SkrinAI · Legal
Privacy Policy
Last updated:
How SkrinAI handles your information when you create designs, use AI features, and manage your account.
Draft for pre-launch review. Bracketed TODOs identify details that must be confirmed before launch.
1. Introduction
This policy describes how information is handled when you use SkrinAI, an AI-powered design platform. SkrinAI is a product name; the responsible operator is [TODO: Add legal entity name, country/state of registration, and business address].
It covers our website, accounts, design tools, and related services. Third-party services also have their own privacy notices.
2. Information we collect
- Account information: name, email address, profile image where provided, account identifiers, preferences, and account dates.
- Authentication information: password credentials for email accounts, Google account information received during OAuth sign-in, linked-account tokens and identifiers, sessions, and authentication records. Session records can include IP addresses and user-agent information.
- Billing information: Polar customer and subscription identifiers, selected plan, subscription status and dates, cancellation information, and billing-event records. Payment details are handled through Polar-hosted payment services.
- Uploaded content: screenshots, images, fonts, and other supported assets, including file names, file metadata, and content you choose to upload.
- AI interactions: prompts, conversations, attached images, design context, tool activity, request status, and usage records.
- Designs and results: project and page data, generated text and images, versions, previews, and export-related records.
- Usage and analytics: feature activity and credit usage needed to operate the service, plus optional product analytics when enabled with your consent.
- Technical information: browser/device information, IP addresses, request URLs, timestamps, response status, referrers where supplied, and operational or error logs.
- Browser storage: authentication cookies; local storage for consent, theme, and editor preferences; and session storage for some in-progress operations. Optional analytics uses additional storage as explained below.
3. How we use information
We use information to register and authenticate accounts, save and edit designs, process AI requests, deliver results, manage subscriptions and usage limits, send transactional communications, respond to support requests, protect the service, troubleshoot failures, and improve SkrinAI. Optional analytics supports understanding product use.
[TODO: Confirm applicable legal bases for processing, including contractual necessity, legal obligations, legitimate interests, and consent, for the markets served.]
4. AI processing
AI features can send your prompts, relevant conversation history, selected or referenced images, and design context to third-party providers to generate or edit designs, analyze images, generate images, remove backgrounds, or perform safety checks. Context may include text visible in an uploaded screenshot.
The current integrations include DeepSeek for design generation and analysis, OpenAI for supporting AI tasks and image generation where enabled, and Replicate for background removal. Which services receive content depends on the feature and configuration.
Provider processing and retention are subject to the applicable provider arrangements. This policy does not promise that providers never retain data or never use it for training. [TODO: Verify provider contracts, retention, training settings, and processing locations before launch.] Avoid submitting content you are not authorized to share.
5. Uploaded content and files
Uploads and generated assets are stored in configured S3-compatible object storage; associated metadata, projects, and AI history are stored in application databases. Time-limited signed URLs are used for file access and transfers. Relevant files or their contents may be made available to processors to complete requested operations.
Deleting an asset through the available asset controls removes its application record and requests removal of its stored object. Some assets cannot currently be deleted because AI request history still references them. Removing one asset does not establish deletion of copies in versions, history, backups, or third-party systems.
6. Analytics, cookies, and preferences
Authentication cookies support signing in and maintaining sessions. Functional browser storage supports consent choices, theme, editor presets, and in-progress operations. Rejecting optional analytics does not disable these service functions.
PostHog product analytics is optional and gated by consent. When enabled and accepted, it uses cookies and local storage for analytics identity and session continuity. Anonymous choices are stored in your browser; signed-in analytics choices are stored against your account.
Analytics events use an allowlist of properties such as feature events, plan, internal user ID, and relevant project or asset identifiers. Prompts, conversation text, uploaded file contents, and design contents are excluded from these product-analytics event properties. Routes are reduced to approved labels; query strings are excluded. IP geolocation enrichment and automatic click capture are disabled. Network services still receive connection information necessary to handle requests.
Session replay is disabled by default. If enabled in a verified deployment, it requires a separate preference and is restricted to eligible public pages with masking; editor, authentication, and payment pages are excluded. No advertising or marketing tracker was identified in the current application.
Use Analytics preferences in the footer, or Settings → Privacy when signed in, to accept, reject, or change optional tracking. Withdrawal stops future collection; it does not automatically erase previously collected records.
7. Payments and billing
Polar provides subscription checkout and customer billing services. Account creation can create a Polar customer using your name, email, and account identifier, even before you subscribe. SkrinAI receives subscription and billing information needed to provide access, reconcile billing events, and handle billing communications.
Cancellation and refund information appears in our Terms of Service. Cancelling a subscription does not delete your account or billing records.
8. Service providers
- Google: OAuth authentication when you choose Google sign-in. Better Auth is the authentication software used by SkrinAI.
- Polar: customer accounts, payment checkout, subscriptions, and billing management.
- PostHog: consent-based product analytics and separately gated session replay.
- DeepSeek, OpenAI, and Replicate: the AI processing described above, as needed by enabled features.
- Resend: transactional email delivery, including subscription activation messages.
- Supabase: the currently configured PostgreSQL database and S3-compatible object storage. Hosting and Redis infrastructure: running the application, sessions, jobs, and storing content. [TODO: Confirm deployed infrastructure providers and regions.]
[TODO: Confirm the final processor list, contractual roles, and applicable data-processing agreements before launch.]
9. Data retention
The application persists accounts, projects, uploads, AI conversations and execution history, usage records, and billing records. Retention varies by record and service; there is no verified universal account-deletion or retention schedule.
[TODO: Confirm retention periods and deletion procedures for account data, files, AI history, analytics, logs, backups, and processor copies before launch.] [TODO: Confirm billing and tax record retention obligations.]
10. Data security
The application uses authentication, workspace authorization, rate limits, and signed file-access URLs to help control access. No system can guarantee absolute security. Keep your account credentials secure and share content carefully.
[TODO: Confirm deployed transport security, storage protections, access controls, backup controls, and incident-response procedures before launch.]
11. International processing
Infrastructure and service providers may process information outside your country. Processing locations depend on deployment and provider arrangements.
[TODO: Confirm processing countries and any required international-transfer safeguards before launch.]
12. Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of your information, restrict or object to processing, withdraw consent, and complain to a relevant supervisory authority. These rights may be subject to exceptions and identity verification.
[TODO: Add a working privacy-request contact and procedures for verifying and responding to requests before launch.]
13. Account and data deletion
Self-service account deletion is not currently available. A verified account/data deletion request process has not yet been established. Subscription cancellation is separate from data deletion and does not remove uploads, designs, AI conversations, or billing records.
Individual asset deletion has the limitations described above. We cannot currently promise complete removal from AI history, backups, or provider systems. Billing records may need to be retained to meet applicable obligations.
[TODO: Establish and test an account/data deletion request process, including uploaded assets, AI history, provider copies, backups, and required billing-record exceptions before launch.]
14. Children and minimum age
[TODO: Confirm minimum age, intended audience, parental-consent requirements where applicable, and procedures for handling children's data before launch.]
15. Changes to this policy
Updates will be reflected in the date above. [TODO: Confirm how material changes will be communicated and any legally required notice or renewed consent before launch.]
16. Contact
Operator: [TODO: Add legal entity name and business address]
[TODO: Add legal/support email]