Privacy Notice
Questions or privacy requests? Email mmcydesign@gmail.com.
Who we are
UIAudit is operated by Maksym Chervynskyi ("we", "us", "our"). We are the data controller responsible for the personal data processed through the UIAudit service.
Categories of personal data we collect
- Uploaded screenshot images and their technical metadata (file type, size).
- AI-generated audit output produced from your screenshots.
- Service usage data (free audit count, redeemed credits, audit history).
- Anti-abuse fingerprints (one-way hashed IP address and hashed user-agent string).
- Payment and billing data processed by Paddle (see below).
- Email address (if you purchase credits or redeem an access code).
Purposes and legal basis
- Delivering audit reports — we process your uploaded screenshots and generate AI analysis. Legal basis: performance of a contract (you request the service, we deliver it).
- Account and credit management — we track usage, credits, and session tokens to operate the service. Legal basis: performance of a contract.
- Abuse prevention — we generate hashed fingerprints from IP and user-agent to enforce free-trial limits and protect service reliability. Legal basis: legitimate interest in preventing fraud and abuse.
- Payment processing — payment data is collected and processed by Paddle (see below). Legal basis: performance of a contract.
- Transactional emails — we send purchase confirmations and access codes to your email. Legal basis: performance of a contract.
How we process data & third-party processors
- Anthropic — uploaded screenshots are sent to Anthropic's Claude API for AI analysis. Anthropic processes image data solely to generate audit output.
- Paddle — our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders and processes payment data, billing information, tax compliance, and invoicing on our behalf. See Paddle's Privacy Policy.
- Lovable / Supabase — application hosting, database, and backend functions.
Data retention
We retain your data only as long as necessary to provide the service:
- Audit results — retained for 12 months from creation, then deleted.
- Session and usage data — retained for 12 months from last activity.
- Anti-abuse fingerprints — retained for 12 months.
- Payment records — retained as required by applicable tax and accounting law (typically 7 years), managed by Paddle.
When data is no longer needed, it is deleted or anonymised.
Security measures
We implement appropriate technical and organisational measures to protect your data, including: encryption in transit (TLS), access controls on databases and infrastructure, one-way hashing of IP addresses and user-agent strings (never stored in plain text), and regular review of our security practices.
Your rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your personal data.
- Restriction — request that we limit processing of your data.
- Portability — request your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at mmcydesign@gmail.com. We will respond within one month.
Your choices and opt-out
- Stop processing — stop using the service at any time; no further data will be processed.
- Delete your data — email mmcydesign@gmail.com to request deletion of your audits, session data, and associated records.
- Email opt-out — we currently send only transactional emails (purchase confirmations and access codes), which are required to deliver what you bought. You can unsubscribe at any time using the link in any email or via our unsubscribe page.
- Cookies — manage or clear cookies via your browser settings. See our Cookie Policy.
International data transfers
Your data may be processed outside the European Economic Area and the United Kingdom. Specifically: Anthropic (United States), Paddle (United States, United Kingdom, EEA), and Supabase (United States, EU). Where applicable, these transfers rely on Standard Contractual Clauses or equivalent safeguards approved under GDPR/UK GDPR.
Right to lodge a complaint
If you are in the EEA or UK and believe we have processed your data unlawfully, you have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to address your concerns first — please email mmcydesign@gmail.com.
Important upload warning
Do not upload screenshots containing credentials, passwords, API keys, payment card details, or other confidential secrets.
Cookies
We use cookies to operate the service. See our Cookie Policy for details on what cookies we use and how to manage your preferences.
Contact
For privacy questions or to exercise your rights, contact: mmcydesign@gmail.com.