Privacy Policy
This policy explains what personal data DisplayWord collects, why, who else sees it, and what you can do about it. It covers both the website displayword.com and the DisplayWord software.
We have tried to write it as a description of what actually happens rather than as a list of everything we might one day do.
1. Who is responsible
The data controller is David Willart, an individual entrepreneur registered in Israel (osek patur), trading as DisplayWord.
Contact for any privacy question or request: hello@displayword.com
We have not appointed a Data Protection Officer; the law does not require one for an operation of this size.
2. The short version
- You can use the Software without giving us anything at all. No account, no registration and no payment card is needed — including for the 60 days of full access to a paid edition. If you never subscribe, we never learn who you are.
- When you do create an account, we collect very little: an email address, a password and your name. Everything else in your profile is optional, and an account with those fields left empty works exactly like any other.
- There is no analytics on this website. No Google Analytics, no tracking pixels, no advertising cookies, no third-party trackers of any kind.
- One cookie, strictly technical, set only after you sign in.
- The Software does not phone home. It contacts us to activate a licence and to check for updates. That is all.
- Your songbooks, service plans and settings never leave your computer. We cannot see them.
- We do not sell personal data. We do not share it for advertising. There is no advertising.
3. What we collect on the website
3.1 Creating an account
Three things: your email address, a password and your name. The name is simply what we use to address you; it does not have to be your legal name. Nothing else is required — no telephone number, no organisation.
Your password is stored as a cryptographic hash. It is not stored in readable form anywhere and cannot be recovered by us. If you forget it, you can set a new one through a one-time link sent to your email address.
We also generate an internal identifier and record the date the account was created.
3.2 Your profile
Inside your account you may add the following details about yourself and your congregation. Every field here is optional.
| Field | Why we offer it |
|---|---|
| Name of your congregation or organisation | Attaching licence keys to it, and helping you when you write to support |
| City | Support, and understanding where the Software is used |
| Country — two-letter code, ISO 3166-1 alpha-2 | Tax and currency handling when you buy a subscription |
| Your role in the congregation, chosen from a list | Understanding who actually uses the Software |
| Your role in your own words — up to 60 characters, offered only if you chose "Other" | The same; it is cleared together with the role |
| "Setup and training" — who helped you set up the Software and learn it: up to three people from a short list of those who work with us, or "Nobody, we found it ourselves" | Knowing which of our people assisted your congregation, so that we can account for their work |
We also record the date the profile was last changed, as an internal audit record.
You can change or clear any of these fields yourself at any time in your account, with one exception. The "Setup and training" field is set once: you may choose it at registration or within 30 days afterwards, and after that it can be changed only by us, on request. We store the identifiers of the people chosen and the date the choice was made. The people on that list are members of our team, not other users; nothing about them is shown to you beyond a name. Any later change is written to an internal audit log.
All profile fields are kept for as long as the account exists, and deleting the account removes them — see section 9.
3.3 Licence key applications — discontinued on 19 August 2026
Until 19 August 2026 the website had a form for requesting a licence key. It asked for the name of your congregation or organisation, your city and country, a two-letter country code, and the edition requested; optionally, contact details, an approximate number of members and a free-text message.
That form has been removed and we no longer collect any of this. It became pointless: the Church edition is free and needs no key, the paid editions run for 60 days without one, and paid keys are issued automatically after purchase.
Applications submitted before 19 August 2026 remain in our database, together with the decision taken on them, and are kept for as long as the account exists. You can have them deleted at any time by asking — see section 9.
3.4 Newsletter
If you subscribe, we store your email address and nothing else.
3.5 Download statistics
When you download an installer from the download page, we record the name of the file, the date and time, the two-letter country code and an approximate city. The country and city are derived from your connection by our hosting provider at the moment of the request; the IP address itself is neither read nor stored by us. These records are not linked to any account or to any other data about you, and they are seen only by the administrator. Their purpose is to know how many copies are downloaded and roughly where. Automatic updates of an installed copy are not counted.
