Privacy Policy
Last updated
This policy explains what personal data ProdKit collects, why, who processes it, and the choices you have. In short: we collect what we need to run ProdKit and bill for it, we don't use analytics or advertising trackers, and we don't sell your data.
1. Who we are
ProdKit is run by Mythical Creature, LLC, a Delaware limited liability company ("we" or "us"). We decide how the personal data described here is used, which makes us its controller. For any privacy question or request, email support@prodkit.cloud.
2. Information we collect
- Account. Your email address, and a workspace name we create from it. If you sign in with GitHub, GitHub shares your user ID, username, name, email address, and profile picture URL, and we store them with your account.
- Sign-in. We email you one-time sign-in codes. Our sign-in provider records when you sign in, and the IP address and browser of each session, for security.
- Projects. Each project's name, its name in image URLs, and the storage URL and bucket name you connect.
- Usage and request logs. For image requests that produce a new response, and a sample of those served from cache, we record the project, the image's path in your bucket, the response status, cache status, content type, size in bytes, and time. From these we keep monthly totals per project and the image paths and sizes (width, crop, quality, and effects) counted toward each month's bill. These logs don't include the viewer's IP address, cookies, or browser.
- Rate limits. To stop abuse, we count sign-in attempts and some dashboard actions per email address, IP address, or account. The counts are stored under pseudonymous SHA-256 hashes rather than the address itself, and deleted after about a day.
- Billing. When you subscribe, Stripe collects your payment details, billing address, and any tax ID on its own pages. We give Stripe your email address and account ID, and we store the Stripe customer ID, your plan, the subscription status, and billing period dates. We never see or store your full card number.
- Support. If you email us, we keep your message and our reply.
- Hosting logs. Our hosting providers keep short-lived operational logs of requests to the website and the image endpoint, which can include IP addresses and browser details. We use them only to run and debug the service.
3. Images and your app's visitors
ProdKit fetches an image from your bucket when someone requests it. Cloudflare transforms it and caches the result in its data centers, and each generated size is also stored in Cloudflare R2 for up to 180 days after it's created, so it isn't transformed again.
We don't look at image contents except to run the service, investigate a report of abuse, or comply with the law. We don't use them for anything else, including training AI models.
When your app's visitors load images through ProdKit, we process those requests on your behalf. Our usage logs record which image was served, not who viewed it. Image paths are whatever you name your files, so keep personal information such as names or email addresses out of them. You're responsible for telling your own users about the services your app relies on, including ProdKit.
4. How we use information
- To run ProdKit: sign you in, connect projects, deliver images, and show your dashboard.
- To measure usage, bill you, and calculate taxes.
- To protect the service: rate limits, abuse prevention, security, and debugging.
- To contact you: sign-in codes, replies to support email, and important notices about your account, billing, or changes to our terms or prices. We don't send marketing email.
- To meet legal obligations, such as tax and accounting records.
We don't sell personal information, share it for cross-context behavioral advertising, or use it to make automated decisions that have legal effects on you.
If you're in the EU or UK, our legal bases are: performing our contract with you (your account, the service, and billing), our legitimate interests in keeping the service secure and working and in handling reports, our legal obligations (such as keeping tax records), and your consent where we ask for it.
5. Service providers
These companies process data for us, only to provide their service to us:
- Supabase: our database and sign-in. Account, project, usage, and sign-in data.
- Vercel: hosts the website, dashboard, and API. Requests to them, including IP addresses in logs.
- Cloudflare: runs img.prodkit.cloud, where it transforms, caches, and stores images. It also provides our DNS and forwards email sent to support@prodkit.cloud. Images, image requests, and support email.
- Stripe: payments, invoices, and tax calculation. Billing details and your email address.
- Resend: sends sign-in emails. Your email address and sign-in codes.
- Our email host: stores the support email Cloudflare forwards to us.
We may also disclose information when the law requires it, to protect the rights and safety of our users or others, or to a company that takes over ProdKit, which would have to honor this policy.
