Privacy · 4 October 2026
Your room, your private project.
Orders are currently closed.
Support contact will be published before orders open.
What we collect and why
The free style brief stays in your browser. When you explicitly create an order, we receive your room photo, email, design preferences and acceptance of the terms and photo rights. We use these to supply the service and handle support. Original photo metadata is removed before storage.
Orders have a randomly generated private access link. Treat it like a password. The token is kept in browser session storage; the server stores its hash. We do not use advertising cookies or analytics trackers.
Villa records and location
When you create a villa archive we receive the name, email, user-entered address label, confirmed coordinates, time zone, wall orientation, notes and consent. Maintenance records include dates, repeat intervals, work notes and any cost you record. Equipment records can include names, manufacturer/model references, dates and warranty notes. Cost records can include vendor, category, date, currency, amount and notes. These are private service data, not public listings. Avoid tenant details, identity documents or sensitive records. A free sun preview sends coordinates to our server for calculation without creating an archive.
Address searches, when configured, send the address to OpenCage for geocoding; results include OpenStreetMap attribution. Confirm the house pin. We do not fetch Google Maps pages: coordinates in full pin links are parsed locally on our server. Optional AI planning is sent to the configured AI provider only after you request it; it includes property notes, up to 30 maintenance records and calculated solar summaries. Sunlight calculations themselves do not use an AI provider.
Private villa keys are hashed on the server and encrypted for receipt/reminder delivery. Keys are held in browser session storage; a list of archive IDs, without access keys, is remembered in local storage for navigation. Resend processes the email and private archive link for receipts and optional reminders. Reminder emails avoid including your street address or detailed work notes. Disable reminders in your archive at any time; they are not marketing.
Service processors
Stripe processes your payment and may collect payment, billing and tax information under its own notice. We receive payment identifiers and status, not your card details. The configured image provider receives the normalized photo and design preferences to generate concepts. The configured host holds the private order database and images. Resend processes your email and private project link to send transactional order messages. The operator must review applicable processor agreements and international transfer safeguards before opening sales.
We do not publish your images or intentionally submit them for model training. AI provider retention and processing are governed by the applicable API agreement; this does not promise zero provider retention.
Retention and deletion
Free villa archives expire after 30 days. Paid villa archives and stored reports expire 30 days after the latest care period ends (365 days after purchase). Use archive export for JSON records, report CSV and print-to-PDF to retain your own copy. Delete in the archive to erase address, coordinates, notes, maintenance, equipment, costs, analyses, stored reports and email jobs earlier. An AI request already sent to a provider cannot be recalled, but a result returning after deletion is not retained.
Minimal villa purchase records are retained for the configured legal/accounting period, including identifiers, payment state and amounts. Deleted villa identifiers are retained to recognize delayed payment notifications and flag any necessary refund. Failed and expired unpaid reports are not publicly accessible. Backups and external processors have separate retention obligations, which the operator must document and honor.
Unpaid order images are removed after approximately one hour. Completed or refunded project images are removed after 30 days. Use the private project page to request earlier deletion. An active generation may need to finish before removal; undelivered paid work is cancelled and refunded. Service workers run deletion checks at least once per minute while running.
Minimal order and payment records may be retained for accounting, fraud prevention and legal obligations. The operator configures the applicable record retention period; email and free-text preferences are removed with your image deletion request. Encrypted backups must have a documented retention schedule and deletion controls; ask support about any relevant backup copy.
Your rights
Contact the published support address to request access, correction, deletion or applicable portability and restriction rights. Where applicable, you can complain to a data protection authority. We do not sell your photos. Submit only photos you can lawfully use, and avoid people, documents or other sensitive information.
Operational records
We record order events, review and payment actions. We do not log room images or private link tokens. The hosting provider may collect connection and security logs subject to its policy.