Privacy Policy
This page explains what Stylelock collects, why we collect it, and who else receives it. It is written in plain language. It is a starting draft — have a human review it before you rely on it for a store listing.
Who we are
Stylelock is a web product that locks a style reference and generates matching brand assets (app icons, favicons, og-images, and illustrations), available through a maker dashboard and an MCP server. Contact: [email protected].
Account data
When you create an account we process your email address and the name you choose to show. We use that data to authenticate you, operate your account, send necessary service messages, and respond to support requests.
Content you submit
You and your agents may submit product briefs, style and palette choices, screen or spot descriptions, asset selections and edits, project names, and related tool inputs. We process that content to explore and lock styles, generate and export assets, issue and manage API keys you request, keep your credit ledger accurate, and show you your projects. That content stays in your account until you delete it or delete the account.
Third-party processors we actually use
These external parties receive user data in order to run Stylelock:
- Polar.sh — receives the account and purchase details needed to run credit-pack checkout and confirm payment.
- OpenRouter — receives the brief and generation inputs required to explore styles and generate assets (and related model usage metadata for metering).
- Cloudflare Pages — receives the request data involved in serving this marketing site (and related static delivery).
- Cloudflare Email Service — receives the email address and message content when we send transactional or support email.
- Model Context Protocol — when you connect an AI client over MCP, that client (and the provider behind it) receives the tool inputs and outputs you authorize in that session.
Everything else runs on infrastructure we operate; no third party receives your data through it.
International transfers
Where the data physically sits: United States (Northern Virginia). If you use Stylelock from outside the United States, your data is transferred to the United States. Where a recipient is covered by an adequacy decision, that is the basis for the transfer; otherwise we rely on Standard Contractual Clauses. The exact basis for each processor is available on request so this page does not go stale as certifications change.
Cookies
This marketing site sets no cookies. Analytics events are counted without a device-persisted identifier, so there is no consent banner on these pages. We store nothing non-essential on your device from this landing. Inside the signed-in product, session authentication may use a strictly necessary httpOnly cookie set by our servers; that cookie is required to keep you logged in and is disclosed here even though consent is not required for strictly necessary storage.
Analytics on this site
Optional product analytics may send anonymous event names (for example, that a visitor clicked Explore a style) with a random identifier created in memory for that page load only. We do not write that identifier to cookies, localStorage, or sessionStorage on this landing.
How long we keep data
Account and content data are kept while your account is active. If you delete your account, we delete associated product content as described in our product rules. Records needed for security, financial audit, or legal compliance may be retained longer where the law requires it.
Your choices
You can revoke API keys you issued and request account deletion. For privacy questions or requests, email [email protected].
Changes
If this policy changes in a material way, we will update the effective date on this page.