Legal
Privacy Policy
Last updated:
This policy explains what personal data StyleDUI handles, why, who helps us handle it, and what you can do about it. We try to collect very little: exploring designs needs no account, and we do not store anonymous prompts.
1. Who is responsible
The data controller (under the GDPR) and data fiduciary (under India's Digital Personal Data Protection Act, 2023) is the individual developer who runs StyleDUI:
[Data controller legal name — to be confirmed before launch]
Contact for anything about your data: contact@styledui.com. That address is also where you send requests and complaints.
2. What we collect
| Data | What exactly | When |
|---|---|---|
| Account | Email address, name and profile picture URL (from GitHub if you sign in with it), whether the email is verified, and the sign-in method. For GitHub sign-in, the OAuth tokens GitHub issues for our app are kept in our database. | When you sign in |
| Sessions | A session token (kept in a cookie), its expiry, the IP address and browser user-agent seen at sign-in, kept with the session. One-time email sign-in tokens are stored until they expire (15 minutes). | While you are signed in |
| Projects and versions | Project names, and each saved version of a design (its layout, style settings, content, and an optional note). | When you save a project |
| Briefs | The text of your brief and how we read it, for signed-in users only, as your history. Briefs from visitors who are not signed in are not stored. | When a signed-in user explores |
| Share links | A random link name, which saved version it points to, when it was created or revoked, and reports made about it (a reason you type, no reporter identity). | When you share or report |
| Run metadata | For a brief we ran: whether it used AI or our built-in engine, the model name, response time, estimated cost, and any fallback reason. It contains no prompts; it is linked to your stored brief only if you are signed in. | On every brief |
| API keys | A name you choose, the first 8 characters for display, and a one-way SHA-256 hash of the key. The key itself is shown to you once and not stored. | When you create a key |
| Rate-limit counters | For visitors who are not signed in: a salted one-way hash of the IP address, with request counts per minute and per day. For signed-in users: the counter is tied to the account id. We do not store the raw IP address in these counters. | On every explore, export or save request |
| Subscription and export records | Payment provider customer and subscription ids, plan, billing interval, status, period end, whether it cancels at period end, and whether it is a founding-member price. Also a record per code or token export (type and time), kept for usage history. A log of payment webhook events (event id and type only) makes sure each is handled once. We never receive or store your card details. | When you subscribe or export |
| Product analytics and errors | A small set of events (for example: brief submitted, directions shown, lock used, export attempted, paywall viewed) with no prompt text, page paths without query strings, and no IP address. Browser and server errors: the error message, page path and technical context. | As you use the site, unless your browser sends Do Not Track |
| Feedback | If you use the thumbs on a design or the Feedback box: the rating (up or down), the message you type (up to 1,000 characters), a short fingerprint of the design you rated (never the design itself), the page you were on, and the time. Signed in, it is stored against your account. Signed out, it is stored with a salted one-way hash of your IP address, plus the email address if you choose to leave one for a reply. Analytics is told only the rating and whether you wrote a message, never the message. | When you send feedback |
| Your address and the sign-in email we send you. We do not send marketing email. | When you request a sign-in link | |
| Messages to us | Whatever you send to the contact address. | When you write to us |
Our hosting provider also processes ordinary technical request data (such as IP address and user-agent) to deliver the site and protect it from attacks. We do not use it to profile you.
What we do not do
- We do not store the prompts of visitors who are not signed in.
- We do not use advertising trackers, sell personal data, or record your screen.
- We do not send your prompts to our analytics tool.
3. Why we use it, and our lawful bases
| Purpose | Lawful basis (GDPR) | DPDP Act |
|---|---|---|
| Run your account, projects, shares, API keys and exports | Contract: it is needed to provide the service you asked for | Consent given by using the feature; legitimate use |
| Take and manage payments, refunds and tax records | Contract; legal obligation (through our payment processor) | Legitimate use for the transaction; legal obligation |
| Send the sign-in email | Contract | Consent by requesting the link |
| Rate limits, abuse prevention, the AI spend limit, and security | Legitimate interests: keeping the service safe and affordable | Legitimate use |
| Turn a brief into designs, including AI-assisted steps | Contract | Consent given by submitting the brief |
| Product analytics and error monitoring | Legitimate interests: fixing bugs and improving the product with minimal data | Legitimate use |
| Answer your messages and requests | Legitimate interests; legal obligation | Legitimate use |
| Read your feedback to decide what to fix and build next | Legitimate interests: improving the product; consent by sending it | Consent given by sending the feedback |
You can object to processing that relies on legitimate interests. See section 9.
4. Who processes data for us
We use the following service providers (“processors”). Each receives only what it needs for its job.
| Provider | What it does | Data involved |
|---|---|---|
| Cloudflare | Hosts and delivers the site | Every request to the site (IP address, user-agent), and the code that runs it |
| Neon | Database (Singapore region) | Everything in the table in section 2 that we store |
| Resend | Sends sign-in emails | Your email address and the sign-in link |
| PostHog | Analytics and error monitoring | The events and errors described above; memory-only, no cookies, IP address disabled, no prompts |
| DeepSeek (DeepSeek V4.1 Flash, through DeepSeek's own API) | Runs the AI-assisted steps: reading a brief, sample content, naming directions | The brief text and the design content being generated, for all users, signed in or not |
| Dodo Payments | Merchant of record: takes payment, issues invoices, handles tax and refunds | Your payment details and billing information, held by Dodo, not by us |
| GitHub | Sign-in with GitHub (OAuth) | Your GitHub identity, email, name and avatar, at your request |
Better Auth is the open-source sign-in library we run inside our own app. It is software, not a separate company that receives your data.
