ImagineSiteImagineSite

Legal

Privacy Policy

This explains what we collect, where it goes, how long we keep it, and how to get it deleted. It describes the system we actually run — including the parts that are less tidy than we would like.

Effective and last updated: July 25, 2026

Plain note: this is the studio's own policy, written by us. It is not legal advice, and no lawyer has reviewed it. If you need advice about your own obligations, talk to a lawyer.

If you read one section, read §06. Every project's brief — including your name and email — is sent to an AI provider. Nothing else in this product tells you that: your finished website never mentions AI, and our emails are deliberately stripped of tool names. This page is the only place it is disclosed, so it is disclosed here in full.

01

Who we are

ImagineSite (ImagineSite) is a one-person independent web studio in the United States. We design, build, publish and support small-business websites. We are the party responsible for the personal information described here — the “controller”, if you want the legal word for it.

To be completed before this page is relied on: registered legal name Peyton Christopher Schlicht, mailing address [[POSTAL ADDRESS]]. These are not in our codebase and we will not invent them. Under California law (Bus. & Prof. Code §17538) a mailing address has to be shown to buyers before payment, so this is a real gap, not a formality.

Contact for anything in this policy — questions, corrections, access requests, deletion requests: pschlicht12@yahoo.com. That address is read by the founder. There is no support team behind it, and there is no separate data-protection officer — this studio is one person, which is both the best and the worst thing about how your data is handled here.

02

What we collect

Everything below comes from you, except the consent record and the activity timestamps, which we write automatically.

  • At checkout: your name, your email address, and your business name if you give one. If you start a checkout and do not finish it, we still have that. We create your project record when you begin, before any payment, so you can come back to it — and so we can send the “you left something unfinished” reminder described in §12.
  • When you tick the two consent boxes at checkout: your IP address and your browser's User-Agent string. We record them on our server at that moment, together with which boxes you ticked, the version of the wording you were shown, the plan, the up-front price, and the monthly amount we disclosed. This is the one place in the whole system that stores an IP address — we do not log them anywhere else. It exists as proof that you agreed to a recurring charge, which is what settles a chargeback or a billing dispute. Both fields are best-effort: the IP may be your network's or a proxy's, and the User-Agent is whatever your browser reports.
  • Your project brief: your business name, industry, description, services, target audience, competitors, inspiration links, domain situation and domain name, colour and style preferences, the sections you want,and the free-text “add your specifics” box.
  • Contact facts to publish on your website: your business phone number, the public email address you want shown, your business address, your opening hours, and links to your social profiles (six platforms are offered in the form — Instagram, Facebook, TikTok, X, LinkedIn, YouTube — and up to ten links are stored). These exist to be printed, word for word, on your finished site.
  • Uploads: your logo, up to eight photos, and up to eight documents — images (JPG, PNG, WebP, GIF, SVG) and PDF, DOC, DOCX, PPTX, XLSX, TXT or ZIP files, each up to 10 MB. Read §07 before you upload anything: where these end up is unusual.
  • Anything you write to us: revision requests; support messages (your name, email, a subject and up to 5,000 characters of message, attached to your project); and enquiries sent from the Signature enquiry form (name, email, business, budget, timeline, message). The enquiry form is rate-limited and has a hidden spam trap; the form does not require a payment, so anyone can send one.
  • Billing records: Stripe's identifiers for your customer, payment method, checkout session and subscription, plus the amounts, the payment status, and whether your monthly support plan ($25/mo on Pro, $50/mo on Signature) is running. Never your card number — see §03.
  • Activity timestamps: when your project was created, when it was activated, and when you last opened it. That last one updates on every visit and is visible to the studio in our admin console — so we can see roughly when you were last in there. It is not used to target anything at you.

03

What we do not collect

  • No accounts, no passwords. There is nothing to sign up for and no password of yours to steal from us.
  • No analytics, no advertising trackers, no tracking pixels — not on this site, and not inside the emails we write. We cannot tell whether you opened one.
  • No card numbers. Card details are typed on Stripe's own pages and never reach our servers. We hold Stripe's reference ids, not your card.
  • No IP logging anywhere except the consent moment described in §02. We do not log IP addresses on page views, on uploads, or in the dashboard. Our hosting and database providers keep their own server logs as part of running their platforms; those are theirs, we do not control them, and we do not use them.
  • No location data, no device fingerprinting, no cross-site tracking. We do not know what else you browse and we have no way to find out.

