Polityka prywatności
Data wejścia w życie: October 7, 2026
Ta strona jest dostępna wyłącznie w języku angielskim. Wiążąca jest wersja angielska.
Hands-On Watch ("we", "us", "our") runs https://www.handson.watch, a site for planning watch modding builds, finding compatible parts, and sharing builds with the community (the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
We keep this short and specific on purpose. If something here is unclear, email us and we will explain.
1. Information we collect
Information you give us:
- Account information. You sign in with Google. Google shares your name, email address, and profile photo with us. We create a public handle for you, which you can change.
- Profile information you choose to add, such as a handle, bio, location, website, and profile photo.
- Content you create, such as builds (including drafts and versions), components and links you add to them, collections, likes, saves and notes, follows, feedback on generated images, and questionnaire answers.
- Messages you send us through the contact form, including your name, email address, subject, and message.
Information collected automatically:
- Usage and device information, such as pages viewed, links and buttons clicked, referring page, approximate location derived from your IP address, browser and device type, and errors you run into. We collect this with PostHog analytics, which may also record session replays of how pages are used, with text you type into form fields masked.
- Performance measurements, such as page load times, collected with Vercel Speed Insights.
- Affiliate link clicks, including the build and product you clicked and, if you are signed in, your account.
Information stored on your device: we store your sign-in session and language preference in cookies, and we keep things like an unsaved build draft, questionnaire answers, and whether you have dismissed the builder tour in your browser's local storage. Analytics also uses cookies or local storage to recognize repeat visits.
2. How we use information
- To provide the Service: signing you in, saving and displaying your builds and profile, and showing your public content to others.
- To generate build visualizations, names, and part suggestions (see "Automated processing" below).
- To understand how the Service is used, fix bugs, and improve features.
- To track affiliate referrals so we can earn commissions that fund the Service.
- To respond to messages you send us.
- To prevent abuse, keep the Service secure, and comply with the law.
We do not sell your personal information, and we do not use it for targeted advertising.
3. What is public
Some information is visible to anyone, including people who are not signed in:
- Your public profile: handle, profile photo, bio, location, website, featured build, and the date you joined.
- Builds you publish, collections you make public, and questionnaire answers you choose to share with the community.
- Who you follow and who follows you.
Drafts, archived builds, and private collections are visible only to you and anyone you share them with. Anyone who has an edit link for one of your builds can edit that build until the link expires, so share edit links carefully. Your email address is not shown publicly.
4. Automated processing
To create build visualizations and suggestions, we send images and details of the parts in a build (for example, product photos, listing titles, and preview images from pages you link) to AI providers: fal.ai for image editing, and OpenRouter, which forwards requests to model providers such as Google. We do not send your profile photo, email address, or name to these providers. Generated images and suggestions can be inaccurate.
When you use Recreate, or search for a part by photo in the builder, we send the photo to fal.ai, which picks out the watch and its parts, and send images taken from the photo (the watch and each part, usually cut out onto a plain background) to AliExpress, which searches for listings that look like them. To suggest a movement for a watch in a photo, we also send the photo to OpenRouter, which forwards it to Google's Gemini model to read which functions the dial shows, such as a date window. We do not store the photo or the cut-out images: they are used for that search and then discarded. fal.ai, OpenRouter, Google and AliExpress handle what they receive under their own policies.
5. AI assistants
You can use parts of the Service from an AI assistant instead of the website, in two ways: through our remote Model Context Protocol (MCP) server at https://www.handson.watch/mcp, which assistants such as ChatGPT and Claude can connect to, and through WebMCP tools that an AI agent running in your own browser can use on our pages.
The MCP server needs no account and saves nothing to one. It finds published builds and parts, checks whether parts fit together, finds parts for the watch in a photo (Recreate), and makes links that open a build in our builder. When an assistant uses it, we receive:
- What the assistant sends to a tool, such as search words, filters, build and listing IDs, and a title for a build link. We receive only these tool inputs, along with the technical details any web request carries, not your conversation with the assistant or anything else in it.
- The IP address the request comes from. When the assistant runs on its provider's servers, as ChatGPT and Claude do, this is the provider's address, not yours.
