Last updated June 28, 2026

Privacy Policy

Paliet collects and processes data needed to operate the service, secure accounts, process purchases, and deliver saved artwork and export files. We do not sell personal information.

Information We Collect

When you create an account, Paliet stores the email address and account details needed for sign-in, email verification, password reset, saved artwork, downloads, and account management. If you buy an export, checkout and payment details are handled by Stripe.

Cookies And Local Storage

Paliet currently uses only essential cookies and similar browser storage. Supabase sets authentication cookies so users can sign in, stay signed in, verify email changes, reset passwords, save artwork, and access their library. Paliet also uses local storage to keep cart items on the device and to remember whether the cookie notice has been dismissed.

Paliet does not currently use analytics, advertising, or cross-site tracking cookies. If optional analytics or marketing cookies are added later, they should not run for users in consent-required regions until those users have a clear choice to accept or reject them.

Service Providers

Paliet relies on trusted providers to run the product, including Supabase for authentication and data storage, Resend for account emails, Stripe for checkout, Vercel for hosting, and Mapbox for map-based artwork features.

Your Choices

You can update account details from your Paliet account page. You can also clear browser cookies and local storage from your browser settings, though doing so may sign you out or clear cart items on that device.

Data Export And Account Deletion

Users can request a JSON export of Paliet account data through a verified support request. The export includes account profile details, saved creations, export jobs and assets, credit balances and ledger entries, local checkout references, prior privacy request records, and notes about provider-side records. It does not include authentication tokens, cookies, service keys, provider secrets, or raw card details.

Signed-in users can also request account deletion from the account page. Paliet requires the account email, an exact typed confirmation phrase, and a recent sign-in before starting deletion. Eligible local app data, including saved creations, export jobs, assets, and active entitlements, is deleted. Payment-adjacent ledger records may be retained in anonymized form where needed for accounting, fraud, dispute, refund, tax, or security obligations.

Retention And Provider Boundaries

Paliet keeps account and saved artwork data while an account is active, or until the user deletes the creation or account. Verified deletion requests are completed within 30 days where operationally possible unless a legal hold or payment/accounting obligation requires retention. Generated export assets are intended to be retained for a limited delivery window rather than permanent file hosting.

Some records are controlled by third-party providers or operational systems. Stripe payment, tax, fraud, dispute, and refund records; Supabase, Vercel, Resend, Mapbox, Google, and support mailbox logs; backups; and future print-fulfillment records are handled according to their provider policies and approved support workflows.

Contact

For privacy, support, billing, or provider-side data questions, contact Paliet at contact@paliet.com. Privacy requests are reviewed through the authenticated account workflow or a support verification process before data is exported, deleted, or retained for a documented reason.