Privacy Policy

mockingpug · mock data and mock APIs for React and Next.js

Effective 27 September 2026

1. Introduction

This Privacy Policy explains what personal data mockingpug ("mockingpug", "we", "us") collects, why we collect it, who processes it on our behalf and what rights you have. It covers this website (mockingpug.com), the mockingpug cloud editor (app.mockingpug.com) and the cloud features of the mockingpug CLI (sign-in, pull and push).

The open-source mockingpug npm package itself runs in your own project and does not send us any data unless you connect it to the cloud with mockingpug login.

2. Who We Are

The data controller is [Imię Nazwisko], [business name from CEIDG], [street, postal code, city], Poland, NIP [0000000000]. For anything related to this Policy or your data, contact us at [email protected].

3. Information We Collect

3.1 Information you give us

  • Account data: email address, name and, if you sign in with GitHub or Google, your profile picture. If you sign up with a password, we store only a salted hash of it (scrypt), never the password itself.
  • Project content: the schemas, tables, endpoints, dictionaries, notes and canvas layout you create, and the versions you publish.
  • Collaboration data: email addresses of people you invite to a project, their access rights, and settings of the share links you create (including a hashed link password, if you set one).
  • CLI and CI data: sign-in codes of the CLI, access tokens (stored hashed), and the name, framework and identifier of each app that pulls or pushes a project.
  • Messages you send us.

3.2 Information collected automatically

  • Product events tied to your account: for example, that you created a project, added a table, published a version, shared a link or pulled a schema into an app. We use them to measure activation and improve the product.
  • Sign-up source: the campaign tags (UTM parameters) or referring page that brought you to mockingpug, stored with your account when you sign up.
  • Anonymous visit counts: when you open a link with campaign tags, we count the visit together with the tags and the page — without any identifier of you.
  • Technical data: your IP address and requests are processed to deliver the service and to protect it from abuse (rate limiting). IP addresses used for rate limiting are kept in memory only and are not stored.
  • Analytics (with your consent only): on the cloud editor, page views, clicks and session recordings with masked inputs through PostHog.

3.3 Information from third parties

If you sign in with GitHub or Google, we receive your name, email address, profile picture and confirmation that the email address is verified. We do not receive access to your repositories or other data.

4. How We Use Your Information

  • to create and run your account and projects, including real-time collaboration;
  • to deliver your schemas to your apps through the CLI;
  • to send transactional emails: email confirmation, password reset and security notices;
  • to see whether our emails arrive and work: our emails contain a small tracking image that reports when an email is opened, and their links pass through links.mockingpug.com, which records the click and forwards you to the page;
  • to understand which campaigns and pages bring new users, and how the product is used;
  • to prevent abuse, fraud and security incidents;
  • to comply with legal obligations.

We do not sell your personal data, do not use it for third-party advertising and do not send marketing emails without your consent.

6. How We Share Your Information

We share data only with service providers that process it on our behalf:

ProviderPurposeLocation
Hosting providerHosting of the website, cloud editor, API and databasePoland (EU)
ResendSending transactional emails, measuring email opens and link clicksUnited States
GitHub, GoogleSign-in, only if you choose itUnited States
PostHogProduct analytics on the cloud editor, only with your consentEuropean Union

We may also disclose data if required by law, to protect our rights and users, or as part of a merger or acquisition — in which case this Policy continues to apply.

7. Shared Links and Collaboration

When you share a project, anyone with the link (or with the link and its password, or the people you invited — depending on the setting you choose) can see the published schema and, if you allow it, example data. Project members see each other's names and email addresses, and see who is currently editing. You control these settings and can revoke a link or remove a member at any time.

8. Cookies and Similar Technologies

We use a small number of cookies and browser storage entries. Strictly necessary ones are always on; optional ones are used only after you allow them in the banner. You can change your choice at any time with Cookie settings at the bottom of the page.

NameWherePurposeType
authjs.* cookiesCloudKeep you signed in; protect sign-in forms (CSRF)Necessary
mp_share_* cookieCloudRemember that you entered the password of a protected share linkNecessary
mp-consent, mp-analytics-consentWebsite, cloudRemember your cookie choiceNecessary
mp_last_email (session storage)CloudPre-fill your email on the sign-in form; cleared when you close the tabNecessary
mp-attributionWebsite, cloudRemember the campaign or page that first brought you here (30 days), so we can attribute your sign-upOptional
PostHog cookiesCloudProduct analyticsOptional

Without your consent, campaign tags are only kept in memory while the page is open and are passed to the cloud editor in the link you click.

9. Data Retention

  • account and project data — while your account exists;
  • product events and sign-up source — while your account exists;
  • email confirmation links — 24 hours; password reset links — 1 hour;
  • CLI sign-in codes — 10 minutes; CLI tokens — until revoked or 90 days of inactivity;
  • anonymous visit counts — kept in aggregate, they do not identify you;
  • database backups — 14 days, after which deleted data is gone from them too.

10. Security

Traffic is encrypted with TLS. Passwords, link passwords and access tokens are stored only as hashes. Access to projects is checked on every request, sign-in and email endpoints are rate limited, and cross-site requests are blocked. No system is perfectly secure; if you find a vulnerability, please report it to [email protected].

11. Your Rights

Depending on where you live, you have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent at any time. To exercise these rights, including deleting your account, write to [email protected] from the email address of your account. We answer within 30 days.

If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority.

12. International Data Transfers

Your account and project data are stored on our server in Poland (EU). Some providers (Resend, GitHub, Google) process data in the United States. Where data is transferred outside the EEA or the UK, the transfer relies on the European Commission's adequacy decisions (including the EU–U.S. Data Privacy Framework) or Standard Contractual Clauses.

13. Children's Privacy

mockingpug is a tool for software developers and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

14. Changes to This Policy

We may update this Policy as the product changes. The effective date at the top shows the latest revision; for material changes we will notify you by email or in the cloud editor before they take effect.

15. Contact Us

[Imię Nazwisko], [business name from CEIDG], [street, postal code, city], Poland, NIP [0000000000]. Email: [email protected].