6. Cookies and local storage
We only use cookies that are strictly necessary for the service, so there's no cookie banner. There are no analytics, advertising, or third-party cookies on prodkit.cloud.
- Session cookies (named sb-<project>-auth-token) keep you signed in. They're set when you sign in and last until you sign out or for up to 400 days. Only our server can read them.
- A GitHub sign-in cookie (sb-<project>-auth-token-code-verifier) holds a one-time check value while you sign in with GitHub, and is removed when sign-in completes.
- Your theme choice (light or dark) is saved in your browser's local storage and never sent to us.
Stripe's checkout and billing portal pages are on Stripe's own domain and set Stripe's cookies, under Stripe's privacy policy. Because we don't track you across sites, the site works the same whether or not your browser sends Do Not Track or Global Privacy Control signals.
7. How long we keep data
- Account and project data: until you ask us to delete your account. Disconnected projects stay with the account, and after an account is deleted we keep only its project names in image URLs, so those URLs can't be given to anyone else.
- Request logs: 35 days.
- Sign-in records (session IP address and browser): until you sign out or your account is deleted.
- Monthly usage totals, and the image paths and sizes counted toward each month's bill: while your account exists, as the record behind your invoices.
- Rate-limit counts: each one matters for an hour or less, and old ones are cleared automatically.
- Transformed images: Cloudflare's caches hold copies for up to 30 days, and stored copies in R2 expire 180 days after they're created. Email us to have a project's stored copies removed sooner.
- Billing records: Stripe keeps invoices and payment records for as long as tax and accounting law requires, even after your account is deleted.
- Support email: while it's useful for helping you, unless you ask us to delete it.
- Hosting logs: up to 30 days.
8. Security
Everything is served over HTTPS. Sign-in uses one-time codes, so there are no passwords to leak. Session cookies can't be read by scripts, database access rules let each account read only its own data, and rate-limit keys are hashed. Only the people who run ProdKit can access production systems, using accounts protected by two-factor authentication.
No system is perfectly secure. If a breach affects your data, we'll tell you without undue delay, as the law requires. To report a security issue, email support@prodkit.cloud.
9. International transfers
We're based in the United States, and our providers store and process data mainly there. Cloudflare caches images in data centers around the world, close to the people viewing them. If you're outside the US, your data is transferred to the US. Where the law requires, those transfers rely on our providers' Standard Contractual Clauses or equivalent safeguards.
10. Your rights
You can ask to access, correct, delete, or export your personal data, or to object to or restrict how we use it. Email support@prodkit.cloud from your account's email address, or tell us how we can confirm the account is yours. We'll respond within 30 days, free of charge.
There's no self-serve account deletion yet, so email us. We cancel any paid plan and delete your account, projects, and usage data. Deleted data can remain in database backups until they expire.
- EU and UK: you have these rights under the GDPR and UK GDPR, and you can complain to your local data protection authority. We'd appreciate the chance to fix the problem first.
- California: you can ask what personal information we collect, use, and disclose, and ask us to correct or delete it. We collect these categories of personal information: identifiers (email address, and IP addresses in sign-in records and hosting logs), commercial information (plan and billing history), and internet activity (usage logs). We use them for the purposes in this policy and disclose them only to the service providers listed. We don't sell or share personal information for cross-context behavioral advertising or use sensitive personal information. We won't treat you differently for using these rights, and an authorized agent can make a request for you with your written permission.
11. Children
ProdKit is for developers and businesses. It isn't directed to anyone under 16, and we don't knowingly collect their data. If you think a child has given us personal information, email us and we'll delete it.
12. Changes to this policy
When this policy changes, we update the date at the top. For significant changes, we'll email account holders before they take effect.
13. Contact
Mythical Creature, LLC is responsible for your personal data. Email support@prodkit.cloud with any privacy question or request. The Terms of Service cover the rest of how ProdKit works.