Privacy policy
Last updated: 23 September 2026
Draft version: fields in square brackets must be completed before going live.
Data controller
[COMPANY NAME] is the controller for account and billing processing, and a processor on behalf of its customers for the content of their projects (data processing agreement, GDPR article 28). Contact: [DPO EMAIL ADDRESS].
Data processed
User identity (name, email address, sign-in provider), project content (briefs, specifications, comments), technical and audit logs. No real business data is needed: mockups exclusively use fictitious data.
Purposes and legal bases
Providing the service and managing accounts (contract), security and abuse prevention (legitimate interest), billing (legal obligation).
Retention periods
Accounts: lifetime of the account plus one year. Content: duration of the subscription, then deletion within 30 days. Technical and audit logs: 12 months. Billing: 10 years.
Processors and transfers
Vercel (application hosting), Supabase (database and authentication, Paris region), Resend (transactional email, EU region), OpenRouter and zero-retention AI model providers (metadata only). Transfers outside the EU are covered by standard contractual clauses.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, which you can exercise at [DPO EMAIL ADDRESS]. You may lodge a complaint with the CNIL.
Cookies
Only strictly necessary cookies are set: authentication session and language preference. Your theme choice is kept in your browser’s local storage. No advertising cookies.