Sandbox
Perfect for making test websites!
Pro Server
Pro Hosting + Autonomous, Deployed Backend.
Or Hire Me to Make it!
1-on-1 expert guidance, or full Dev work, for your rapid MVP.
People's Apps!
Click on an App or Website to see what people made!
Engine Failure
Click to copy verbose log
Connecting to Oracle...
Ai Site Completed
Perfect for making test websites!
Pro Hosting + Autonomous, Deployed Backend.
1-on-1 expert guidance, or full Dev work, for your rapid MVP.
Click on an App or Website to see what people made!
Effective date: June 4, 2026 Β· 20sec Inc Β· Delaware
This Privacy Policy explains what 20sec Inc ("we", "us", "20sec") collects about you when you use 20sec.app, the 20sec lead-finder, the AI site-generation features, and any blast-outreach tools we run on your behalf. We wrote it ourselves β no generic legal template β to make sure it actually reflects what the service does.
Account information. Your email address, login session token, language preference, and any payment customer ID Stripe gives us when you subscribe. We never see or store your credit card number β that lives at Stripe.
Site-generation inputs. The prompts and ideas you type into the homepage hero, any images you paste or upload, and the HTML files our AI returns. Generated sites are stored on our server tied to your account until you delete them.
Editor activity. When you use the admin / "edit-agentically" tools to modify a generated site, we keep version history (the previous and current HTML, plus a small log of the edit request) so revisions are reversible.
Lead data you collect. When you use the lead finder to scrape businesses from public sources (Google Places, HERE Maps, OpenStreetMap), the results are stored in your lead pool β business name, address, phone, email (if listed), website, social URLs. These are SMB contact details that are publicly listed on those sources; we organize them for you, we don't create them.
Outreach activity. When you fire a Gmail or WhatsApp blast through the platform, we log: which leads you sent to, the message variant you used, send status (queued / sent / bounced / complained), and the third-party message ID from Resend or Green API. We do not read the body of replies β replies route directly to whatever inbox you configured.
Server logs. Standard web logs (your IP address, user agent, request paths, timestamps) so we can debug outages and detect abuse. Retained 30 days then automatically pruned unless tied to an active investigation.
Browser storage. We use localStorage for session continuity (login token, lead-finder UI state, language preference, share-variation pool). We do not use third-party advertising cookies. We do not use Google Analytics, Facebook Pixel, or similar trackers.
To run the service: generate sites, store them, render the editor, queue + send your blasts, accept payment, send you account email. To provide support: when you email us, we look at the row(s) involved. To improve the product: aggregated, de-identified stats on which categories, geographies, and message variants perform best β never tied to a single visitor.
We do not sell, rent, or lease your data to anyone. We do not feed your prompts or generated content back into a public AI model's training set.
The service relies on the following processors. Each receives only the minimum data needed to do its job:
Account data: kept while your account is active. Generated sites and lead lists: kept until you delete them or close the account. Blast queue rows: kept 90 days after send completion for delivery auditability, then pruned. Server logs: 30 days. After account closure, we delete personal data within 30 days, except where we are legally required to keep records (e.g., payment receipts for tax purposes β retained per IRS requirements).
Access and correction. Email will@20sec.app and we'll send you an export of your data within 30 days.
Deletion. Same email β say "delete my account" and we'll wipe within 30 days. Note that blast recipients we've already sent to are kept anonymously in the unsubscribe suppression list so we don't accidentally re-contact them after deletion.
Unsubscribe. Every blast email we send carries a one-click unsubscribe link as required by CAN-SPAM. Unsubscribed addresses are added to a permanent suppression list across the entire 20sec system β once unsubscribed, always unsubscribed, even by other accounts.
GDPR (EU residents). You also have the rights to data portability and to object to processing. Same email, we'll respond within 30 days.
CCPA (California residents). You have the right to know what we collect, to deletion, and to opt out of "sale" of personal information. We don't sell personal information, so there's nothing to opt out of, but the rights to know and delete apply β use the email above.
The service is not directed at users under 13. We don't knowingly collect data from anyone under 13. If you believe a child has used the service, email us and we'll delete the account.
Our servers are in the United States. If you're using the service from outside the US, your data is processed in the US. By using the service you consent to that transfer.
