Your property. Your privacy.
A clear view of
what you share.
This is a studio concept and local review build. Local inquiries are stored on the computer running the site. A local receipt does not mean that the studio received an email. The inquiry form identifies the active storage mode before you submit.
Your concept preview
The photographs you choose for a concept preview are processed in your browser tab. They are not automatically uploaded. Resetting the preview or closing the tab releases the app’s access to its working copies. Your original files remain yours; browser and operating-system memory management is outside this app’s control.
When you send a request
We store your property name, contact email, optional listing link and message, chapter labels, sharing choice, consent, and submission time. Listing query strings and fragments are removed. We do not visit your listing or fetch its images. A hashed rate-limit identifier helps protect the form from abuse.
Photographs are included only when you explicitly choose to share them. Where enabled, you can attach up to three JPEG, PNG, or WebP derivatives of up to 1 MB each. The server validates the images, resizes them to at most 1200 pixels on the long edge, and re-encodes them to remove embedded metadata. Production photo sharing is currently disabled.
Storage and retention
In local mode, request details and shared images are held in a private SQLite database on the computer running this site. Shared images become eligible for deletion after 30 days and request details after 90 days. Cleanup runs when a request is handled or the retention job is invoked; an offline development computer cannot run scheduled cleanup.
Production mode requires a separately configured private Supabase database and an active retention process before it can accept requests. Its retention function deletes inactive request details after 90 days. There is no email notification provider configured in this build. Operators must review saved requests through authorized database access.
Delete your request
Your receipt includes a private deletion token. Keep it with your reference: anyone who has both can delete the request. The server keeps only a hash of that token. Delete your request and shared photographs using the confirmation form. Opening a deletion link never deletes anything by itself.
Deletion removes active database copies, including shared photographs. Copies in host or database-provider backups may remain until those backups expire. Backup expiry depends on the deployed provider configuration; this development build does not promise immediate removal from backups.
Before a public launch
The studio’s legal identity, privacy contact, hosting region, backup schedule, and production operator access must be supplied and this notice updated before public inquiry collection. The current preview does not invent those details.