Privacy policy
Last updated: October 2, 2026
SolidVents is a parametric pattern generator that runs in your browser. Most of what you do in it never leaves your device. This policy explains the parts that do: what we collect, why, who helps us process it, how long we keep it, and what you can ask us to do with it.
The short version
- Your designs stay on your device unless you turn on cloud backup, submit a design to the community, or work through the API.
- We do not sell personal data and we do not show ads.
- We use Google Analytics to see how the tool is used. In the EU, the UK and Switzerland it only sets cookies after you accept, and anyone can switch it off.
- Payments are handled by Lemon Squeezy or Afdian. Card numbers never reach us.
- Write to solidvents@gmail.com to get a copy of your data or to have your account deleted.
Who we are
SolidVents is an independent project run by Yoshi Chen, an individual based in Taiwan (“we”, “us”). We are responsible for the personal data described here: the controller under the EU and UK GDPR, and the data collector under Taiwan’s Personal Data Protection Act.
This policy covers solidvents.com, the web app at solidvents.com/app, the REST API, the MCP server, and the solidvents-mcp package. You can reach us at solidvents@gmail.com.
What we collect
When you use the app without an account
- Your designs are saved in your browser’s local storage, or in a folder on your own disk if you choose one. They are not sent to us. Images you load as a background or a tracing reference are processed in your browser and saved inside the design on your device.
- Export limit. To count the three free exports a day, each export sends us your IP address, your browser’s user agent and a device identifier. The identifier combines a random ID stored in your browser with a hash of browser characteristics (screen size, language, time zone and how your browser draws a test image).
- Usage analytics through Google Analytics: pages you visit, features you use, events such as exports, your approximate location derived from your IP address, and your device and browser type. See Cookies and local storage.
When you create an account
- Sign-in details: your email address and password. The password is stored hashed by our sign-in provider and we cannot read it. If you sign in with Google, we receive your email address, name and profile picture from Google. The name is only used to pre-fill the credit field when you submit a design, and the picture is shown in the app’s header.
- Account status: whether you have Pro, your plan, subscription and order identifiers, when your current period ends, and when you signed up.
- Session ID: a random ID created at each sign-in, so that one account is active on one device at a time.
- Analytics ID: your account ID (a random string, not your email) and whether you are on the free plan or Pro are sent to Google Analytics, so we can tell how signed-in people use the tool across visits.
When you use the cloud repository (Pro)
- If you turn on cloud backup, the designs you save (all their settings, including any background image inside them), their names, your folders and their order are stored in our database. If you turn backup off or Pro ends, the designs are moved back to your browser and deleted from our database.
When you send us something
- Feedback: your message and the email address you give.
- Pro survey: your answers (industry, what you use SolidVents for, how you found it, what you used before, what you would like added), your email address and your language.
- Community submissions: the design and its thumbnail, its name, the credit name and description you write (both shown publicly once approved), an optional private note to us, your language, your email address, and when you agreed to the contributor declaration. When you like a design, we store which design you liked.
- Promotion program: your credit name, email address, the link to your public post, the platform and any suggestions you add.
- Emails you send to solidvents@gmail.com.
When you send the app link to yourself
- On a phone you can ask us to email you a link to open SolidVents on a computer. We store the address you enter and the page you sent it from, and send the email. The delivery log we use to limit repeat sends is deleted after 7 days. We do not use these addresses for newsletters.
- Before sending, and when you sign up, we check that the email domain can receive mail by asking Google Public DNS. Only the part after the @ is sent.
When you buy Pro
- Lemon Squeezy is the merchant of record: it collects your name, billing address and payment details under its own privacy policy. We pass it your account ID and email address so the purchase is linked to your account, and we receive your email address, customer, order and subscription identifiers, the plan and renewal dates.
- Afdian (for payments from mainland China): we receive your Afdian user ID, the order amount and the payment note you write, which contains your email address so we can activate Pro on the right account.
When you use AI design (MCP and REST API, Pro)
- Credentials: API tokens are stored only as a hash, with their first characters, the name you gave them and when they were last used. If you connect an AI app such as Claude, we store that authorization.
- Usage log: for each call, your account, the channel, the tool, which token or connected app was used, whether it succeeded and how long it took. Not the parameters you sent, your IP address or your user agent.
- Exports made through the API are also recorded in the export log above, with the IP address and user agent of the calling machine.
- Files: exports, mockup images and designs you open in the app are stored for up to 2 days so you can download them. Reference images you send for tracing or comparison are processed in memory and not stored.
Technical logs
- Our hosting and database providers keep technical logs of requests (IP addresses, times, errors). Some of our server logs, such as those for payment processing, include email addresses.
How we use it
- To run the service: sign-in, cloud repository, Pro features, the API, and emails you ask for. This is needed to provide what you signed up for.
- To keep it fair and safe: enforcing the free export limit and the one-device session, preventing abuse of the API, and keeping the service secure. This is our legitimate interest in keeping a free tier sustainable.
