StyleDUI

Legal

Privacy Policy

Last updated:

This policy explains what personal data StyleDUI handles, why, who helps us handle it, and what you can do about it. We try to collect very little: exploring designs needs no account, and we do not store anonymous prompts.

1. Who is responsible

The data controller (under the GDPR) and data fiduciary (under India's Digital Personal Data Protection Act, 2023) is the individual developer who runs StyleDUI:

[Data controller legal name — to be confirmed before launch]

Contact for anything about your data: contact@styledui.com. That address is also where you send requests and complaints.

2. What we collect

DataWhat exactlyWhen
AccountEmail address, name and profile picture URL (from GitHub if you sign in with it), whether the email is verified, and the sign-in method. For GitHub sign-in, the OAuth tokens GitHub issues for our app are kept in our database.When you sign in
SessionsA session token (kept in a cookie), its expiry, the IP address and browser user-agent seen at sign-in, kept with the session. One-time email sign-in tokens are stored until they expire (15 minutes).While you are signed in
Projects and versionsProject names, and each saved version of a design (its layout, style settings, content, and an optional note).When you save a project
BriefsThe text of your brief and how we read it, for signed-in users only, as your history. Briefs from visitors who are not signed in are not stored.When a signed-in user explores
Share linksA random link name, which saved version it points to, when it was created or revoked, and reports made about it (a reason you type, no reporter identity).When you share or report
Run metadataFor a brief we ran: whether it used AI or our built-in engine, the model name, response time, estimated cost, and any fallback reason. It contains no prompts; it is linked to your stored brief only if you are signed in.On every brief
API keysA name you choose, the first 8 characters for display, and a one-way SHA-256 hash of the key. The key itself is shown to you once and not stored.When you create a key
Rate-limit countersFor visitors who are not signed in: a salted one-way hash of the IP address, with request counts per minute and per day. For signed-in users: the counter is tied to the account id. We do not store the raw IP address in these counters.On every explore, export or save request
Subscription and export recordsPayment provider customer and subscription ids, plan, billing interval, status, period end, whether it cancels at period end, and whether it is a founding-member price. Also a record per code or token export (type and time), kept for usage history. A log of payment webhook events (event id and type only) makes sure each is handled once. We never receive or store your card details.When you subscribe or export
Product analytics and errorsA small set of events (for example: brief submitted, directions shown, lock used, export attempted, paywall viewed) with no prompt text, page paths without query strings, and no IP address. Browser and server errors: the error message, page path and technical context.As you use the site, unless your browser sends Do Not Track
FeedbackIf you use the thumbs on a design or the Feedback box: the rating (up or down), the message you type (up to 1,000 characters), a short fingerprint of the design you rated (never the design itself), the page you were on, and the time. Signed in, it is stored against your account. Signed out, it is stored with a salted one-way hash of your IP address, plus the email address if you choose to leave one for a reply. Analytics is told only the rating and whether you wrote a message, never the message.When you send feedback
EmailYour address and the sign-in email we send you. We do not send marketing email.When you request a sign-in link
Messages to usWhatever you send to the contact address.When you write to us

Our hosting provider also processes ordinary technical request data (such as IP address and user-agent) to deliver the site and protect it from attacks. We do not use it to profile you.

What we do not do

3. Why we use it, and our lawful bases

PurposeLawful basis (GDPR)DPDP Act
Run your account, projects, shares, API keys and exportsContract: it is needed to provide the service you asked forConsent given by using the feature; legitimate use
Take and manage payments, refunds and tax recordsContract; legal obligation (through our payment processor)Legitimate use for the transaction; legal obligation
Send the sign-in emailContractConsent by requesting the link
Rate limits, abuse prevention, the AI spend limit, and securityLegitimate interests: keeping the service safe and affordableLegitimate use
Turn a brief into designs, including AI-assisted stepsContractConsent given by submitting the brief
Product analytics and error monitoringLegitimate interests: fixing bugs and improving the product with minimal dataLegitimate use
Answer your messages and requestsLegitimate interests; legal obligationLegitimate use
Read your feedback to decide what to fix and build nextLegitimate interests: improving the product; consent by sending itConsent given by sending the feedback

You can object to processing that relies on legitimate interests. See section 9.

