Privacy statement
What we hold, and why
Stylaform stores the minimum needed to run your brand systems: who you are, which workspace you belong to, the brands you build and the pages you ask us to scan.
Last updated 18 August 2026
Who is responsible
Stylaform is the controller for the data described here. For anything in this statement, write to hello@stylaform.com.
What we collect
Account. Your email address, your display name if you set one, and the sign-in method you used. Passwords are stored only as a hash; magic-link sign-in stores no password at all.
Workspace and brand content. Everything you create: brands, tokens, rules, uploaded assets, exports and version history. This is your material and we treat it as confidential.
Sites you scan. When you point a scan at a URL we fetch those public pages and keep the measured values, the findings and a record of the scan. We do not sign in to your site and we do not collect data about that site's own visitors.
Activity and security records. Sign-in attempts, invitations, role changes, exports and invoice downloads, with a timestamp and the acting user, so a workspace owner can audit what happened.
Billing. Your plan, credit balance and ledger. Card details never reach us; Stripe holds them.
Why we may hold it
To perform our contract with you, which covers running the service, your workspace and your billing. To meet legal obligations, which covers invoices and tax records. And for our legitimate interest in keeping the service secure and abuse-free, which covers rate limits and the security log.
AI processing
Some features send content to an AI model: extracting a brand from a website, suggesting directions, and writing findings in plain language. What is sent is the page content or brand values relevant to that task, not your account details. Model providers act as our processors, and the content is not used to train their models.
Every AI call is metered against your workspace credits and recorded in the credit ledger, so you can see exactly what ran and when.
Who else processes it
Our hosting, database and email providers, our AI model providers, and Stripe for payments. Each acts on our instructions under a data processing agreement. We do not sell your data and we do not share it with advertisers.
Where it is kept, and for how long
Account and workspace data lives for as long as the workspace exists. Delete a brand and it goes with its assets and versions; close a workspace and we remove its content, apart from invoices and the records we must keep for tax purposes.
Scan results and activity records are kept while they are useful for auditing, then removed on a rolling basis. Backups age out on their own schedule.
Your rights
You can ask for a copy of your data, correct it, have it deleted, restrict or object to processing, and receive it in a portable form. Most of it is already exportable from inside the app: brands export as structured files and the credit ledger exports as CSV.
Write to hello@stylaform.com and we will respond within a month. If you think we have handled your data badly, you can complain to your national data protection authority.
Cookies and browser storage
Stylaform sets no advertising or analytics cookies. The cookie statement lists every item we store in your browser and why it is there.
Changes
When this statement changes materially we update the date at the top and show the notice bar again, so you are not left reading an old version.