A clear description of the data SchemaCraft uses.
This notice is written around the current product architecture: authentication, hosted billing, bounded website inspection, saved workspaces and coarse product telemetry.
1. Controller and contact
Controller / provider: [LEGAL ENTITY NAME]
Registered address: [REGISTERED ADDRESS]
Registration ID: [REGISTRATION / COMPANY ID]
VAT / tax ID: [VAT ID / TAX ID — if applicable]
Privacy contact: [PRIVACY CONTACT EMAIL]
Effective date: [EFFECTIVE DATE]
2. Data processed
Account data: email address and authentication identifiers required to sign in and associate product work with an account.
Billing data: Stripe handles payment and subscription processing. SchemaCraft uses the billing identifiers needed to reconcile the selected plan and subscription state.
Saved product data: schemas, project metadata and agency workspace records that you explicitly save into the product.
Inspection data: when you ask SchemaCraft to inspect a URL, the server fetches the requested public webpage using bounded network controls. The returned HTML is treated as transient request data and is served with no-store cache headers; product telemetry records coarse audit events rather than the full page body.
Technical / abuse-prevention data: server-side rate limiting uses an IP-derived key for protected endpoints. This is used to protect availability and prevent automated abuse.
Local browser state: the current free-tier UI stores a daily generation counter in browser storage. This local counter is a product UX control and is not treated as proof of account entitlement.
3. Purposes and safeguards
We use the data above to provide authentication, save user work, reconcile subscription access, operate website inspection, measure coarse product events and protect the service from abuse.
Access to protected product records is scoped to the authenticated account through database row-level security and server-side entitlement checks. External website fetching is bounded by protocol validation, redirect limits, timeouts, response-size limits and private-address protections.
4. Service providers
Current product integrations include Supabase for authentication and application data, Stripe for billing and Google Gemini for AI-assisted generation. Those providers process data only as necessary for the relevant service operation and under their own terms and privacy documentation.
5. Your rights
Depending on applicable law, you may have rights including access, rectification, erasure, restriction, objection and data portability. You can start a privacy request by emailing [PRIVACY CONTACT EMAIL]. We may request enough information to verify the requester's identity.
6. Changes and retention
We retain account and workspace information for as long as needed to provide the service, maintain contractual and security records, and satisfy applicable legal requirements. Specific retention periods depend on the type of record and will be documented here as the production retention schedule is finalized.
This notice may be updated when the processing materially changes. The effective date above identifies the version currently intended for production.
This page describes the current product architecture and must be reviewed against the operator's actual legal identity, jurisdiction, retention schedule and contractual setup before launch.