Paintlang Privacy
Draft, last updated 2026-07-16. Questions: combinedwork196@gmail.com
The short version: the studio runs in your browser and stores your open paintings in your browser. We only hold what you explicitly send us: traced images (processed, not kept), cloud saves, and library contributions. We do not sell data and we do not run third-party ad or analytics trackers.
What stays in your browser
Open tabs, undo history, tool settings, and your account key live in your browser's localStorage. Clearing site data removes them.
What reaches our servers
Tracing: when you import an image, its pixels are sent to our tracing service, converted to code, and returned. Images are processed in memory and not stored. Cloud saves: saved paintings and their version history are stored so you can retrieve them; they are private to your account. Library contributions: stored and public by design, credited to your artist name. Rate limiting: request IPs are used transiently for abuse prevention.
Accounts
Key accounts store only a hash of your key plus your chosen name. Signing in with GitHub or Google gives us your name and provider user id (and email address from Google's basic profile); we use them only to identify your account. Paid plans are processed by Razorpay (India) or Dodo Payments (internationally), which handle your payment details under their own policies; we store only your plan status and a customer reference.
Usage counters
To understand which features matter, the app increments first-party daily counters when broad actions happen: a visit, a trace, opening the gallery, publishing, loving or opening a community painting, following an artist, exporting, sharing, saving, or clicking an upgrade button. Each counter is a single number per day (for example "exports today: 41"). These counters carry no account id, no browser fingerprint, and no content; they cannot be traced back to you. There are no third-party analytics, no ad trackers, and no tracking cookies anywhere on the site.
Community, profiles and follows
Publishing a painting to the community is public by design: the painting, its code, title, description, thumbnail, and your artist name are visible to everyone and may be opened and remixed. Your public profile shows your artist name, join date, published paintings, and follower counts - never your private gallery, versions, or workspace. Follows and loves are stored with your account so they work across devices; they are visible only as aggregate counts. Removing a published painting stops new copies immediately; existing remixes keep theirs. Artist names are unique across the community.
Share links and synced tabs
Share links for small paintings carry the whole painting inside the link itself and never touch our servers. Larger paintings are stored on our servers so a short link can serve them; anyone holding the link can view that painting, and the stored copy remains until you ask us to delete it. When you are signed in, your open studio tabs are synced to our servers so your workspace follows you across devices; this workspace is private to your account and is overwritten as you work.
Infrastructure
The site is served by GitHub Pages; the API runs on Cloudflare Workers with data in Cloudflare D1 and KV. Those providers process traffic under their own terms.
Your choices
Delete any cloud painting or library contribution from the app at any time. To delete an entire account and its data, email us from the account in question.
This is a working draft written for an independent product, not legal advice. It should be reviewed by a lawyer before relying on it commercially.