Privacy Policy
The short version
Styles Gallery stores your account and your billing records, anything you deliberately send us — a newsletter signup, a message through the contact form — a log line for each request to our API, and the anonymous, cookie-free website analytics, both described below. That is the list. The gallery is a static website that needs no account at all. The extension does its work inside your own browser: the designs you pick and the sites you pin them to are stored locally in your browser's extension storage, not on our servers. We never collect your browsing history, and we do not sell or share your data with advertisers.
What we collect
Account information
When you create an account we store your email address, your name and avatar if your sign-in method supplies them (Google does; a magic link doesn't), and when the account was created. Sign-in uses Google OAuth or an emailed magic link — we never see or store a password.
Billing
Payments are processed by Stripe. We store your subscription status and your Stripe customer ID; your card details go to Stripe and never touch our servers. Stripe's handling of them is governed by Stripe's own privacy policy.
Newsletter
If you subscribe to product news, we store the email address you gave us, which page you gave it on, the IP address the request came from (the record that you consented, and when), and whether you have confirmed. Addresses collected before the extension shipped — when this list was a launch waitlist — are the same list under the same consent, and can leave it the same way. It is double opt-in: nothing is sent to an address that hasn't clicked the confirmation link, and every mail after it carries a one-click unsubscribe. We use the list for product news about Styles Gallery and nothing else, and we never sell or rent it.
Messages you send us
The contact form sends your name, email address and message to our support inbox, so we can answer you; we keep the thread as long as it is useful for support. The uninstall survey is the opposite — it has no email field and is not tied to your account or to any identifier: the reason you pick and the optional note are the whole message.
Server logs
Our API records one line per request so we can keep the service secure and debug it. Each line holds the time, the HTTP method, the API path (never the query string), the response status — and, when a request is refused, the short reason why — how long it took, a random request identifier, your IP address and browser user-agent string, and — if you were signed in — your user id and email address. It also records where the request came from: the origin it was sent from and the page it was made from, again without its query string — or, for a request from the extension or the gallery, which part of it made the request: the extension's panel opening, a background check that you are still signed in, signing out, or the gallery's sidebar checking whether you are signed in. These logs are kept for up to 90 days on the same EU infrastructure as the rest of the service. We also look at them in aggregate to understand how the product is used; they are not used to build a profile of you or shared with anyone.
Website analytics
This website — not the extension — counts page views with Umami, an analytics tool we host ourselves. It sets no cookies, stores nothing in your browser, and does not fingerprint you, so there is no banner asking you to agree to it and nothing to opt out of. It records which pages get read, which calls-to-action get pressed, roughly where in the world the visit came from and what kind of device it was — never who you are. Because we run it, your visit is not handed to an analytics company at all; the request does not even leave our own domain. We used Google Analytics until August 2026 and removed it. The extension itself sends no analytics of any kind.
Cookies
If you never sign in, we set no cookie at all. When you sign in we set a session cookie; it is what keeps you signed in, and the site does not work without it. Signing in also sets a few short-lived ones that only the sign-in uses: the CSRF token that protects the sign-in form, the page to return you to, and for Google, the sign-in state. Your browser also stores your theme and similar interface choices, which neither identify you nor leave your browser. That is the whole list — no analytics cookies, no advertising cookies, and no ad networks. It is also why this site has no cookie banner: every cookie we set is there to sign you in.
What the extension does — and doesn't — see
The extension applies design tokens to the page you point it at, in your browser, and nothing about that page is sent to us. Your picks — which palette, fonts and style you chose for which site — live in your browser's extension storage, along with the panel's own settings and — if you are signed in — a cached copy of your account's name, email, avatar and plan, refreshed whenever the panel opens so it still knows what you bought while you are offline. Pinning a site grants the extension permission for that one origin so it can re-apply your picks when the page reloads; unpinning removes the permission. Screenshots are taken and saved by your own browser, to the folder or clipboard you choose, and never pass through us. Font files are fetched by your browser directly from Google Fonts, not through us, and cached locally.
To know which site a tab is on, the extension reads the address of the tab you open the panel on, and of tabs on the sites it has permission for — the ones you pinned, or every site if you allowed all sites — to light its toolbar badge and re-apply your picks. That happens in your browser; addresses are never sent to us, and the only record kept is which sites your picks and pins belong to.
The extension makes exactly two kinds of network request: font files from Google, and one question to styles.gallery — whether you are signed in and what plan you are on, sent with your session cookie and a tag naming which part of the extension asked. There is no analytics, no telemetry and no page-content upload of any kind. Uninstalling opens our farewell page in a normal browser tab; the survey there is anonymous, and closing the tab sends nothing.
Account email is transactional only: magic links you asked for, a welcome note, payment-failure warnings, renewal reminders and a note when a subscription ends. The one non-transactional list is the newsletter above, which you have to confirm before it can reach you and can leave from any mail it sends. Delivery runs through our own mail service, which hands the message to Amazon SES for the last hop — so SES processes the recipient address and the message on our behalf. Bounce and complaint notices come back to us so we stop sending to dead addresses.
Your rights
From the Privacy tab in your settings you can export everything we hold about your account, or delete the account outright — both run immediately, with no request queue. The export is one JSON file covering your account details, how you sign in, your subscription and billing records, and your newsletter subscription if you have one; deleting the account removes all of it, that row included. There is no recovery window. Three things outlive it and none is ours to delete on request: the request logs above, which age out 90 days after the request that wrote them, and Stripe's record of any payment you made — Stripe retains what payment regulations require it to retain — and backups of the database, in Cloudflare R2 in Europe, which keep a copy of the deleted rows until they age out, at most 56 days later; we never restore a deleted account from one. One more is kept on purpose: if mail to your address ever bounced or drew a complaint, our mail service keeps a one-way hash of the address so it is never mailed again, and Amazon SES keeps its own list of such addresses. If you have no account — you only subscribed to the newsletter, or wrote to support — the unsubscribe link handles the first, and one line to the address below handles either.
If you are in the EU/EEA or UK, these are your GDPR rights to access, portability and erasure; the rest (rectification, restriction, objection, withdrawal of consent) work by writing to us. Our grounds for processing are the contract with you (your account, your subscription), your consent (the newsletter — withdrawable at any time, without affecting what was done before), and our legitimate interest in keeping the service secure and working, and in understanding in aggregate how it is used (server logs, and the aggregate visit counts above, which identify nobody).
Where data lives
Our servers, database and logs are hosted in Germany, in the EU. Backups of that database, encrypted at rest, are kept in Cloudflare R2 object storage in Europe (its Western Europe location), each for at most 56 days. A few other companies handle data on our behalf, under their own safeguards: Cloudflare carries the traffic between your browser and us and stores the encrypted backups of our database in Cloudflare R2, Stripe takes payments, Google provides OAuth sign-in, and Amazon SES delivers our email from the US. Analytics is no longer on that list — we host it ourselves, on the same servers, in Germany. Our own fonts are not on that list: they are part of the site itself and served from styles.gallery, so an ordinary page here asks Google for nothing. The one exception is the typography gallery, which shows real specimens of Google-hosted families and therefore has your browser load them from Google directly.
Changes and contact
If this policy changes materially we will note it here and move the date at the top. Questions, requests, complaints: support@styles.gallery.