- If you use ChatGPT, the anonymized user ID that OpenAI attaches to tool calls ("openai/subject"), which does not tell us who you are. ChatGPT may also send details such as your language or approximate location; we do not use or keep them. We don't receive an ID for you from Claude.
- For Recreate, the web address of the photo and the photo itself, which we download from that address.
How we use and keep it:
- We use the IP address and the ChatGPT ID only to apply rate limits, so that no one person, assistant, or address uses more than a fair share. For each of them we keep counters, stored under the IP address or ChatGPT ID, of how much of each limit is left and when it was last used. Each limit's window lasts a minute (most tool calls and part searches), an hour (fit checks and photo downloads), or a day (Recreate runs). The counters do not include tool inputs and are not linked to an account. We do not yet delete old counters automatically.
- Photos for Recreate are handled as described in "Automated processing" above and are never stored: not the photo, its web address, or anything cut out of it. Each Recreate run is kept as a job under a random ID, with its result (the listings it found), so the assistant can fetch the result if it takes a while. The job is deleted one hour after it starts.
- Part searches and fit checks are cached with their results for up to about 15 days, so the same question is answered faster, and listings we look up are added to our catalogue of parts. Neither records who asked.
- We count each tool call in our analytics (PostHog) as an "agent_tool_called" event, with the tool's name, whether it worked, and how it was reached ("remote-mcp" for the MCP server, "webmcp" for WebMCP). For the MCP server, these events contain no IP address, ID, or tool inputs, and are not linked to a person.
- Our hosting providers, Vercel and Convex, keep request and error logs, which can include the IP address a request came from, for a limited time under their own retention settings.
Others involved: part searches and listing details come from AliExpress's APIs, which receive the search words and listing IDs but not the IP address or ID of whoever asked. Fit checks and listing lookups send listing details to OpenRouter, which forwards them to model providers. Recreate sends the photo to fal.ai, and images taken from it to AliExpress, as described in "Automated processing." Results go back to the assistant you are using, and its provider (for example, OpenAI for ChatGPT or Anthropic for Claude) handles them, and your conversation, under its own privacy policy.
WebMCP tools work only in your browser, on our pages, while you have them open. They act with your session, just as if you had clicked yourself, so what they do is collected and used as described in the rest of this policy, and each call is counted in analytics like your other activity. You choose the agent that uses them, and its provider handles what the agent sees under its own policy.
7. Affiliate links and third-party sites
Many part links on the Service are affiliate links. If you buy something after following one, we may earn a commission at no extra cost to you. When you leave our site, the other site (such as AliExpress) collects information under its own privacy policy and may set its own cookies to attribute the referral. We do not sell products, process payments, or receive your payment details.
8. How long we keep information
We keep your account and content for as long as your account exists. If you delete a build, we delete it from our active database. Contact form messages are kept as long as needed to handle your request. What we keep when an AI assistant uses the Service, and for how long, is described in "AI assistants" above. Analytics data is kept according to our analytics provider's retention settings. We may keep limited information longer when the law requires it or to resolve disputes.
9. Your choices and rights
- You can edit your profile and delete your builds at any time from the Service.
- You can ask us to access, correct, export, or delete your personal information, or to delete your account, by emailing privacy@handson.watch. We will respond within 30 days and may need to verify that the request comes from you.
- You can block or clear cookies and local storage in your browser. Some features, such as staying signed in, will not work without them.
- Depending on where you live, you may have additional rights, such as the right to object to or restrict certain processing, to withdraw consent, or to complain to your local data protection authority. We will honor these rights as required by applicable law.
10. Security
We use reputable hosting providers, encrypt traffic with HTTPS, and limit access to personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. International users
We are based in the United States, and our service providers may process information in the United States and other countries. By using the Service, you understand that your information will be transferred to and processed in these countries, whose data protection laws may differ from those where you live.
12. Children
The Service is not directed to children under 13 (or under 16 in the European Economic Area and the United Kingdom), and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do, we will change the date at the top of this page, and for significant changes we will provide a more prominent notice. Continuing to use the Service after a change takes effect means you accept the updated policy.
14. Contact us
Questions or requests about this policy or your information: privacy@handson.watch.