Privacy Policy
Last updated 1 August 2026
Draft. This document describes how the product actually works, but it has not been reviewed by a lawyer. It should be before the service takes real customers.
The short version
We collect what the product needs to work: an account so you can sign in, the banners and brand kits you make, and enough usage data to know which parts of the app are worth improving. We do not sell any of it.
What we store
Your account. An email address, and a display name and avatar if you set one. If you sign in with Google we receive your email address and profile name from them; we never see your Google password.
Your work. Workspaces, projects, campaigns, the banner documents themselves, brand kits, and any images or fonts you upload. Also the chat messages you send the assistant, because a conversation you cannot scroll back through is not much use.
Your team. Who belongs to which workspace, their role, and pending invitations including the email address an invitation was sent to.
Billing. Which plan a workspace is on and how many seats it has. Card details are handled entirely by Stripe and never reach our servers.
Who else sees it
Running this needs other companies, and each of them sees only the part they need:
Supabase hosts the database, the authentication and the file storage — so effectively all of the above lives on their infrastructure. Stripe processes payments and holds card details. Resend delivers transactional email, so it sees the address an invitation or password reset goes to. PostHog receives product analytics: pages visited, features used, and an identifier for your account.
AI providers. Generating a banner means sending your prompt, the current banner document and any reference images you attach to a large language model — Anthropic, Google or OpenAI depending on the model in use. Assume anything you type into the assistant leaves our servers.
What we do not do
We do not sell personal data, we do not run advertising trackers on this site, and we do not use the contents of your workspace to train AI models.
Deleting your account
You can delete your account from your settings. Doing so removes your personal workspaces and everything inside them. Workspaces you share with other people survive you: ownership passes to the longest-standing remaining member, so a team does not lose its work when one person leaves.
Deletion is not instant everywhere — backups roll off on their own schedule, and Stripe keeps invoice records for as long as tax law requires it to.
Cookies
A session cookie keeps you signed in. A second, smaller one remembers which workspace you were last looking at — it is a preference, not a key, and it grants no access on its own. PostHog sets its own cookie to recognise a returning visitor.
Your rights
If you are in the UK or the EU you can ask for a copy of your data, ask us to correct it, or ask us to erase it. Write to hello@indiebytes.dev and we will answer within a month.
Changes
If this policy changes in a way that matters, the date at the top changes and we email account holders. Minor wording fixes will just appear.