Your photo stays personal.
This is a local preview. Uploaded photos are validated in memory and discarded; sample results do not use your photo. Demo email addresses are held in local process memory with the order and disappear when the server restarts.
A hosted sample preview can store an encrypted, HttpOnly cookie containing your chosen style, budget and furniture notes for up to seven days, so sample results survive server restarts. This cookie contains no photo or email address and is separate from advertising consent. Sample links in this mode also require the original browser session.
Understanding the experience
Recent order links are saved in this browser’s local storage for up to seven days. These private links grant access to your results, so anyone using this browser can open them. No photo or email address is stored in this list. Use “Forget link” on the homepage to remove an entry; this does not delete the server order.
We use a random session identifier in your browser’s session storage to count visits and photo selections, and capture campaign tags from the page URL. These first-party counts contain no room photos or email addresses. Local demo counts disappear when the server restarts. We do not currently load Meta tracking or advertising cookies.
Planned connected service
When advertising measurement is configured, an optional, unticked choice on the order form lets you share your purchase amount, SHA-256 hashed email and ad click reference with Meta. Refusing does not affect your order. Room photos, furniture notes and private order links are never included in these events. Hashed identifiers can still be personal data. This version uses server purchase events and does not load a browser Meta Pixel.
To fulfill your order, your room photo and brief will be processed by OpenAI and stored privately in Supabase. Stripe processes payments, and Resend delivers requested transactional email. Photos must not contain people, sensitive documents or information you do not have permission to share.
Order links expire after seven days. Automated deletion, a final retention policy, business identity and a privacy contact must be configured and reviewed before public launch.
This draft describes the development version; it is not a finalized public privacy notice.