4. Who processes data for us

We use the following service providers (“processors”). Each receives only what it needs for its job.

ProviderWhat it doesData involved
CloudflareHosts and delivers the siteEvery request to the site (IP address, user-agent), and the code that runs it
NeonDatabase (Singapore region)Everything in the table in section 2 that we store
ResendSends sign-in emailsYour email address and the sign-in link
PostHogAnalytics and error monitoringThe events and errors described above; memory-only, no cookies, IP address disabled, no prompts
DeepSeek (DeepSeek V4.1 Flash, through DeepSeek's own API)Runs the AI-assisted steps: reading a brief, sample content, naming directionsThe brief text and the design content being generated, for all users, signed in or not
Dodo PaymentsMerchant of record: takes payment, issues invoices, handles tax and refundsYour payment details and billing information, held by Dodo, not by us
GitHubSign-in with GitHub (OAuth)Your GitHub identity, email, name and avatar, at your request

Better Auth is the open-source sign-in library we run inside our own app. It is software, not a separate company that receives your data.

5. Cookies and browser storage

Because of this, StyleDUI shows no cookie banner.

6. AI processing

When the AI-assisted path is on, your brief and the generated design content are sent to DeepSeek's API (DeepSeek V4.1 Flash), which processes data in China. We do this for signed-in and signed-out visitors alike, but we only store the brief for signed-in users. If the AI service is unavailable or over its daily spend limit, the built-in engine produces the directions without any model call. Do not put personal data, secrets or confidential material into a brief. We log one line per AI call with timing, model name and token counts, never the prompt or the answer.

7. How long we keep data

8. International transfers

We use providers that process data in several countries. Our database is in Singapore, our hosting network is global, and analytics runs on PostHog's US cloud. DeepSeek processes AI requests in China. Other providers may process data in the United States or elsewhere. Where the law requires it, we rely on safeguards such as standard contractual clauses or the provider's data processing terms. Under the DPDP Act, we transfer data outside India except to any country the Government restricts.

9. Your rights

If the GDPR or UK GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, withdraw consent you have given, and complain to your supervisory authority.

Under India's DPDP Act, you have the right to obtain a summary of your data and how it is processed, to have it corrected, completed or erased, to have your grievance addressed, and to nominate another person to exercise your rights if you die or cannot act.

To use any of these rights, email contact@styledui.com from the address on your account. We will reply within 30 days. This address is also our grievance contact.

Deleting your account and data

Sign in and use Delete account in the danger zone on your Account page. You confirm by typing your email address. We first cancel any active subscription with our payment provider (if that fails, nothing is deleted, and you can try again), then permanently delete your account, projects and versions, briefs, share links (they stop working immediately), API keys, sessions, subscription record, export history and feedback you sent while signed in, and you are signed out. Invoices and tax records held by Dodo Payments are kept as the law requires, and copies in provider backups roll off on their own schedules. You can still email contact@styledui.com instead and we will do it for you. You can also delete single projects, revoke share links and revoke API keys from inside the app.

Downloading your data

Download my data on the same page (or GET /api/account/export while signed in) gives you a JSON file with your profile, projects with their latest versions, briefs, share links, API key names and prefixes (never the keys themselves), subscription status, export history and the feedback you sent while signed in. It is a copy for portability; it contains no passwords, tokens or key hashes.

10. Security

Traffic is encrypted in transit. API keys are stored only as hashes. Data access is scoped to the signed-in owner in our code. No system is perfectly secure; if a breach affecting you occurs, we will tell you and the authorities as the law requires.

11. Children

StyleDUI is for adults. You must be at least 18 to create an account, and we do not knowingly collect data from children. If you think a child has given us data, email us and we will delete it. (India's DPDP Act treats anyone under 18 as a child and requires verifiable parental consent, which we do not collect.)

12. Changes

We will update this page when our data practices change and update the date at the top. For significant changes we will also tell signed-in users by email or on the site.

13. Contact

contact@styledui.com. See also the Terms of Service.