Privacy Policy
Last updated: 1 October 2026
This policy explains what personal data Reglaze collects, why, and what your rights are. The data controller is [to be completed: legal name of the operator], [to be completed: registered address]. Contact: hello@reglaze.io.
1. Data we collect
| Data | Where it comes from | Why |
|---|---|---|
| Email address and a password hash (we never store the password itself) | You, when you sign up | Your account, login and service messages |
| Websites you add, briefs you write, the designs generated, and the plan and redesigns used | You, and the Service | Providing the Service |
| Screenshots and page structure of the websites you submit | The public pages of those websites | Generating and checking designs, previews and reports |
| Captures of pages behind your website's login (account area) — the page's HTML as it appeared on screen, which may include personal data shown there; emails and long numbers are replaced by default | You, with the capture bookmark, an upload, or a test account login you give us | Designing, checking and previewing your account area |
| A test account's username and password, if you choose that way of capturing | You | Signing in once to capture the pages you asked for; used in memory during that capture only and never stored or logged |
| Orders and payments: plan, amount, status, date and the payment provider's reference | You and the payment provider | Billing, accounting and tax obligations |
| IP address, browser user agent, request logs | Your browser | Security, preventing abuse (for example, limiting login attempts) and fixing errors |
| Website address and email from the “free preview” request form | You | Preparing and sending the preview you asked for |
We do not collect card numbers. When online payment is enabled, the payment provider processes payments on its own systems.
Screenshots of the websites you submit may show personal data that is published on those pages, for example names in reviews. We use it only to create the design and do not extract or analyse it. Only submit websites whose public pages you may have processed in this way.
2. Legal bases (GDPR / UK GDPR)
- Contract: your account, redesigns, previews, installation and billing.
- Legitimate interests: security, preventing fraud and abuse, keeping the Service working, and handling free-preview requests you send us.
- Legal obligation: keeping payment records for tax and accounting purposes.
3. Who processes data for us
| Provider | Purpose | Location |
|---|---|---|
| OVH | Server hosting and storage | United Kingdom / EU |
| Anthropic, PBC | AI processing of screenshots, page structure and briefs to generate designs | United States |
| Payment provider (when online payment is enabled) | Processing payments | Named here before activation |
| Email provider (when service emails are enabled) | Sending account and preview emails | Named here before activation |
We do not sell personal data, do not use advertising trackers and do not run third-party analytics on reglaze.io. Where data is transferred outside the UK or EEA, for example to Anthropic in the United States, it is protected by the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.
4. How long we keep data
- Captured account-area pages: until you delete them in your cabinet, remove the website, or delete your account. Copies used by a finished design are kept with that design.
- Account data, websites, designs and screenshots: while your account exists. When you delete your account, we delete its websites and designs, and remove the account's email and password within 30 days.
- Payment records: for as long as tax and accounting law requires, which is usually up to 7 years. These records are kept even after the account is deleted.
- Temporary files for AI processing: deleted automatically after 3 days.
- Login sessions: 30 days, or until you log out.
- Server logs: kept briefly and rotated automatically, usually within a few weeks.
- Free-preview requests: up to 12 months, unless you ask us to delete them sooner.
5. Cookies and local storage
reglaze.io uses two cookies: axio_s, which keeps you logged in, and axio_lang, which remembers the language you chose for our pages. Both are strictly necessary for the Service to work as you asked, so no consent banner is required. Preview pages store a single setting in your browser's session storage, axio-off, which remembers the Before/After toggle until you close the tab.
Fonts for our own pages are served from our servers. Preview pages are different: they load images, scripts and fonts directly from the website being previewed and from the fonts chosen for the design, such as Google Fonts. Those third parties receive your IP address and may set their own cookies under their own policies, just as when you visit the original website.
6. Your rights
Depending on where you live, you can ask us to give you access to your data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. You can delete your account yourself in Account, or email hello@reglaze.io. We reply within one month. You may also complain to your data protection authority, such as the ICO in the UK or the supervisory authority in your EU country.
7. Security
Data is encrypted in transit (HTTPS). Passwords are stored as salted scrypt hashes, sessions use random tokens that are stored only as hashes, and access to production systems is restricted. No system is perfectly secure. If a breach affects your data, we will notify you and the authorities as the law requires.
8. Children
Reglaze is a business tool and is not intended for anyone under 18. We do not knowingly collect children's data.
9. Changes
We will post changes on this page and update the date above. If a change is material, we will tell registered users by email or in the Service.
Questions about this document: hello@reglaze.io