Exponential / About / Privacy Policy
Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your information.
Last updated: June 12, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Software, Website, or Service and tells You about Your privacy rights and how the law protects You. Exponential CMS is self-hosted software that runs entirely on Your own Hosting Environment and does not transmit any data about Your installation, your content, or your users back to the Developer. By using the Service, You agree to the handling of information in accordance with this Privacy Policy.
1. Interpretation and Definitions
1.1 Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
1.2 Definitions
For the purposes of this Privacy Policy:
- You means the individual accessing or using the Software, Website, or Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Software, Website, or Service, as applicable.
- Developer (referred to as either "the Developer", "We", "Us" or "Our" in this Agreement) refers to Exponential CMS's core developers and project maintainers.
- Software or CMS refers to Exponential CMS, a free, open-source web content management system built on the 7x platform (v6.0.14 and later).
- Website refers to the Exponential project website, accessible from https://exponential.earth
- Service refers to the Software and Website collectively.
- Country refers to the United States of America.
-
Extensions means software packages that enhance or
extend the functionality of the Software, installed under the
extension/directory. - Hosting Environment means any server, virtual machine, container, or cloud instance on which You deploy and run the Software. who processes the data on behalf of the Developer. It refers to third-party Service Providers or individuals who facilitate the Service, provide the Service on behalf of the Developer, perform services related to the Service, or assist the Developer in analyzing how the Service is used.
- Personal Data is any information that relates to an identified or identifiable individual.
- Non-Personal Data is any information that does not relate to an identified or identifiable individual.
- Usage Data refers to anonymised data collected by standard web analytics tools when You visit the Website (for example, page views, referral sources, and general geographic regions). This data is never collected from Your self-hosted installation of the Software.
2. Information We Collect
2.1 Your Self-Hosted Installation
Exponential CMS runs entirely on Your own Hosting Environment. The Software does not phone home, does not transmit telemetry, and does not send any data about Your installation, your content, your editors, or your end-users to the Developer or to any third-party service. What happens inside Your installation stays inside Your Hosting Environment.
2.2 Website Analytics
The Website may use standard web analytics tools to understand how visitors interact with the Website. This helps the Developer improve the Website experience and includes Non-Personal Data such as page views, referral sources, and general geographic regions. This is separate from the Software and applies only to Website usage.
2.3 Website Cookies
The Website uses cookies to provide and improve the user experience. We use two types of cookies:
- Essential Cookies: These are necessary for the Website to function properly and cannot be disabled. They enable basic functions like page navigation and access to secure areas of the Website.
- Analytics Cookies: These cookies help us understand how visitors interact with the Website by collecting and reporting information anonymously. They are used with Google Analytics to measure Website performance and user engagement. These cookies are only set with your explicit consent.
For analytics cookies, we use Google Analytics which is subject to Google's Privacy Policy. We have configured Google Analytics to anonymize IP addresses and use secure, strict cookie settings.
3. Third-Party Integrations
Exponential CMS can be connected to third-party services — such as search engines, payment gateways, social platforms, or external APIs — through Extensions or direct configuration. When You enable such integrations, data may be exchanged with those providers according to their own privacy policies. The Developer has no control over how third-party services handle data You send to them.
- Review the privacy policy of any third-party service before enabling its integration
- You are solely responsible for API keys and credentials You configure within Your installation
- The Developer is not liable for data handling practices of any third-party service You choose to connect
4. Extensions
Exponential CMS supports a modular extension architecture. Extensions may be developed by the core team, community contributors, or independent developers and are not always owned or controlled by the Developer. From a privacy perspective:
4.1 Extension Data Handling
Extensions operate independently and may have their own data collection, processing, and privacy practices. The Developer has no control over or visibility into:
- What data Extensions may collect from You or Your Hosting Environment
- How Extensions process or store Your information
- Whether Extensions transmit data to external servers
- Extension compliance with privacy laws and regulations
4.2 Developer's Responsibility Regarding Extensions
The Developer does not:
- Monitor or control Extension data collection practices
- Have access to data collected by Extensions
- Validate Extension privacy policies or practices
- Accept responsibility for Extension privacy violations
- Assist with Extension-related privacy questions where possible
4.3 Your Privacy Rights with Extensions
When using Extensions, You should:
- Review each Extension's documentation and privacy notes before installation
- Understand what permissions and data access Extensions require
- Reach out to the Developer or the community if You have privacy-related questions about any Extension
- Disable or remove an Extension if it does not meet Your privacy requirements
- Monitor Extension behavior and data usage on Your Hosting Environment
5. Self-Hosted Installation Privacy
Because Exponential CMS is self-hosted, You are the data controller for all personal data that flows through Your installation — including the data of your editors, members, and site visitors. The Developer has no access to that data. You are responsible for:
- Securing Your Hosting Environment and database
- Maintaining your own privacy policy for your website's end-users
- Complying with applicable data protection laws (such as GDPR, CCPA, or similar) as the data controller
- Configuring and auditing any Extensions or integrations that may collect or transmit data
6. Data Security
The security of Your data matters. Because the Software runs on Your own Hosting Environment:
- No personal data is collected or transmitted from Your installation to the Developer
- You control all access to Your database and file system
- The Developer recommends keeping Your server software, operating system, and Exponential CMS up to date to minimise security exposure
7. Data Retention
The Website retains Usage Data in accordance with the Developer's data management practices and the retention policies of any analytics tools in use. Since no data is collected from Your self-hosted installation, there is nothing for the Developer to retain on Your behalf. The Developer reviews and purges old data periodically in accordance with best practices.
8. Your Rights and Choices
Regarding data management and privacy choices, You have the following options:
- Self-Hosted Control: Because the Software runs on Your own Hosting Environment, You are the data controller for all data within Your installation and can manage, export, or delete it at any time
- Cookie Management: You can manage your cookie preferences for the Website through the cookie consent banner or by clearing your browser's cookies. Analytics cookies are only set with your explicit consent and can be declined at any time
- Extension Control: You can install, uninstall, or disable Extensions at any time through the Software's extension configuration
- Contact Developer: Contact the Developer if You have questions about the Software's data handling or would like to request information about the types of data collected
- Extension Support: The Developer supports all Extensions. If You have privacy questions or concerns about any Extension, contact the Developer and we will do our best to assist
9. Children's Privacy
The Software does not knowingly collect Personal Data from anyone, including children, as it runs entirely on Your own Hosting Environment. The Website does not target children. If You are a parent or guardian and have concerns about Your child's use of a site powered by Exponential CMS, please contact the operator of that site directly, as they are the data controller for their installation.
10. Changes to This Policy
The Developer may update this Privacy Policy from time to time. The Developer will notify users of any material changes on the Website. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
11. Contact Information
If You have any questions about this Privacy Policy or the Developer's privacy practices, please contact the Developer:
- Email: support@exponential.earth
- Discord: Join our Discord community
12. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction where the Software is developed and maintained.
For the most up-to-date version of this Privacy Policy, please visit the Website regularly.