Privacy Policy
Last updated: 8 August 2026
In short: we collect the minimum needed to run your account — your email, your designs, and a record of what you spent tokens on. We never sell your data, and we never see your card details. You can delete your account and its data from inside the app.
1. Who is responsible for your data
Şahıs Şirketi Önder Gecü (sole proprietorship), Bursa, Türkiye, is the data controller for the personal data described here. Contact: support@theplaidstudio.com.
2. What we collect and why
| Data | Why we hold it | Legal basis (GDPR) |
|---|---|---|
| Email address, password (stored only as a cryptographic hash), email-verification state | To create your account, sign you in, and let you recover access | Performance of a contract |
| Your saved designs and their preview thumbnails | So your work is there when you return | Performance of a contract |
| Plan, token balance, and a ledger of token grants and spends | To apply your plan correctly and to resolve billing disputes | Performance of a contract; legal obligation (accounting) |
| Export records (time, format, resolution) | To enforce plan allowances and detect abuse | Performance of a contract; legitimate interest |
| Payment records received from Paddle (subscription status, transaction ids, amounts) | To grant what you paid for and keep required financial records | Performance of a contract; legal obligation |
| If you use Share & Earn: the preview image you chose to share, and a one-way hash of visitor IP address + browser identifier + date | To display the shared image and to count each visitor only once, so referral rewards cannot be farmed. We store the hash, not the IP address itself. | Legitimate interest (fraud prevention) |
| Server logs (including IP address) and error diagnostics | Security, abuse prevention, and fixing faults | Legitimate interest |
What we do not collect
- Card and payment details. These go directly to Paddle. We never see or store your card number.
- We do not use advertising trackers or sell data to third parties.
- We do not build behavioural profiles for marketing.
3. Cookies and local storage
We use browser storage only for things the Service needs to work: your sign-in token, your language and interface preferences, and a referral code if you arrived through someone's share link. These are not advertising cookies. Paddle may set its own cookies during checkout; see Paddle's privacy notice for those.
Usage analytics
We use Umami to understand how the site is used. Umami sets no cookies and does not track you across other websites, which is why you are not asked to accept an analytics banner. It records page views along with the referring site, an approximate country, and your browser, operating system and device type. It also records a small number of product milestones — creating an account, generating your first pattern, completing your first export, and opening a checkout — so we can see where the Service is confusing or broken.
If you reach us from an advertisement or a shared link, the campaign parameters in that link
(utm_source and similar) are kept in your browser and attached to the account-creation
event, so we can tell which campaigns are worth continuing. We never send your name, email
address, account id or any design you make to Umami, and we do not use this data to target
advertising at you or to build a profile about you.
4. Who else processes your data
- Paddle.com Market Ltd — merchant of record: payment processing, tax, invoicing and fraud checks.
- Amazon Web Services (AWS Lightsail) — server hosting (Frankfurt, Germany).
- GoDaddy (Professional Email) — sending verification and password-reset email.
- Umami Software, Inc. — cookieless usage analytics (see section 3).
These providers act on our instructions under data-processing agreements. We do not share your data with anyone else except where the law requires it.
5. International transfers
Our providers may process data outside your country. Where data leaves the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
- Account data and designs — while your account is open.
- After you delete your account — removed from active systems promptly, and from routine backups within 30 days.
- Financial and token-ledger records — retained for the period required by accounting and tax law (typically up to 10 years), even after account deletion.
- Referral visitor hashes — 12 months.
- Server logs — up to 90 days.
7. Your rights
Under the GDPR — and, if you are in Türkiye, under KVKK — you may request:
- a copy of the personal data we hold about you;
- correction of inaccurate data;
- deletion of your data ("right to be forgotten");
- restriction of, or objection to, processing based on legitimate interest;
- portability of data you provided to us;
- to lodge a complaint with your national data protection authority.
Deleting your account: open Account in the app and choose Delete account. This permanently removes your designs, token balance and profile. You can also email support@theplaidstudio.com and we will do it for you within 30 days.
8. Security
Traffic is encrypted with HTTPS. Passwords are stored as salted hashes, never in readable form. Access to production systems is limited and authenticated. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
9. Children
The Service is not intended for people under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
10. Changes to this policy
We may update this policy. Material changes will be announced by email or in the app before they take effect, and the date at the top will change.
11. Contact
Privacy questions or requests: support@theplaidstudio.com.