Security and your data
If you are deciding whether to trust a small company with a wall you are about to build, this is the page that should answer it.
Where your work lives
Your account and your designs sit in a managed Postgres database run by Supabase. Traffic between your browser, this site and the services behind it is encrypted in transit with TLS, and the data is encrypted at rest by the providers holding it.
Every workspace is walled off from every other one at the database level, not by a check in the page you are looking at. The rules live next to the data, so a bug in the interface cannot hand your rows to somebody else's account.
Payment cards
Card details go straight to Stripe and never touch our servers. We hold the identifiers Stripe gives us for your customer and subscription records, your plan and your renewal dates. We never see or store a full card number.
Who else touches the data, and why
Twelve companies process data on our behalf. The privacy policy names every one of them, what it holds and why it is there.
| Provider | What it is for |
|---|---|
| Supabase | The database and the sign-in system: your account, your projects and your libraries. |
| Stripe | Payments. Card data goes to Stripe directly, so we never hold it. |
| Anthropic | The AI assistant, when you use it. |
| The alternative AI model, reachable only by our own administrators while testing. No customer conversation is routed to it. This is a different thing from Sign in with Google, where Google is not our processor. | |
| Vercel | Hosting, server logs, page-view counts and page-speed measurements (Core Web Vitals). Sets no cookie. |
| Resend | Account email: sign-in links, receipts, replies. |
| Cloudflare | The security check on the pages where you create an account, sign in, or ask us to delete your account. It sees the connection and the IP address it came from, and never your email, your name or anything you typed. |
| Ahrefs Web Analytics | Counts page views. Sets no cookie and keeps no raw IP address. |
| PostHog | Product analytics, and only if you accept the cookie banner. Autocapture and session recording are switched off. |
| Upstash | Rate limiting. A short-lived counter against your IP address, holding no name, no email and nothing you typed. |
| Jam | Bug recordings, made only when you start one from a recording link we sent you, or by our own team while testing. Its scripts load on every page and record nothing until a recording starts. |
| Sentry | Error reports, sent only when a page hits an error that nothing caught. A report holds the error, your browser, the page address without anything after a question mark and the approximate location (country and city) Sentry works out from your connection, and it carries no account id and no email address. It sets no cookie. |
Your designs are yours
You own what you draw. You can export your cut lists and your material lists, and you can close your account and take your work with you. We do not sell it, and we do not train a model on it.
Signing in
You can sign in with Google or with an emailed link. If you set a password we store only a salted hash of it, so nobody here can read it. One account can be signed in from one place at a time, which is what stops a shared login quietly becoming five.
What we do not claim
We do not hold a SOC 2 report, an ISO 27001 certificate or any other audit badge, and we are not going to print one on a page because it looks reassuring. What is written above is what is actually running. If that changes, this page changes with it.
Found something that looks wrong? Tell us, and you will get a real answer from the person who wrote the code.
The longer versions
The privacy policy lists every category of data, every provider and every right you have over it. The terms cover the agreement itself. The cookie page covers what is stored in your browser.