Privacy Policy
Set ("we", "us", "our") operates the website setdesign.app. This policy explains what data we collect, how we use it, and your rights regarding that data.
We believe in collecting the minimum data necessary to provide the service. We do not run ads, do not sell your data, and do not use third-party analytics or tracking pixels.
Your work stays on your computer
Set renders in your browser. The images and video you place on the screens, your projects, and your exports are processed on your computer and are never uploaded to us. A saved project is a file on your disk. The recovery copy Set keeps between sessions lives in your browser's own storage on your device and never leaves it. The one exception is an AI assistant you connect yourself, below.
What we collect
- Email address, collected at checkout by Stripe, and when you sign in with an emailed verification code. Used to identify your purchase and to sign you in on another device. Verification codes are stored only as a hash and expire after ten minutes.
- Payment information, processed entirely by Stripe. We do not store credit card numbers, bank details, or other financial data on our servers. We receive a confirmation of payment status and your Stripe customer ID.
- Operational server logs: our licence API runs on Cloudflare Workers, which records short-lived operational logs (timestamps, request metadata, error events) used solely to keep the service running and debug failures. These are automatically deleted after a few days. We keep no activity logs in our database, and no browsing history or personal content is tracked.
The app itself sends nothing to us while you work, with two exceptions you switch on yourself. If you use the phone motion controller, the paired phone streams its orientation and its browser's user-agent through our relay to your own desktop for as long as that session is open. The relay passes those frames between your two devices and never stores them. If you connect an assistant, what it asks of Set passes through our relay too (below). Otherwise the app contacts our licence API only when you export, sign in, or buy a licence.
Connecting an assistant
You can connect an AI assistant to Set (Claude, ChatGPT, or another app that speaks the Model Context Protocol) and switch on Assistant in Set's sidebar. While you do, the assistant can read a description of the scene open in Set and ask Set for pictures of it. That description and those pictures pass through our API to the assistant you connected, and from there to the company that runs it, under that company's own terms and privacy policy. Our API relays them and does not keep them.
- Images or video an assistant sends to put on a screen are kept on our servers (Cloudflare R2) for up to a day, so your Set window can fetch them, and are then deleted.
- Exports an assistant asks for are rendered in your browser and saved to your computer, like any export. The assistant is shown a small picture of the result; the file itself is never uploaded to us.
- The connection itself: we keep a record that you allowed an assistant (its name, when, and an identifier derived from your account that is not your email) until you remove it in Set's Assistant card, or for three months after you allowed it, whichever comes first. After that the assistant asks you to allow it again. If the licence it was allowed under is refunded, the connection ends and its record is removed the next time the assistant renews it.
Only an assistant you allowed while signed in with your licence can use Set, and only while Set is open with Assistant switched on. You see every change it makes, and each one can be undone.
Cookies and local storage
We do not use authentication cookies. Your licence status is stored in your browser's local storage as a signed token, together with the last answer our licence API gave for it. When you connect an assistant, our API sets one cookie that ties the connection request to the browser that started it; it expires within ten minutes and is used for nothing else.
We use browser storage to save your preferences (theme, work area, whether Assistant is on) and the recovery copy of the project you are working on. This data stays on your device and is never sent to our servers.
We do not use advertising cookies, tracking cookies, or any third-party cookie-based analytics.
Third-party services
We use the following services to operate Set:
- Stripe: payment processing. Stripe Privacy Policy
- Cloudflare: hosting, CDN, DNS, the database that holds purchase records, and transactional email (receipts and verification codes). Cloudflare Privacy Policy
Everything the app loads (its code, the device models, the fonts) is served from our own domain; no request from the app reaches any other third party. Each service above has its own privacy policy governing how they handle data, and we encourage you to review them.
How we use your data
- To verify your licence and sign you in on another device
- To process your payment and activate your licence
- To provide customer support if you contact us
- To maintain and improve the service
We do not sell, rent, or share your personal data with third parties for marketing purposes.
Data retention
We keep your purchase record (email, payment status, Stripe identifiers) for as long as your licence exists; it is what lets you sign in on any device. If you request deletion, we will remove it within 30 days (note that deleting it permanently disables signing in with that licence).
Operational server logs are retained for approximately 3 days and then automatically deleted. Media an assistant sends to Set are deleted within a day; the record of a connected assistant is kept until you remove it, and for three months after you allowed it at most.
Payment records are retained by Stripe according to their data retention policies and applicable financial regulations.
Your rights
Under GDPR and similar data protection laws, you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: ask us to correct inaccurate data
- Erasure: ask us to delete your data ("right to be forgotten")
- Portability: receive your data in a structured, machine-readable format
- Withdraw consent: withdraw consent for data processing at any time
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. If you are in the EU or UK, you also have the right to lodge a complaint with your data protection authority.
Children
Set is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of Set after changes constitutes acceptance of the updated policy.
Contact
For privacy-related questions or data requests, email [email protected].