3.6 What we do not collect
- We do not store your IP address. What is stored instead is the two-letter country code of your connection — country only, not city, not address. The single exception is the approximate city recorded for installer downloads, described in 3.5.
- We do not record your browser's user agent.
- We do not use analytics, counters, pixels or advertising tools of any kind. This was verified across the whole site.
One narrow exception, for honesty: when an administrator performs an action on a licence key — issuing it, resending it, revoking it — we record that action, who did it, and the administrator's IP address, in an internal audit log. This concerns our own staff actions, not visitors.
3.7 Error logs
When something fails — an email does not go out, a third-party service returns an error — a technical message is written to our hosting provider's system log. We deliberately do not print email addresses into these messages. The text of a third-party error response may occasionally contain one. Retention of these logs is governed by the hosting provider's own policy.
4. What the Software collects
4.1 Activation
When you activate a licence key, the Software sends us the key and an installation fingerprint.
We want to be precise about what the fingerprint is, because vague wording here is how privacy policies become untrue.
The fingerprint is produced by taking three values from your computer — the computer name, the Windows user name, and the hardware address of the first active network adapter — combining them, applying a SHA-256 hash, and keeping the first half of the result.
What this means in practice:
- The original values cannot be recovered from the fingerprint. The hash is one-way and is additionally truncated. Your computer name, user name and hardware address are never transmitted or stored by us in readable form.
- We do not treat the fingerprint as anonymous data. It is stable and its purpose is precisely to tell one installation from another. Under the GDPR this is pseudonymised personal data, not anonymous data, and we treat it accordingly.
Its only purpose is to enforce the number of installations a key permits.
We also record the two-letter country code of the activation request.
4.2 Updates
The Software periodically asks our release server whether a newer version exists. This is a request for a file. No information about your computer, your installation or your usage is attached.
4.3 What stays on your device
Your songbooks, service plans, settings, backgrounds and any media you add are stored locally on your computer. They are never uploaded to us. We cannot read them, and we cannot recover them for you.
4.4 No usage tracking
The Software contains no analytics, no usage statistics and no crash reporting. We do not know which features you use or how often you run it.
5. Why we are allowed to process this (legal bases)
For readers in the EU, EEA and UK, the GDPR requires us to state a legal basis for each purpose.
| What | Purpose | Legal basis |
|---|---|---|
| Email, password and name | Operating your account | Performance of a contract (Art. 6(1)(b)) |
| Optional profile fields — congregation, city, country, role, role in your own words | Attaching keys, supporting you, and applying the right tax and currency at checkout | Performance of a contract for the country code at purchase; consent for the rest, since you choose whether to fill them in and can clear them at any time |
| "Setup and training" field and the date it was set | Accounting for the work of the people who assist congregations | Legitimate interests (Art. 6(1)(f)) — the field is optional, and its default is "Nobody" |
| Download statistics — file, time, country, approximate city | Knowing how many copies are downloaded and where | Legitimate interests — no account is involved and no IP address is kept |
| Licence application details, collected before 19 August 2026 | Assessing and issuing your key at the time | Performance of a contract, and steps taken at your request before entering one |
| Installation fingerprint | Enforcing the installation limit of your licence | Legitimate interests (Art. 6(1)(f)) — protecting the licensed product against unlimited copying, using the least identifying method we could design |
| Country code | Statistical understanding of where the Software is used; fraud prevention | Legitimate interests |
| Administrator audit log | Accountability for actions on licence keys | Legitimate interests |
| Newsletter | Sending you the newsletter | Consent (Art. 6(1)(a)) — withdrawable at any time |
6. How long we keep it
We keep personal data only as long as it serves the purpose it was collected for.
