Privacy
What we keep, and why.
Draft awaiting review by counsel. It is not final: the retention periods and the contact below may change before launch.
What we collect
Your briefs. What you type is used to style your looks and is stored with them, so you can come back, refine, save and share. It never goes in a web address, it isn’t shown to anyone who opens a link to your results, and it is sent to our AI provider, DeepSeek, to interpret the style — never to retailers.
Your account. Your email is used only to sign you in. Saves, Style DNA, receipts, creatives and share pages belong to your account. Public receipts and share pages show only what you chose to share, never your email.
Shopping. We record which product you opened, from which look, so we can count clicks and, when a retailer reports a sale, the commission. See how we make money.
Analytics. Events like “generation completed” or “look saved”. We don’t send your brief, your email or your exact size to analytics.
Fair use. To stop the free allowance being reset by clearing cookies, each style story made without an account counts against a scrambled form of your network address (a keyed hash, never the address), kept for seven days.
We don’t sell personal style profiles.
AI-generated content
Style Me Like uses artificial intelligence (DeepSeek) to interpret your brief and to write the headlines, stylist notes, look names and Style Receipt lines around your looks. That text is generated by AI: it can be wrong, and it is a suggestion, not professional advice. Products, prices, retailers, sizes and stock always come from retailer data, never from the AI.
Who processes it
- Cloudflare
- Runs the site (Cloudflare Workers), stores the share images we render (R2) and enforces rate limits. Sees your IP address and requests, as any host does.
- Supabase
- Our database and sign-in: your email address, your briefs and style stories, saves, Style DNA and receipts. Hosted in the United States (AWS us-west-2).
- Supabase Auth email
- Sends your sign-in link and code. We will name the email provider here once it is chosen.
- DeepSeek (our AI provider)
- Interprets your brief and writes the headlines, stylist notes and receipt lines around your looks. What it receives is the text of your brief and the style details needed to answer it, not your email address. Before your brief reaches it, we remove email addresses, phone numbers and web addresses, and it receives no account or user id. DeepSeek’s privacy policy says it processes and stores data in the People’s Republic of China.
- Anthropic (fallback, off) — draft line for counsel
- A backup AI provider we can switch on if DeepSeek is unavailable. It is off, and it only processes anything if we turn it on. If we ever do, your brief would be processed by Anthropic, with the same removal of contact details, and Anthropic would receive only an opaque id that it can’t link to your account.
- Cloudflare AI Gateway
- Carries our requests to DeepSeek. Payload logging is turned off, so the gateway doesn’t keep the text of your brief or the answer.
- PostHog
- Product analytics, when switched on: events like “look saved”, never your brief, email or exact size. Hosted in the United States. Off when your browser sends Do Not Track.
- Retailers and affiliate networks
- When you open a shop link, the retailer and its affiliate network see that visit, as with any link. We don’t send them your brief or your email.
How long we keep it
Your account and everything in it are kept until you delete the account. Style stories made without an account stay tied to that browser’s anonymous session id until you delete them with an account or ask us to. The network hash for fair use is kept seven days. Share images we render are deleted with your account.
Your choices and rights
Delete everything. Signed-in people can delete their account from the account page. That removes your briefs, style stories, looks, saves, Style DNA, receipts, creatives and share pages, the shop clicks and share activity recorded with them (including what you did before signing in on this browser), and the images we rendered from them. Product analytics events are not yet deleted automatically; ask us and we’ll remove them.
You can also ask us for a copy of your data, or to correct it. Turning on Do Not Track in your browser switches analytics off.
Cookies and browser storage
- sml_sid
- An anonymous session id, so the looks you make stay yours before you sign in. HttpOnly, 30 days.
- sml_aid
- An anonymous analytics id, so product metrics can be counted without knowing who you are. One year.
- sml_attr
- Where your visit came from (for example a Pinterest pin), for this browser session.
- sml_login
- Set when you ask for a sign-in email, so only this browser hands its anonymous history to your account. HttpOnly, one hour.
- sml_brief
- Set for five minutes when you tap “Make your own” on a share page, so the starter brief reaches the home page without going in the web address. Read once, then removed.
- sb-… (Supabase)
- Keep you signed in after you use a sign-in link or code.
- ph_… (PostHog)
- PostHog’s own id and settings, in a cookie and in local storage. Only when analytics is on and Do Not Track is off.
- sml_demo_user
- Demo mode only: the labelled demo account.
- sml:… (browser storage)
- In this browser only: your latest results for this tab, a save or receipt waiting for sign-in, a brief you are handing to Create, and Style DNA before you sign in.
Contact
A privacy contact address will be listed here before launch.