04

Why we use it

Each of these is a separate purpose. If you are in the EEA or the UK, the bracketed phrase is the legal basis we rely on for it; §11 explains what that gets you.

  • To build and support the website you bought — the brief, the uploads, the revisions, the support messages. [Performance of our contract with you.]
  • To take payment and manage your subscription — through Stripe. [Performance of our contract with you.]
  • To prove you agreed to a recurring charge — the consent record, including the IP and User-Agent from §02. [Our legitimate interest in being able to defend a chargeback or dispute, and in complying with automatic-renewal law.]
  • To answer you — support replies and enquiry responses. [Performance of our contract, or our legitimate interest in replying to someone who wrote to us.]
  • To send the two “you left something unfinished” reminders described in §12. [Our legitimate interest in following up an order you started — and you can switch these off with one click.]
  • To keep tax, accounting and payment records. [Legal obligation.]

We do not use your information to make any automated decision that has a legal or similarly significant effect on you. The AI in §06 writes websites; it does not decide anything about you.

05

Who we share it with

We do not sell your personal information — not for money, not for anything else of value — and we do not share it for cross-context behavioural advertising. We have never done either, and there is no code in this product that could. We also do not collect the categories that count as sensitive personal data under US state privacy laws, and we ask you in §06 not to send us any.

These are the companies that handle your data because they run part of the service. Each is used to provide their service to us and for nothing else.

  • Stripe — payments, your saved card, invoices and the billing portal. Stripe receives your name, your email and your order details. Stripe also uses payment data for its own fraud prevention and legal compliance, which makes it an independent controller for that purpose, not just our processor.
  • Supabase — our database, our file storage and the server-side functions that run the app. Every piece of your project lives here, in the United States (Supabase's us-east-2 region).
  • Netlify — hosts this website. It also runs the background function that relays our AI requests and holds the API key, so your brief content passes through Netlify on its way to and from the model. Netlify's form handling may also receive messages your own visitors send you, once your site is live — see §08.
  • Anthropic — the AI that plans every website and generates Pro ones. §06 is the full disclosure and it is the one that matters most.
  • Resend — our email provider. It receives your email address, your name, and the contents of our messages to you, including the private link back to your project. As of the date at the top of this page it has received none of that, because the email channel is not switched on yet. §12 explains what that means and what happens when it is.
  • Our own notification channel ([[CONFIRM: DISCORD / SLACK / NTFY]]) — when something happens on your project, the studio gets a message in a chat app. Those messages are not redacted. They carry your name, your email, your enquiry or support text, and your full brief. When a Pro website is finished and you have chosen a version, the finished website file goes with it as an attachment; for hand-built work the message carries the design brief and prompt in the body instead. It is how one person keeps track of the work. You should also assume your brief exists in the founder's email inbox and as a working copy on the founder's computer.

Wired up but switched off: the code has a seam for an outside image-enhancement service (Higgsfield) that would receive the public links to your uploaded photos. It has no key configured and does nothing today. If it is ever turned on, this list gets updated before it is, not after.

Contractual protection: each provider above is intended to be bound by a data processing agreement that limits them to acting on our instructions. [[CONFIRM: DPAs EXECUTED WITH STRIPE, SUPABASE, NETLIFY, RESEND, ANTHROPIC]] — until those are actually accepted, this sentence describes the intention rather than a signed fact, and we would rather say so than imply otherwise.

We also disclose information if the law requires it, or to establish or defend a legal claim. If the studio were ever sold or transferred, customer records would move with it, and we would tell you before that happened.

This list does double duty. It is also the subprocessor list for the website we run for you — the one your own visitors use. If you need the commitments that go with that (what we may do with your visitors' data, notice before we add a provider, help answering a visitor's request), they are in section 19 of the Terms. Keeping the names here and the promises there means one list to maintain rather than two that drift apart.

06

How we use AI

Every project's brief is sent to Anthropic's Claude API — Pro and Signature alike — to produce the design plan your website is built from. That includes your own contact name and email address.