We will describe what actually happens rather than what sounds reassuring.
| Data | Retained |
|---|---|
| Account and profile fields | for as long as the account exists; you can clear any optional field yourself at any time, except the "Setup and training" field after its 30-day window (see 3.2) |
| Download records | 12 months. After that they are reduced to monthly totals (file, country, month, number of downloads); the individual rows, including the approximate city and the exact time, are deleted |
| Any licence application submitted before 19 August 2026 | for as long as the account exists |
| Licence keys and activation records | for as long as the key exists, so that the installation limit can be enforced |
| Administrator audit log | for as long as the account exists |
| Newsletter address | until you unsubscribe |
| Sign-in session | 30 days, then it expires automatically |
| Email confirmation token | 24 hours, then it expires automatically |
We do not currently delete accounts automatically after a period of inactivity. Sessions and confirmation tokens expire on their own; everything else stays until you ask us to remove it.
You can have your data deleted at any time by asking — write to hello@displayword.com and we will delete it within 30 days. See section 9.
We intend to introduce automatic deletion of long-dormant accounts. When we do, this section will be updated with the periods, and we will not state them here before the deletion actually runs.
7. Who else sees your data
We use a small number of service providers. They process data on our instructions.
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare | Website hosting, database, file storage, DNS, email forwarding | Global network |
| Brevo | Sending transactional email and the newsletter | European Union |
Our source code is hosted on GitHub, but it contains no personal data.
We do not sell personal data, do not share it for advertising, and do not transfer it to anyone else except where required by law.
Where your data is processed
Our database runs on Cloudflare's global network and is not restricted to a particular jurisdiction: no regional limitation was set when it was created, and replication is disabled. Your data may therefore be processed outside the European Economic Area.
Where that happens, the transfer is covered by the standard contractual clauses in Cloudflare's data processing agreement, which we have accepted as their customer. We will not tell you that your data stays in the EU, because it may not.
Brevo, which sends our email, processes data in the European Union.
Once payments are enabled, purchases will be handled by Paddle.com Market Limited (and affiliated companies of the Paddle group) acting as merchant of record. They will process the data necessary for your purchase, including your billing details, which reach them directly and never pass through our systems. Their privacy policy is published at paddle.com/legal/privacy.
8. Emails we send
| Contains | |
|---|---|
| Email confirmation | A one-time link, valid 24 hours |
| Password reset | A one-time link, sent only when you ask for it |
| Licence key issued | A download link and your licence key in the body of the message |
| Newsletter | Marketing content; unsubscribe link in every message |
We want to be explicit about the second one: your licence key is sent to you in plain text inside an email. Email is not a secure channel. Treat the message as you would a password, and delete it once you have stored the key somewhere safe.
9. Your rights
If you are in the EU, EEA or UK, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent where consent is the basis. Similar rights exist under other privacy laws, and we apply them to everyone regardless of where you live — it is simpler and fairer than sorting people by jurisdiction.
How to exercise them: write to hello@displayword.com. We will respond within 30 days.
Being straightforward about the mechanics: you can edit or clear the optional fields of your profile yourself (the "Setup and training" field only within 30 days of registration), but there is no self-service button that deletes the account itself. Requests are handled manually by a person. This is a small operation; a request by email reaches the same person either way.
You also have the right to complain to a supervisory authority in your country.
10. Cookies and local storage
One cookie:
| Name | Purpose | Properties | Duration |
|---|---|---|---|
dw_session | Keeps you signed in | HttpOnly, Secure, SameSite=Strict | 30 days |
It is set only after you sign in. It is strictly necessary for the account to work.
We also store your chosen interface language in your browser's local storage. It never leaves your browser and is not readable by other websites.
There are no advertising cookies, no analytics cookies and no third-party cookies. We do not display a cookie consent banner because we do not set anything that requires consent.
11. Children
DisplayWord is intended for use by congregations and organisations, and accounts are meant to be held by adults. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.
12. Security
Passwords are stored hashed. Traffic to the website is encrypted. Access to the administrative interface is restricted.
We will not claim more than that. This is a small operation without a dedicated security team, and you should weigh that when deciding what to entrust to any service, including this one.
If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify you directly.
13. Changes to this policy
We may update this policy. The current version, with its effective date, is always at displayword.com. Where a change materially affects you, we will give notice by email at least 30 days beforehand.
14. Contact
hello@displayword.com