Privacy Policy
Effective: 10 August 2026. Last updated: 10 August 2026.
This Privacy Policy explains how [LEGAL ENTITY NAME] (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use Cadrly (the “Service”), including our website, application, and related APIs.
1. Data controller
The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS, COUNTRY].
Privacy: support@cadrly.com. Support: support@cadrly.com.
2. Scope
This Policy covers guests browsing the Service, registered users, and anyone who contacts us about the Service.
It does not cover third-party sites or services we link to. Those follow their own privacy policies.
3. Personal data we collect
Depending on how you use the Service, we may process:
- Account data: name, email, password (stored hashed), timezone, avatar if you upload one, and marketing email preference (opt-in / opt-out timestamps).
- Usage and content data: project specs, prompts, AI outputs you generate or store, presets, settings, and history tied to your account.
- Token and billing data: token packs, purchase history, package selections, and payment-related records. Card payments are handled by our payment provider (for example Stripe). We do not store full card numbers on our servers.
- Technical data: IP address, browser type, device or approximate region, timestamps, security logs, and CSRF/session identifiers.
- Abuse-prevention data: IP addresses and related signals used to limit free-token abuse.
- Communications: messages you send to support or legal contacts.
- Cookie and consent choices: your consent preferences and timestamps.
- Analytics data (only if you consent to Analytics): events such as pages viewed, feature use, referral source, device/browser info, and approximate location, including via Mixpanel when enabled.
4. AI processing and third-party models
Cadrly sends prompts and related specification data you submit to third-party AI providers (currently including DeepSeek, OpenAI for vision features such as Analyze, or successors we configure) to generate outputs.
Do not submit secrets, passwords, payment card data, special-category personal data, or confidential third-party information you are not allowed to process.
Those providers process data under their own terms and privacy policies. We configure the Service to send what is needed for the AI action you request.
5. Purposes and legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on these bases:
- Contract: creating and managing your account, running the studio, delivering AI actions you request, managing tokens, and customer support.
- Legitimate interests: securing the Service, preventing fraud and abuse (including free-token abuse), improving reliability, and basic product analytics strictly needed for security and operations.
- Consent: non-essential cookies or storage (Preferences), Analytics (including Mixpanel when enabled), and optional marketing communications.
- Legal obligation: accounting, tax, and responding to lawful requests.
6. Cookies and similar technologies
We use cookies and local/session storage as follows:
- Essential: session authentication, CSRF protection, and security. Required for the Service to work and cannot be switched off in-product.
- Preferences (optional): remembering UI choices such as free-offer helper flags. Set only if you allow Preferences.
- Analytics (optional): product analytics including Mixpanel when integrated. Loaded only if you allow Analytics.
You can change optional choices anytime via Cookie settings in the app (Settings when signed in, or Cookies in the status bar as a guest).
Blocking essential cookies may prevent sign-in and core features from working.
7. Mixpanel and analytics
We may use Mixpanel (Mixpanel, Inc. and affiliates) to understand product usage, funnels, and reliability.
Mixpanel initializes only after you accept Analytics (or an equivalent consent). If you reject Analytics, we will not load Mixpanel for that browser profile under our consent controls.
Mixpanel may process identifiers, event properties, and device/browser metadata. See Mixpanel’s privacy documentation for subprocessors and retention.
You can withdraw Analytics consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
8. Marketing emails
If you opt in (for example via a separate checkbox at signup, or later in Settings), we may send product tips, feature updates, and offers to your account email.
Marketing email is optional and separate from account and transactional emails (verification, password reset, security notices, purchase receipts), which we send as needed to provide the Service.
You can withdraw marketing consent anytime in Settings → Account → Email preferences, or via the unsubscribe link in each marketing email. Withdrawal does not affect the lawfulness of processing before withdrawal.
When we use an email delivery provider (for example Resend) for marketing, we share only what is needed to send and measure those messages (typically email and basic profile fields you provided), under our instructions.
9. Who we share data with
We share personal data only as needed:
- Infrastructure and hosting providers that store or process Service data on our behalf.
- AI model providers that process prompts and specs to return generations.
- Payment processors (for example Stripe) for top-ups.
- Analytics providers (for example Mixpanel) when you consent to Analytics.
- Email delivery providers for transactional mail and, if you opt in, marketing mail.
- Professional advisers (legal, accounting) under confidentiality.
- Authorities when required by law or to protect rights, safety, and the Service.
We do not sell your personal data.
10. International transfers
Providers may process data in countries outside your own, including the United States or other jurisdictions.
Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms offered by our vendors.
11. Retention
We keep personal data only as long as needed for the purposes above, including:
- Account data: for the life of the account, then deleted or anonymized within a reasonable period after closure unless law requires longer retention.
- Projects, history, and presets: until you delete them or close the account (subject to backups for a limited time).
- Token and transaction records: as needed for accounting, disputes, and legal obligations (often several years).
- Security and abuse logs (including IPs tied to free-token claims): for a limited period consistent with fraud prevention.
- Analytics events: according to our analytics provider settings and your consent status.
- Marketing preference records: as long as needed to honor opt-outs and demonstrate consent history.
12. Security
We use technical and organizational measures appropriate to the risk (for example HTTPS, hashed passwords, access controls, session security).
No method of transmission or storage is fully secure. Keep your credentials confidential.
13. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object, port data, and withdraw consent.
To exercise rights, email support@cadrly.com. We may need to verify your identity.
You may lodge a complaint with your local supervisory authority (for example the ICO in the UK, or your EU member state DPA).
14. Children
The Service is not directed to children under 16 (or a higher age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
15. Changes
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, give additional notice.
Continued use after changes take effect counts as acceptance where permitted by law. Where consent is required, we will ask again.
16. Contact
Questions about this Policy: support@cadrly.com.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS, COUNTRY].