Privacy status

Projects stay private, with an explicit beta policy boundary.

This is an implementation notice for the public beta, not final legal policy. It says what the current product stores and which retention decisions are still being finalized.

Current product boundary

Projects and support requests are restricted to the account through Row Level Security. Artifact bytes use private object storage. Private artwork is not used for model training by default and is not sent to a vision model without explicit processing consent.

First-party measurement

The product records a fixed set of funnel and reliability event names, routes, optional opaque product IDs, and bounded outcomes. The event schema does not accept artwork, prompts, email, filenames, signed links, or arbitrary properties. No third-party analytics provider is required.

Optional prompt planning

AI prompt planning is disabled unless the product owner explicitly enables a reviewed provider. When enabled and you ask it to create a design from text, the prompt and structured setup target are sent to that provider to propose a bounded object plan. Images, account rows, machine files, storage links, and database access are not provided to the model. Deterministic software still validates and compiles every proposal, and the model never writes embroidery-file bytes.

Requests and retention

Signed-in users can open privacy or account-deletion requests through Support. The request starts a reviewed tombstone and deletion process; it does not instantly erase data. Final retention periods, deletion service level, region, subprocessors, and final legal policy text are still being finalized during the beta.