HTTPS everywhere. Passwords are stored hashed (we never see your plaintext password). API keys for third-party services are stored server-side and never exposed to the browser. We use HMAC signing for any deploy-pipeline calls so requests can't be replayed. No system is 100% secure β if we ever experience a breach affecting your data, we will notify you within 72 hours of discovery.
If we materially change how we handle your data, we'll update the "Effective date" at the top and email account holders. Continued use after 30 days counts as acceptance of the new terms.
20sec Inc
c/o Harvard Business Services
16192 Coastal Highway
Lewes, DE 19958, USA
Email: will@20sec.app
Effective date: June 4, 2026 Β· 20sec Inc Β· Delaware C Corp
By using 20sec.app or any related service operated by 20sec Inc, you agree to these Terms. If you don't agree, stop using the service.
20sec provides an AI-assisted website and app generator, a lead-finder for local businesses, and a cold-outreach blast pipeline (email + WhatsApp). Tiers:
You must provide a working email when you create an account. You're responsible for everything that happens under your account, including content generated by your prompts. Keep your login secure. If you suspect unauthorized access, email us β we'll lock the account.
The most important rule: follow the law where your recipients live. You agree to:
We reserve the right to suspend or terminate accounts that violate these rules. Egregious abuse (especially spam to consumers) results in immediate termination without refund.
The site generator produces HTML based on the prompt you provide. We do not warrant that generated content is accurate, complete, fit for a particular purpose, or free of third-party rights infringement. You are responsible for reviewing what the AI returns before publishing, sending, or otherwise relying on it. If the AI hallucinates a stock URL or makes up a fact, that's a known limit of the technology β verify before you ship.
Pro Server is billed monthly in advance via Stripe. You can cancel anytime from the admin panel; cancellation stops the next billing cycle but does not refund the current one. We do not pro-rate partial months. Refunds for the current month are at our discretion and typically granted only when the service was materially unavailable for that month.
Business contact data shown in the lead finder comes from third-party public sources (Google Places, HERE Maps, OpenStreetMap). We do not warrant that any specific phone number, email, or address is accurate, current, or that the business consents to receiving outreach. You are responsible for honoring any "do not contact" requests you receive and for keeping your outreach within the law.
The 20sec brand, the platform code, the AI prompts and templates we built, and our infrastructure are our property. The HTML the AI generates for your site is yours to use commercially. You grant us a non-exclusive license to host, serve, and modify your generated sites for the purpose of running the service.
We aim for high uptime but make no SLA. The service is provided "as is" and "as available". Outages can happen; AI quotas can run out; third-party services we depend on (Stripe, Resend, Google) can fail. We are not liable for losses caused by such outages.
TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE.
TO THE FULLEST EXTENT PERMITTED BY LAW, OUR TOTAL LIABILITY FOR ANY CLAIMS ARISING OUT OF OR RELATED TO THE SERVICE IS LIMITED TO THE AMOUNT YOU PAID US IN THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR $100, WHICHEVER IS GREATER. WE ARE NOT LIABLE FOR INDIRECT, CONSEQUENTIAL, OR INCIDENTAL DAMAGES (LOST PROFITS, LOST DATA, LOST OPPORTUNITY) EVEN IF WE WERE ADVISED OF THE POSSIBILITY.
You agree to indemnify and hold 20sec Inc, its officers, employees, and agents harmless from any claims, damages, or expenses (including reasonable legal fees) arising out of your use of the service, your content, or your violation of these Terms or any law. This is especially relevant if a third party brings a complaint about outreach you sent through the platform.
You can stop using the service anytime. We can terminate accounts for material breach of these Terms (especially abuse of the blast features). Upon termination, your access ends, and we delete your data within 30 days as described in the Privacy Policy. Sections that should survive termination (intellectual property, disclaimers, limitation of liability, indemnification, governing law) will survive.
These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-law principles. Any dispute will be resolved by binding arbitration in Delaware under the rules of the American Arbitration Association, except that either party may seek injunctive relief in court for IP or confidentiality matters. You waive any right to a jury trial or to participate in a class action. If arbitration is held to be unenforceable, the exclusive forum is the state or federal courts of Delaware.
If we change these Terms materially, we'll update the "Effective date" and email account holders. Continued use after 30 days counts as acceptance.
These Terms plus the Privacy Policy constitute the entire agreement between you and 20sec Inc about the service. They supersede any prior agreements.
20sec Inc
c/o Harvard Business Services
16192 Coastal Highway
Lewes, DE 19958, USA
Email: will@20sec.app