- To handle payments: activating Pro, matching orders to accounts and keeping the records tax law requires.
- To answer you: replying to messages, reviewing community and promotion submissions, granting rewards and publishing approved designs.
- To improve the tool: understanding which features are used and where people get stuck. In the EU, the UK and Switzerland this relies on your consent; elsewhere on our legitimate interest in improving SolidVents.
We do not sell personal data, use it for advertising, or make automated decisions about you that have legal or similarly significant effects.
Giving us personal data is optional. You can design and export without an account; sign-in, Pro, the cloud repository and the API need an email address, and we cannot provide them without it.
Cookies and local storage
SolidVents does not set cookies of its own. Google Analytics sets two cookies (_ga and one starting with _ga_) to recognize a returning browser; they last up to two years.
- In the EU, the UK and Switzerland, Google Analytics does not set cookies until you accept them in the banner we show.
- Everywhere else it is on by default. You can turn it off below, by opening any SolidVents page with ?ga_optout=1 added to the address, or with Google’s opt-out add-on.
The app also stores things in your browser’s local storage that it needs to work: your sign-in session, the device identifiers described above, your designs, your language and interface preferences, and which notices you have already seen. They stay on your device. Clearing your browser data removes them, including any designs that only exist in this browser.
The welcome video in the app is embedded from YouTube in privacy-enhanced mode (from Bilibili if your browser is set to Simplified Chinese). Those services may store data in your browser under their own policies.
Who processes your data
We rely on these providers. Each only receives what it needs for its part:
- Supabase: database, sign-in and server functions. Our database is hosted in India. Privacy policy
- Netlify: hosting for the website, the API and the MCP server, in the United States. Privacy policy
- Cloudflare: DNS, content delivery and temporary storage of API files. Privacy policy
- Google: Analytics, Google sign-in if you use it, the email domain check, and storage for our database backups. Privacy policy
- Resend: sending emails, such as the app link you request and notifications to us when you send feedback or a submission. Privacy policy
- Lemon Squeezy: payments, as merchant of record. Privacy policy
- Afdian: payments from mainland China, only if you pay there.
This means your data is processed outside your own country, including in India, the United States and, for Afdian payments, mainland China. Where the law requires it, we rely on the safeguards these providers offer, such as standard contractual clauses.
We may also disclose data when the law requires it, or when it is needed to protect our rights or someone’s safety. If SolidVents is ever transferred to someone else, your data would go with it and remain covered by this policy.
How long we keep it
- Account: for as long as you have it. When you ask us to delete it, we do so within 30 days.
- Export log (IP address, user agent, device identifier): 30 days.
- Send-the-link delivery log: 7 days. The address record is kept until you ask us to delete it.
- API usage log: 180 days. API files: 2 days.
- Cloud designs: until you delete them, turn backup off or Pro ends. They are then moved back to your browser.
- Feedback, survey answers, promotion and community submissions: as long as we need them to handle the request. Approved community designs stay published until you delete them or ask us to.
- Payment records: as long as tax and accounting law requires.
- Google Analytics: event data is kept for the retention period set in our account, no longer than 14 months.
We keep periodic backups of the database in private storage that only we can access. Data you delete drops out of the next backup. Older backups are kept only to recover from data loss and are not used for anything else.
Your rights
You can ask us to:
- tell you what data we hold about you and give you a copy;
- correct or complete it;
- delete it, including your whole account;
- stop or limit using it, or object to how we use it;
- send it to you in a machine-readable form (EU and UK).
Write to solidvents@gmail.com from the address on your account, so we can confirm the request is yours. We answer within 15 days and complete corrections and deletions within 30 days. If you gave consent (for example to analytics cookies), you can withdraw it at any time; this does not affect what was done before.
Some things you can do yourself: your designs in the browser are under your control, you can edit or delete your community submissions under My submissions, revoke API tokens in the app’s settings, and cancel a subscription through the link in your Lemon Squeezy receipt email (or by writing to us).
If you think we have handled your data wrongly, please tell us first. You can also complain to the data protection authority where you live.
Security
Everything is sent over HTTPS. Database access rules make sure each account can only read its own data. Passwords and API tokens are stored only as hashes, card numbers never reach us, and administrative access is limited to the project owner.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authorities as the law requires.
Children
SolidVents is not meant for children under 13, or under 16 in the EU and the UK, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
When this policy changes we update the date at the top of the page. If a change is significant, we will announce it in the app or on the changelog before it takes effect. How SolidVents may be used is set out in the terms of service.
Contact
Yoshi Chen (SolidVents), Taiwan. Email: solidvents@gmail.com.
Questions about your data?
Write to us for a copy of your data, a correction, or to have your account deleted. Please send it from the email address on your account.
This policy is also available in eleven other languages from the language menu below. If a translation differs from the English version, the English version applies.