Legal
Privacy notice
The short version
What is stored in your browser
Local storage on this device holds:
- the palette you are currently working on;
- up to sixteen recently used colours;
- your light/dark theme preference.
None of it is transmitted anywhere. You can remove all of it from Settings or by clearing site data in your browser.
What is stored on the server
Only if you create an account:
- Account — your email address and an encrypted password, handled by Supabase Auth. Passwords are never stored or seen by Colorstruct.
- Profile — username, and optionally display name, bio and website.
- Palettes and collections — what you save, with their colours, roles, construction settings and visibility.
- Activity — likes, follows and reports you file.
- Operational logs — request and error records, kept short-term for reliability and abuse prevention. They do not contain palette contents or credentials.
Images
Image colour extraction happens entirely in your browser using the browser’s own image decoder and a canvas. The file is never sent to a server, never stored, and is discarded from memory when you choose another image or leave the page.
Cookies
Colorstruct sets no analytics or tracking cookies. Signing in sets a session cookie, which is HttpOnly, SameSite=Lax and Secure in production. It exists only to keep you signed in and is removed when you sign out.
Advertising
Colorstruct is free and supported by advertising. Ad slots are clearly labelled, reserve their space so nothing shifts, never overlay content, never play audio, and never appear inside the palette controls. Where a third-party ad network is enabled by the operator of a deployment, that network may set its own cookies and receive your IP address and page URL — its own privacy policy then applies alongside this one. No palette content, account information or image data is ever shared with an advertiser.
Sharing
Colorstruct does not sell personal data and does not share it with third parties except the infrastructure providers needed to run the service (hosting, and Supabase for the database and authentication), and where legally required.
Your choices
- Use Colorstruct without an account. Nothing about you is stored on a server.
- Change or remove your profile details at any time in Settings.
- Change a palette’s visibility or delete it at any time.
- Request deletion of your account and all associated data by emailing privacy@colorstruct.app. Deletion removes your profile, palettes, collections, likes and follows.
Children
Colorstruct is not directed at children under 13, and accounts should not be created by them.
Changes
If this notice changes materially, the date at the top changes and the change is described here. Continued use after that constitutes acceptance.
Contact
Questions about this notice: privacy@colorstruct.app.