No ads, no trackers, no analytics cookies, no selling data. Everything you make stays on your device unless you sign in and choose to save to the cloud or publish to the mag.
On your device (browser localStorage): your autosaved session, saved Looks, preferences like sound and colophon toggles, and · if you sign in · the authentication token that keeps you signed in. All of this is strictly necessary for the app to function, which is why there is no cookie consent banner: we set no optional or third-party cookies at all.
Crash and feedback reports: when the app crashes, or when you send feedback, a report is stored so problems can be found and fixed. It contains the error message, app version, an anonymous per-browser device id, browser and hardware characteristics (user agent, screen size, graphics renderer name, memory ceiling), the state of your document at that moment (counts and sizes of layers and pages · never the artwork's pixels), and a short trail of recent in-app actions such as "tool brush" or "fx riso". Reports contain no artwork, no email unless you type one into the feedback form, and are readable only by the editor.
Anonymous usage counters: the app counts, per day and for everyone together, how often features are used · "the pen tool was picked 143 times today", "the riso effect ran 51 times". These are single shared numbers with no user id, device id, or session trail attached; they cannot describe any person's activity, and they exist so development effort follows what people actually use.
In the cloud, only if you sign in: your email address (from Google sign-in or the email link), your chosen @username, your plan tier, projects you explicitly save to the cloud, and pieces you explicitly publish to CUTWORK MAG. Published pieces · image, title, tags, @username, effect trail · are public by design. Cloud projects are private to your account, enforced at the database level (row-level security).
Hosting by Netlify (serves the static site; sees standard access logs). Authentication, database and file storage by Supabase. Google sign-in involves Google as the identity provider. We add no other third parties, no ad networks, and no analytics services.
Settings → Download my data exports everything we hold about you as a JSON file. Settings → Delete my cloud data permanently removes your cloud projects and published pieces, including their stored files. To delete the account itself (email + sign-in record), write to mourya@i-studio.in and it will be removed within 30 days. Clearing your browser storage removes everything local.
If this policy changes materially, the new version appears here with a new effective date. Contact: mourya@i-studio.in.