Privacy Policy

Last updated: May 24, 2026

This Privacy Policy describes how FindPreset processes personal data when you use our website and Service.

1. Data controller

Controller: Ing. Radek Svoboda, OSVČ
IČO: 02393131
DIČ: CZ9307155099
Registered address: Slovanská 1870, 684 01 Slavkov u Brna, Czech Republic
Email: support@findpreset.com

We are not legally required to appoint a Data Protection Officer under Article 37 GDPR; the contact above serves as the privacy contact.

You have the right to lodge a complaint with the Czech data protection authority:
Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic — www.uoou.cz

2. What we collect and why

DataSourcePurposeLegal basis (GDPR Art. 6)
Email addressYou (signup)Account identity, service communicationsContract performance (Art. 6(1)(b))
Name (if provided by social login)Google OAuthDisplay in your accountContract performance
Uploaded imagesYouAI or EXIF processing to generate presetsContract performance
Generated presets and thumbnailsService processingHistory feature, recent extractions displayContract performance
IP address, user agentBrowserSecurity, abuse prevention, basic logsLegitimate interest (Art. 6(1)(f))
Usage analytics (page views, events)Google AnalyticsImproving the ServiceConsent (Art. 6(1)(a))
Subscription status, payment emailLemonSqueezy webhooksService entitlement and access controlContract performance

We do not sell, rent, or trade your personal data.

3. Image handling specifically

AI mode: your image is transmitted to Anthropic, PBC (USA) for processing via the Claude API. Anthropic's API terms state that they do not train models on customer API inputs and retain inputs only for limited abuse-detection purposes (typically not exceeding 30 days). We store a 200×200 pixel thumbnail of the image in our database for the "recent extractions" feature, alongside the generated preset. You can request deletion at any time.

EXIF mode: processing happens entirely on our server. The image is not transmitted to any AI provider. The same thumbnail storage applies.

Original full-size images are never retained. They are discarded immediately after processing completes.

4. Third-party processors

We rely on the following processors who handle personal data on our behalf under Data Processing Agreements (DPAs):

ProcessorRoleCountryTransfer mechanism
Supabase Inc.Database hostingUSAStandard Contractual Clauses
Clerk, Inc.AuthenticationUSAStandard Contractual Clauses
Anthropic, PBCAI processingUSAStandard Contractual Clauses
Vercel Inc.Hosting and edge networkUSAStandard Contractual Clauses
Lemon Squeezy Inc.Payment processing (merchant of record)USAStandard Contractual Clauses
Google LLCAnalyticsUSAStandard Contractual Clauses

Standard Contractual Clauses (SCCs) are the EU Commission-approved mechanism for transferring personal data to countries without an adequacy decision under GDPR Article 46.

5. Retention

  • Account data: retained for the lifetime of your account, plus 12 months after deletion for legal and accounting purposes.
  • Generated extractions in history: retained while subscription is active plus 90 days after cancellation. Deleted on earlier request.
  • Image thumbnails: retained for 30 days, then auto-deleted.
  • Original images: not retained — discarded after processing.
  • Invoicing data (via LemonSqueezy): 10 years, as required by Czech accounting law.

6. Your rights under GDPR

You have the right to:

  • Access your personal data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure ("right to be forgotten", Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability — receive your data in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, where consent is the legal basis (Art. 7)
  • Lodge a complaint with ÚOOÚ or your local supervisory authority

To exercise any of these rights, email support@findpreset.com. We will respond within 30 days.

7. Cookies

CookiePurposeTypeRetention
Clerk session cookies (__session, __clerk_*)AuthenticationStrictly necessarySession
_ga, _gid (Google Analytics)AnalyticsStatistical (consent required)2 years / 24 hours

Strictly necessary cookies do not require consent under the ePrivacy Directive. Analytics cookies are loaded only after consent.

8. Security

We apply technical and organizational measures appropriate to the risk, including TLS encryption in transit, encryption at rest by our database provider, access controls limiting personal data to authorized personnel only, and a webhook signature verification layer to prevent forged requests.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice at least 30 days before they take effect.

10. Contact

Email: support@findpreset.com
Postal: Slovanská 1870, 684 01 Slavkov u Brna, Czech Republic