visitors to this site.”
  • Upstash — the database everything else is written to.
  • Anthropic — reading for risk, proposing a removal, drafting pull quotes, writing reports and case studies, and translating testimonials.
  • Deepgram, OpenAI and Google — transcription of audio and video, whichever of them is configured.
  • Resend — sending the product's email.
  • Paddle — taking payment, as merchant of record.

Data location and retention

Text, ratings, permissions, transcripts and translations are stored in a managed Redis database; videos and photographs are stored as files in Vercel Blob. Both are retained for as long as the project exists. Deleting a testimonial from the dashboard removes it from the database and deletes its files from storage, immediately and permanently; if storage refuses at that moment the record still goes, and a daily sweep deletes any file no testimonial points at anymore. Deleting the project does the same for everything it holds.

Your rights

If you are located in the EU/EEA, UK or a jurisdiction with similar data protection law, you may request access to, correction of, or deletion of your personal data by writing to support@hazelsong.com.