What goes to Anthropic:

  • On both tiers, at the planning stage: your business details, your free-text answers, the contact facts you asked us to publish, links to your uploaded files, and your name and email address as the person we are building for.
  • On Pro, where the website itself is generated: the derived build brief and the full HTML of your website.
  • When you ask for a change: your revision request in your own words, along with the site it applies to.

Anthropic is our processor for this. It handles the data to give us the service and not for its own purposes. Anthropic's commercial API terms state that inputs and outputs are not used to train its models by default. That is Anthropic's commitment in Anthropic's terms — we rely on it, we have no way to verify it from our side, and we would rather tell you where the assurance comes from than present it as our own guarantee.

It is retained for about 30 days. Anthropic keeps API inputs and outputs for a limited period under its standard retention. Our requests deliberately do not use zero-retention mode, so that period applies to your brief. We will not tell you your brief vanishes the moment it is processed, because it does not.

Please do not put other people's personal information, or anything sensitive, into your brief, your uploads or your revision requests — customer lists, staff records, health details, financial account numbers, government ID numbers. Nothing in this service needs any of it, and everything you put in the brief goes to the places described in this section and in §05.

What differs between the tiers is what happens next. Pro goes on to have the website itself generated by the model. Signature does not: a person designs and builds your site by hand from that plan, and AI tools may still be used as a drafting aid along the way.

Your finished website will not mention any of this, and neither will our emails. That is a deliberate product decision — you bought a website, not a tour of our toolchain — but it means this page is the only place you are told. Which is why it is told here in full, rather than in a sentence at the bottom.

07

Files, previews and links

Three things about how access works here, because they are unusual and you should know them before you upload anything.

  • Your uploads and your website previews are stored in public-but-unlisted storage. The links are long and unguessable, are not listed anywhere, are not indexed by search engines, and preview pages are served with instructions telling search engines to stay away and browsers not to leak the address. But there is no password on them, and anyone who has a link can open it. We will not describe them as private, because they are not. Treat a preview link, and anything you upload, as something you would be comfortable handing to whoever you send it to — and to whoever they forward it to.
  • Those links do not expire, and you cannot revoke them. There is no button that kills a preview link and no automatic expiry. The same link is reused across revisions, so an old link always shows the newest version of your site — convenient, and worth understanding before you share one widely. Each of the up to three Pro versions has its own separate link. The links to your uploaded images are also embedded in your generated website, so once your site is published those files are public in the ordinary sense of the word.
  • Your project id, and the private resume link we send you, are the keys to your project. Because there are no accounts, whoever holds them can see your brief, your uploads, your previews and your billing status. Keep those to yourself, and tell us if you think a link has gone somewhere it should not.

You can remove or replace the logo, photos and files you uploaded, yourself, from your dashboard at any time — that is the only deletion you can perform without asking us, and it does delete the stored file. It cannot pull back copies that have already gone elsewhere: anything already sent to the AI provider, already delivered to the studio's notification channel, or already built into a published site stays where it is until those places age it out or we remove it by hand.

08

The website we build for you

This part is about your finished website, not about browsing ours. Once your site is live, you are the one operating it — its visitors are your visitors, and any privacy notice it needs is yours to publish. Here is what we know about how the sites we deliver behave, so you can write that notice accurately.

  • Fonts. The websites we build load their fonts from Google Fonts at the moment a page opens, which means your visitors' browsers make a request to Google — and Google receives their IP address as part of that. The same is true of the preview links in §07.
  • Contact forms. If your finished site has one, it is wired to the form handling of whatever host we publish you on — in practice Netlify's — so what a visitor types into it goes to that host and then to you. We will confirm which host and which handler when we publish, so you can name it correctly in your own policy. Not every site ships with a form: some are delivered with phone and email links instead.

On ImagineSite's own site, by contrast, fonts are bundled into the page at build time — your browser never contacts Google here. The difference is deliberate and worth knowing, because it means our site and your site do not have the same privacy footprint.

09

How long we keep it

Honestly: indefinitely. We keep project records, briefs, uploads, generated websites, every stored version and the full before-and-after history of every revision, so that we can support and rebuild your site years later. Our notification and admin records are append-only, which means the messages we queued about your project — including their contents, the payment links and the private links they carried — stay there too. Enquiries sent through the Signature form are archived rather than deleted.

Nothing expires on its own. There is no retention schedule and no automatic deletion anywhere in this system. The only deletion you can perform yourself is removing or replacing your own uploaded logo, photos and files.

