Legal

    Privacy Policy

    What we collect, why we need it, and what you control. We keep as little as we can, and we never sell it.

    Effective September 26, 2026

    The short version

    • We keep what an account needs: a username, a password stored only as a salted hash, and an email address if you choose to add one.
    • Designs you upload are deleted 2 hours after upload, unless you share them in the community. AI review sends the frame it looks at to OpenAI.
    • No ads and no tracking cookies. We count visits without cookies and keep only daily totals. One cookie keeps you signed in; another keeps the free plan fair.
    • Download everything we hold about you, or delete your account, from your Account page at any time.

    This summary helps you find your way; the full text below is what applies.

    1. What we collect

    Your account
    Your username; your email address, if you add one; your password, stored only as a salted scrypt hash (never the password itself); a profile picture, if you upload one; and your plan, its end date, and how many conversions you've made.
    Two-step sign-in
    If you turn it on: the secret your authenticator app shares with us, and your recovery codes, stored only as one-way hashes.
    Google and Discord
    If you sign in with or connect one: from Google, your account ID, email address, and profile picture link; from Discord, your user ID, username, and avatar.
    Designs
    The .fig files you upload, the frames you choose, and the projects we generate from them.
    Payments
    For PayPal, the payment notification PayPal sends us: the payer's name and email address, the amount, the note, and the transaction ID. For crypto, the transaction ID and amount, which are public on the blockchain. We never receive card or bank details.
    Support
    The tickets and messages you send us.
    AI review
    On paid plans, a record of each review: the frame's name, how many tokens it used, and what it cost.
    Visits
    Daily totals of page views and visitors: which pages were opened, the site a visit came from (such as Google or Discord), a campaign tag in the link, and the kind of device, browser, and operating system. To count a visitor once a day, we hash your network address and browser with a random value that is replaced every day, so visits can't be linked from one day to the next or traced back to you. No cookies are used for this, and browsers that send Do Not Track or Global Privacy Control aren't counted.
    Security and fair use
    A random ID for your browser (in a cookie) and a salted, one-way hash of your network (IP) address, keeping the last 8 of each per account; when you last used the site; and an activity log of account events such as sign-ins, plan changes, and conversions (with the file and frame names).

    2. How we use it

    • To run your account and make the conversions and AI reviews you ask for.
    • To apply plan limits and keep the free plan fair: one free conversion per browser or network.
    • To match payments to orders and start plans.
    • To answer support tickets.
    • To protect accounts and the service, for example by slowing down password guessing and spotting abuse.
    • To let the operator know about new orders, payments, and support tickets.
    • To see how the site is used, from daily visit totals, and improve it.

    We don't sell your data, show ads, or use your designs to train AI models.

    3. Who else sees it

    • PayPal handles PayPal payments. What you give PayPal is covered by PayPal's own privacy policy.
    • Google and Discord, when you sign in with them. Profile pictures of accounts that connected Discord load from Discord's servers.
    • Discord, for the operator. Notifications go to a private Discord channel only the operator reads: the username, plan, and amount for orders and payments, and the subject and message of support tickets.
    • Blockchain explorers and price feeds. We check our own wallets for incoming payments (mempool.space, litecoinspace.org, Blockscout, and a Solana server) and read exchange rates from Coinbase or CoinGecko. These requests contain none of your personal data.
    • OpenAI, when AI review looks at a frame (paid plans): the frame's layers (their names, positions, sizes, and text) and a picture of it. OpenAI doesn't use this to train its models, keeps it for up to 30 days to watch for abuse, and is asked not to store the answer.
    • Other members see your username and profile picture on what you share in the community, and the designs you share.
    • The law. We disclose data if we're legally required to, or when it's needed to protect people or the service.

    4. Cookies and browser storage

    NameWhat it's forKept for
    lazyui_sessionKeeps you signed in. Scripts can't read it.30 days
    lazyui_deviceA random ID, so the free conversion is one per browser and mass sign-ups are slowed down.400 days
    lazyui_2faHolds a sign-in between your password and your authenticator code, when two-step sign-in is on. Scripts can't read it.10 minutes
    Local storageYour theme, your recent projects list, and which tips you've seen. It stays in your browser; we never receive it.Until you clear it

    There are no advertising or analytics cookies, and no third-party trackers. Visits are counted on our own server, without cookies.

    5. How long we keep it

    Uploads and generated projects
    Deleted 2 hours after upload.
    Designs shared in the community
    Until you or an admin remove them.
    Your account and support tickets
    Until you delete your account.
    Sign-up records per network
    31 days.
    Unpaid checkout orders
    7 days.
    Activity log
    The most recent 2,000 events across the site.
    Visit totals
    Two years. The daily value that makes visitors countable is replaced every day, and the hashes made with it are dropped along with it.
    AI review records
    The most recent 3,000 reviews across the site; monthly totals of tokens and cost are kept for accounting.
    Payment records
    Kept after an account is deleted, for accounting, refunds, and fraud prevention.

    6. Your choices

    • See and download your data. On your Account page, Download my data gives you a file with your account, plan, payments, orders, activity, AI reviews, tickets, and shared designs.
    • Correct it. Change your email address, password, and picture on the Account page.
    • Disconnect Google or Discord from the Account page.
    • Delete your account. Delete account removes your account, its sign-ins, profile picture, support tickets, and shared designs right away. Payment records and activity log entries are kept, as described above.

    Depending on where you live, you may have other rights over your data. For anything the Account page doesn't cover, ask us on our Discord server or Telegram, or open a ticket from Support after you sign in.

    7. Security

    Passwords are hashed with scrypt and a unique salt. Sign-in cookies can't be read by scripts and are marked Secure over HTTPS. Network addresses are stored only as salted hashes that can't be turned back into addresses. Repeated failed sign-ins, codes, and password checks are slowed down, and you can turn on two-step sign-in with an authenticator app from your Account page. No system is perfectly secure; if a breach affects your data, we'll tell you.

    8. Children

    Lazy UIs isn't meant for children under 13, and we don't knowingly collect their data. If you believe a child has an account, ask us on our Discord server or Telegram, or open a ticket from Support after you sign in, and we'll delete it.

    9. Changes to this policy

    We may update this policy. The date at the top shows when it last changed, and for significant changes we'll also post a notice on the dashboard.

    10. Contact

    Questions about your data or this policy? Ask us on our Discord server or Telegram, or open a ticket from Support after you sign in.