The short version: we store your sign-in email and your purchases, nothing else. Last updated August 2026.
Account. Signing in with Google gives us your email address and profile picture. That is the whole account record. We use the email to sign you in, to send purchase receipts, and to send the weekly email described below.
Purchases. Payments are processed by Stripe. Your card details go to Stripe directly and never touch our servers; we store only which assets or kits your account owns.
Server logs. Like every web server we keep short-lived access logs (IP address, requested URL, browser user agent) for abuse prevention and debugging.
Reduced-licence applications. If you apply for the student or regional price you upload one document that shows you qualify. It is stored outside the public web root, is visible to one reviewer and to nobody else, and is deleted the moment the application is decided, whether it is approved or declined. No copy is kept, and it is never published, shared or used for anything other than that decision. What survives the decision is the application itself: which of the two reasons you gave, the country and school you typed, what you wrote, and the answer.
No third-party analytics, no ad trackers, no fingerprinting, no selling or sharing of your data with anyone. Every cookie here is our own and is read by nobody else.
This is the complete list.
sess keeps you signed in and is set only once you sign in, and
after_login remembers for half an hour which page to return you to afterwards.
pf_consent remembers whether you said yes or no to the ones below, so we do not
ask again. pf_vid and pf_sid are measurement: one random id for the
browser and one for the current half hour. They hold a random number and nothing else, they
are not derived from anything about you, no other site can read them, and there is no profile
behind them. We use them to count visitors rather than page loads, and to see which page
somebody first arrived on before they opened an account.
Where we ask first. In the EEA, the UK and Switzerland, and anywhere we cannot tell, we set no measurement cookie until you accept. Decline and none is ever set. Elsewhere, where local law does not require the question, we set it without interrupting you. Wherever you are, if you decline we honour that: a refusal follows the person, not the country.
Our emails carry no tracking pixel and no click redirector, so we cannot tell
whether you opened one, and every link goes straight to the page it names. Links in the weekly
email do carry a tag saying which week they came from (utm_campaign), which lets us
count how many people came back from a given send. It is the same counting the rest of the site
does, it is not tied to your account, and stripping it from the URL changes nothing but the
count.
Always. Sign-in links, purchase receipts and replies to support threads you started. These go out whatever your settings say, because you asked for them.
Weekly, to free accounts. One email a week listing assets and kits published in the previous seven days, and only in weeks where something was actually published. Every one of them carries an unsubscribe link that works in one click, without signing in, and turning it off changes nothing else about your account. If a link ever fails, email [email protected] and it is done by hand. Paid accounts do not get it at all.
Want your account and its data deleted? Email [email protected] from the address you signed in with and it is gone.