The consent records described in §02 are kept for at least three years after our relationship ends — deliberately, and beyond the window in which a payment can be disputed. They are the evidence that you agreed to what you agreed to, and they are the one category we will not delete on request while that period is running.

You can ask us to delete your data by emailing pschlicht12@yahoo.com. A person then does it by hand, in our database and in Stripe. There is no automated purge and we are not going to pretend there is. We will complete it within 30 days. We will keep what we are required or entitled to keep — payment, tax and accounting records, the consent records above, and anything needed for a live legal claim — and we will tell you what was kept and why.

10

Security, and what happens if it fails

Plainly, here is what protects your information:

  • In transit, everything moves over encrypted (HTTPS/TLS) connections — your browser to us, and us to Stripe, Supabase, Resend and Anthropic.
  • At rest, your data sits in Supabase's managed Postgres and Storage, which Supabase encrypts at rest.
  • Our database tables are locked by row-level security and are not reachable from a browser at all. Everything the app does goes through server-side functions holding keys your browser never sees.
  • Card data never touches us. It is entered on Stripe's pages. We hold Stripe's reference ids and nothing else.
  • Generated websites are sandboxed when we show them to you, in a way that stops a preview from reading anything else in your browser.

And here are the honest limits.

  • Access is one person, and it is total. The founder is the only human with access, and the admin console — which is protected by a passcode, not by individual accounts — shows every customer's brief, contact details, messages and billing status. Whoever holds that passcode sees all of it. There is no team, no contractor, and no separate support tool with narrower access.
  • The studio's notification messages are not redacted (§05). Your name, email, brief and finished site files land in a chat app and stay in its history.
  • Holding a link is access (§07). Because there are no accounts, your project link and your resume link are the credential, and your uploads and previews sit behind unguessable but public links that never expire.

No system is perfectly secure, and we are not going to tell you this one is.

If there is a breach: if we learn that your personal information has been accessed by someone who should not have it, we will investigate, do what we can to contain it, and notify you without unreasonable delay — by email to the address on your project, and consistent with what the breach-notice law of your state or country requires. We will tell you what happened, what of yours was involved, and what to do about it. We will not sit on it while we decide whether it looks bad.

Found a vulnerability? Please tell us at pschlicht12@yahoo.com with “Security” in the subject line. We will not threaten you for reporting one in good faith, and we will tell you what we did about it.

11

Your choices and rights

Everyone, wherever you are. Email pschlicht12@yahoo.com to get a copy of what we hold about you, to correct it, or to have it deleted. We will respond within 30 days. It is a manual process handled by a person: there is no self-service export button and no deletion button, and we will not pretend otherwise. Read §09 first — it says what we cannot delete and why. We will not treat you worse, or charge you differently, for asking.

California. We are a small business that falls below the CCPA's thresholds, so those obligations do not currently apply to us. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not collect sensitive personal information as California defines it. We will honour reasonable access, correction and deletion requests from California residents anyway, on the same 30-day promise.

Texas, and other US state laws. Texas's data privacy law exempts small businesses from most of its requirements, and we expect to be one. The part that still binds a small business is the ban on selling sensitive personal data without consent — we do not sell any personal data at all, sensitive or otherwise, which is stated here so there is no ambiguity about it. Residents of other US states with privacy laws should email us; the manual process is the same one for everybody.

If you are in the EEA, the UK or Switzerland

We do not geo-block orders, so we may hold your data. The lawful bases we rely on are listed against each purpose in §04. In addition to access, correction and deletion, you can ask us to restrict how we use your data, to give you a portable copy of what you provided (we will produce it by hand — see §09), and to object to any use we base on legitimate interests, including the two reminder emails in §12. Where we rely on your consent, you can withdraw it at any time without affecting what we did before you withdrew it.

You also have the right to complain to your data protection supervisory authority — in the UK, the Information Commissioner's Office. We would rather you told us first so we can fix it, but that is your right and not conditional on asking us.

Two honest notes. This studio has no EU or UK representative and no data protection officer; the founder is the contact for all of this. And §09 is not a European retention schedule — it is an admission that there isn't one. If either of those matters to your business, weigh it before you send us a brief.