5. Cookies and browser storage
- One cookie, strictly necessary. When you sign in, our sign-in library sets a session cookie. It is marked HttpOnly, SameSite=Lax and, on https, Secure, and it exists only to keep you signed in. It is strictly necessary for a service you asked for, so it needs no consent banner.
- Analytics uses no cookies. PostHog runs in memory only for the current page load: it does not set cookies or write to local storage, it does not capture IP addresses, it respects Do Not Track, and it does not record sessions.
- Your browser's own storage, for features you use. Your current exploration is kept in session storage; a small taste profile learned from your choices is kept in local storage; and if you paste a paid API key into the editor to export, it is kept in local storage on your device. None of this is used to track you, and none of it is sent to analytics. Clear it in your browser at any time.
Because of this, StyleDUI shows no cookie banner.
6. AI processing
When the AI-assisted path is on, your brief and the generated design content are sent to DeepSeek's API (DeepSeek V4.1 Flash), which processes data in China. We do this for signed-in and signed-out visitors alike, but we only store the brief for signed-in users. If the AI service is unavailable or over its daily spend limit, the built-in engine produces the directions without any model call. Do not put personal data, secrets or confidential material into a brief. We log one line per AI call with timing, model name and token counts, never the prompt or the answer.
7. How long we keep data
- Account, projects, versions, briefs, share links, API keys, export records, feedback you sent while signed in: until you delete them or delete your account. Deleting your account (section 9) removes all of it from our database at once. Deleting a single project hides it and its share links straight away, and a daily cleanup permanently deletes it, with its versions and share links, 30 days later. Email us if you need a project erased sooner.
- Sessions: expire after 30 days without use (each day of use renews them); one-time sign-in tokens expire after 15 minutes. The daily cleanup deletes expired sessions and tokens.
- Feedback from visitors who are not signed in: the message and rating are kept, but the IP hash and any reply email are removed by the daily cleanup once the feedback is 90 days old, so it can no longer be tied to you. Feedback you sent while signed in is part of your account: it is included in your data export and deleted with your account.
- Rate-limit counters: short-lived by design (per-minute and per-day windows); the daily cleanup deletes counters older than 2 days.
- Billing records: the subscription record stays while your account exists and is deleted with it. Payment webhook log entries (event id and type only) are deleted after 90 days. Dodo Payments keeps invoices and tax records for as long as the law requires, and we cannot delete those.
- Analytics and error data: kept in PostHog for the period set in its project settings [retention period to be confirmed].
- Backups and logs held by our providers roll off on their own schedules.
8. International transfers
We use providers that process data in several countries. Our database is in Singapore, our hosting network is global, and analytics runs on PostHog's US cloud. DeepSeek processes AI requests in China. Other providers may process data in the United States or elsewhere. Where the law requires it, we rely on safeguards such as standard contractual clauses or the provider's data processing terms. Under the DPDP Act, we transfer data outside India except to any country the Government restricts.
9. Your rights
If the GDPR or UK GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, withdraw consent you have given, and complain to your supervisory authority.
Under India's DPDP Act, you have the right to obtain a summary of your data and how it is processed, to have it corrected, completed or erased, to have your grievance addressed, and to nominate another person to exercise your rights if you die or cannot act.
To use any of these rights, email contact@styledui.com from the address on your account. We will reply within 30 days. This address is also our grievance contact.
Deleting your account and data
Sign in and use Delete account in the danger zone on your Account page. You confirm by typing your email address. We first cancel any active subscription with our payment provider (if that fails, nothing is deleted, and you can try again), then permanently delete your account, projects and versions, briefs, share links (they stop working immediately), API keys, sessions, subscription record, export history and feedback you sent while signed in, and you are signed out. Invoices and tax records held by Dodo Payments are kept as the law requires, and copies in provider backups roll off on their own schedules. You can still email contact@styledui.com instead and we will do it for you. You can also delete single projects, revoke share links and revoke API keys from inside the app.
Downloading your data
Download my data on the same page (or GET /api/account/export while signed in) gives you a JSON file with your profile, projects with their latest versions, briefs, share links, API key names and prefixes (never the keys themselves), subscription status, export history and the feedback you sent while signed in. It is a copy for portability; it contains no passwords, tokens or key hashes.
10. Security
Traffic is encrypted in transit. API keys are stored only as hashes. Data access is scoped to the signed-in owner in our code. No system is perfectly secure; if a breach affecting you occurs, we will tell you and the authorities as the law requires.
11. Children
StyleDUI is for adults. You must be at least 18 to create an account, and we do not knowingly collect data from children. If you think a child has given us data, email us and we will delete it. (India's DPDP Act treats anyone under 18 as a child and requires verifiable parental consent, which we do not collect.)
12. Changes
We will update this page when our data practices change and update the date at the top. For significant changes we will also tell signed-in users by email or on the site.
13. Contact
contact@styledui.com. See also the Terms of Service.