Privacy Policy
Last updated: 3 June 2026
This Privacy Policy explains how SU Studio (CVR: 46441311) collects, uses, and protects your information when you use BrushLens (brushlens.app).
The short version
- Your reference photos never leave your device. We never see them, store them, or process them on our servers.
- We collect only the information needed to give you access and accept payment.
- We don't sell or share your data with third parties for advertising.
- You can delete your account and data at any time.
What we collect
Account information
When you sign in or create an account, we collect:
- Email address - to identify your account and send service messages
- Name and profile picture (if provided via Google, Facebook, or Patreon login) - displayed in the app
- Authentication provider - e.g. whether you signed in with Google, Facebook, email, or Patreon
Payment information
If you subscribe to BrushLens, payment is processed by Stripe. We do not see, store, or have access to your card details. Stripe handles all payment data under their own privacy policy (stripe.com/privacy). We store only:
- Your Stripe customer ID (a reference, not your card)
- Your subscription status (active, cancelled, etc.)
- Your subscription plan and expiration date
Your reference photos and analysis data
Your photos and the analyses you perform stay on your device only. They are processed locally by your browser and stored in your browser's local storage and IndexedDB. We do not upload, store, or have any access to them.
Technical data
We use Vercel as our hosting provider, which automatically logs basic technical information about visits to brushlens.app (IP address, browser, page accessed) for security and performance monitoring. We do not use this data to track individuals.
What we don't do
- We don't use third-party analytics or tracking pixels
- We don't show advertisements
- We don't sell or rent your personal information
- We don't process your reference images on our servers
How we use your information
- To provide access to BrushLens features
- To process subscription payments via Stripe
- To send transactional emails (login links, payment receipts, important account notifications)
- To respond to support requests
- To comply with legal obligations
Third-party services we use
- Stripe - payment processing
- Vercel - web hosting
- Upstash - encrypted database for user accounts
- Resend - transactional email delivery
- Google, Facebook, Patreon - optional sign-in providers (only if you choose to use them)
Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data
- Object to or restrict our processing
- Lodge a complaint with the Danish Data Protection Authority (Datatilsynet)
To exercise these rights, email hello@brushlens.app.
Data retention and deletion
We keep your account data for as long as your account is active. If you cancel your subscription, we retain your account record for 12 months in case you wish to return, then delete it. You can request immediate deletion at any time by emailing hello@brushlens.app from the email address associated with your account. We will delete your data within 30 days of receiving the request.
Children
BrushLens is not directed at children under 16. If you believe a child has provided us with personal information, please contact us.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to active subscribers.
Contact
Data controller: SU Studio (CVR: 46441311)
Email: hello@brushlens.app
← Back to BrushLens