12

Emails we send

As of the date at the top of this page, our customer email channel is not switched on. Our email provider has no key configured, which means no email has ever been sent to a customer from this system — not a receipt, not a “your site is ready”, not an invoice. The messages are written and held in a queue. When the key is configured, that queue delivers, including messages written weeks or months earlier. We are telling you this because a policy that quietly promised email you never got would be worse than an awkward paragraph.

Once it is on, this is what we will send about your project and your payments:

  • Payment confirmations, and status updates as your project moves along.
  • Your build invoice and payment link, plus automatic reminders 3 days and 7 days later if it has not been paid.
  • “You left something unfinished” reminders — at most one each, triggered by how long ago your order was created and whether your questionnaire has been submitted.
  • Notice if a payment fails, and replies when you contact support.
  • A once-a-year reminder, while your monthly support plan is running, telling you the amount, that it renews automatically, and how to cancel. It is not a bill and needs nothing from you.

There is no marketing list. We do not sell or rent your address, we never add you to anything, and our emails contain no tracking pixels — we cannot tell whether you opened one.

The two “you left something unfinished” reminders carry an unsubscribe link. Click it and we stop sending them, immediately and permanently. Those are the two messages that chase you rather than answer you, so they are the two you can switch off. They are also blocked in code until a real postal mailing address is configured — [[POSTAL ADDRESS]] — because US anti-spam law requires one on that kind of message, and we would rather send nothing than send it non-compliantly.

Everything else — payment confirmations, your build invoice and its reminders, failed-payment notices, the yearly subscription reminder, and replies to things you sent us — is about money or about work you bought, and we will keep sending those while you have a live project. If you want out of those too, email pschlicht12@yahoo.com and say so; we will do what we can, but we may still have to send notices the law requires about a payment you owe or a subscription you hold.

Separately, Stripe may email you a card receipt from its own system when you pay. That is Stripe's message, sent under Stripe's settings, and it is not affected by any of the above.

13

Cookies and Do Not Track

Our own code sets no cookies. Your project is remembered in your own browser's local storage (a key called vela:order:v1, holding your recent orders and the private links to them), which stays until you clear it, and in the resume links we send you. The founder's admin passcode is held in session storage and disappears when the browser closes. An older version of this app also used a browser database called vela; nothing writes to it now, but if you used the site long ago it may still be sitting in your browser. Clearing your browser storage removes your end of all of this; email us for a fresh link.

One caveat we will not paper over: our hosting and database providers run their own platforms underneath us. They may set their own operational cookies and they keep their own request logs, which include IP addresses, to deliver and protect the service. We do not control those, we do not read them, and we do not use them to track anyone — but “no cookies at all, anywhere” would be a claim about someone else's infrastructure that we cannot make.

Stripe's checkout and billing pages set Stripe's own cookies for payment processing and fraud prevention. Those are governed by Stripe's privacy policy.

Do Not Track: some browsers send a “Do Not Track” signal. There is no agreed standard for how a site should answer it, and we do not respond to it — mainly because we are not tracking you in the first place. We do not allow any third party to collect personally identifiable information about your activity across other websites through our site.

14

International transfers

We operate from the United States, and our data lives there: the database and file storage are in Supabase's us-east-2 region. Our other providers process data in the United States and in the other regions where they operate. If you use this service from outside the US, your information is transferred to the US and handled there.

Where a transfer out of the EEA or the UK needs a legal safeguard, we rely on the mechanisms in our providers' own agreements — Standard Contractual Clauses, the UK Addendum, and the EU–US Data Privacy Framework where a provider is certified under it. As noted in §05, those provider agreements still need to be formally accepted on this account: [[CONFIRM: DPAs / SCCs EXECUTED]].

15

Children

This service is for adults running businesses. It is not directed to children, we do not knowingly collect personal information from anyone under 13, and there is nothing here aimed at them. If you believe a child has given us data, email us and we will delete it.

16

Changes to this policy

If we change this policy in a way that matters, we will update the date at the top of this page — that date is always the version you are reading. Smaller corrections, like a clearer sentence or a new provider name, appear here with a new date as well.

We will also email customers whose project is active and whose email address we hold, once the email channel described in §12 is switched on. Until it is, the date on this page is the only notice we can honestly promise, so it is worth checking here before a renewal if any of this matters to you.

Questions about any of it: pschlicht12@yahoo.com.