Legal
Privacy Policy
Last updated: May 2026
01Information We Collect
We collect information you provide directly to us when you create an account, complete onboarding, or use the Service:
- Account information — your name, email address, optional phone number, and ZIP code.
- Design history — photos you upload of your rooms and the AI-generated transformations they produce.
- Preferences — your style choices, budget range, color palettes, room types, and lease constraints.
- Property information — addresses, square footage, bedroom and bathroom counts, and optional floor plans for properties you import.
- Birthday month and day — optional, used for seasonal personalization and birthday acknowledgments.
- Referral information — referral codes you use during signup and any referral activity you generate.
We also collect information automatically when you use the Service:
- Usage data via PostHog product analytics — page views, feature interactions, and aggregate session activity.
- Payment information via Stripe — we never see or store full payment card details on our servers; Stripe handles all card data.
- Authentication and session cookies for keeping you signed in.
02How We Use Your Information
We use the information we collect to:
- Provide and improve the Service — generate room transformations, recommend products, and respond to your interactions with Ivy.
- Personalize Ivy AI recommendations to your stated style, budget, lease constraints, and design history.
- Send transactional emails (account, password reset, design completed, upgrade confirmation) and, with your consent, occasional marketing emails.
- Process payments and manage subscriptions via Stripe.
- Analyze usage patterns to understand which features work and which need refining.
- Send birthday and seasonal design suggestions when you have shared the relevant information.
03Information Sharing
We do not sell your personal data. We share specific data with specific service providers strictly to operate the Service:
- Stripe — payment processing, subscription management, and the billing portal.
- PostHog — product analytics; events are sent with a hashed identifier and aggregate properties.
- Resend — transactional and lifecycle email delivery.
- Anthropic and Google — AI processing for room generation and Ivy responses; the prompts include your inputs (photos, preferences, property details) needed to generate a relevant response.
- Supabase — database hosting for your design history, preferences, and account data.
- Vercel — web hosting for the application itself.
Affiliate partners such as Amazon, Faire, and Wayfair receive click and referral data when you follow a product link, but they do not receive your personal account information from us.
We may share information when required by law, valid legal process, or to protect the safety of users and the public.
04Data Retention
We retain your account data for as long as your account remains active. Your design history is retained for the life of the account so you can revisit past projects.
If you delete your account, we remove your personal data and design history within 30 days, except where retention is required by law (for example, financial records related to past payments). Aggregate analytics data, with no personally identifying information, is retained for up to two years.
05Your Rights
You have the following rights regarding your data:
- Access — view your account information and design history from your dashboard at /account.
- Delete — delete your account from /account/security; this triggers the 30-day removal process described above.
- Opt out of marketing — every marketing email includes an unsubscribe link; transactional emails (receipts, password resets) continue regardless.
- Export — request a copy of your data by emailing contact@callacopper.com.
- California residents — you have additional rights under the CCPA, including the right to know what personal information we have collected and the right to request deletion. Contact us at the address below to exercise these rights.
06Cookies and Tracking
We use cookies for two purposes: keeping you signed in (authentication and session cookies) and product analytics (PostHog). You can disable cookies in your browser's settings, but doing so will prevent you from staying signed in.
We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking.
07Children's Privacy
The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us so we can remove it.
08Security
We take security seriously. Your data is transmitted to and from our servers over HTTPS. Passwords are hashed and never stored in plain text. We rely on Supabase Row Level Security and application-layer access controls to isolate one user's data from another's.
We review our security posture regularly and partner with reputable providers (Stripe, Vercel, Supabase) that maintain industry-standard certifications. Despite our efforts, no system is perfectly secure; if you believe your account has been compromised, contact us immediately.
09Changes to this Privacy Policy
We may update this Privacy Policy from time to time. For material changes — for example, adding a new category of data we collect or a new service provider we share with — we will notify you by email at least 30 days before the change takes effect.
10Contact Us
For questions about this Privacy Policy, data requests, or to exercise your privacy rights:
Calla & Coppercontact@callacopper.com
28262 Diehl Rd
Warrenville, IL 60555