Draft: requires legal review. This page is a template and is not yet a binding document.

Privacy Policy

Last updated 2026-09-26

This policy explains how Edge Case Studios, LLC (“we”) handles personal data in connection with Mosaicdeck. It covers three groups of people: customers (people with a Mosaicdeck account), visitors to our customers' sites, and visitors to this website.

1. Customers

What we collect

  • Account details: email address, and your name and profile picture if you sign in with Google.
  • Workspace data: workspace and site names, settings, alert channels, and the people you invite.
  • Billing: handled by Stripe. We store your subscription status and Stripe customer ID, not card numbers.
  • Security records: active sessions (with the browser's user agent), an audit log of security-relevant actions, and hashed (not raw) IP addresses used for rate limits and abuse prevention.
  • Email events: bounces and complaints, so we stop emailing addresses that can't or don't want to receive mail.

Why, and on what basis

  • To provide the Service you signed up for (performance of a contract).
  • To keep the Service secure, prevent abuse and fix problems (legitimate interests).
  • To send service emails such as sign-in links, alerts, digests and billing notices (contract). Digests and alerts can be turned off, and every digest has a one-click unsubscribe link.
  • To keep financial records (legal obligation).

We don't sell personal data, use it for advertising, or use Customer Data to train AI models.

2. Visitors to our customers' sites

When a customer adds the Mosaicdeck script to their site, we process data about that site's visitors on the customer's behalf, as a processor under our Data Processing Addendum. The customer is the controller; questions about a specific site should go to its owner.

The script sets no cookies and stores nothing in the browser. It sends the page path, the referring site's hostname, UTM campaign tags, the window width, and any custom events or errors. We use the visitor's IP address and user agent in memory to derive a country, a browser and OS family, and a visitor hash made with a salt that changes every day. IP addresses are not stored, and salts are deleted after 2 days, so visitors can't be recognised across days or across sites. Details: what we collect.

3. Visitors to this website

This website uses no cookies, analytics or advertising trackers. If we start measuring it, we'll use Mosaicdeck itself, in exactly the way described in section 2.

Contact form. If you write to us through our contact form, we receive your name, email address, the topic you choose and your message, and use them only to answer you. The message reaches us by email (sent through Resend) and stays in our inbox for as long as we need it to handle your request. Cloudflare Turnstile checks that the form is being used by a person. To limit abuse we store a one-way hash of your IP address and the time of your message, never the address itself, and delete it after one hour.

4. Retention

Analytics data is kept for the retention period of the customer's plan and then deleted automatically. Account and workspace data is kept while the account exists. When an account or workspace is deleted, it can be restored for 7 days, and its data is then permanently purged. We keep billing records as long as the law requires. Contact-form messages are kept only as long as needed to handle the request, and the hashed IP used for rate limiting is deleted after one hour.

5. Subprocessors

We use these service providers to run Mosaicdeck:

SubprocessorPurposeLocation
Cloudflare, Inc.Hosting, compute, databases, storage, queues and network (the whole service runs on Cloudflare)Global network
Stripe, Inc.Payments, subscriptions, invoices and taxUnited States
Resend, Inc.Sending email: sign-in links, alerts, digests, billing notices, and delivering contact-form messages to usUnited States
Anthropic, PBCAI features: site detection, dashboard layouts and digest wordingUnited States
Google LLC"Sign in with Google" only, when you choose itUnited States

The current list, with the data each one receives, is on the Subprocessors page.[International transfer mechanism, e.g. Standard Contractual Clauses: to be completed after legal review]

6. Security

Data is encrypted in transit. Secrets you give us (such as metrics endpoint secrets and webhook URLs) are encrypted at rest. Access is limited by workspace roles, and sign-in tokens and sessions are stored only as hashes.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict processing, and to complain to a data protection authority. You can delete your account in the app. To make any other request, contact us through our contact form.

8. Changes

We'll post changes here and update the date above. For material changes, we'll also notify account holders by email.

Contact

Edge Case Studios, LLC
Contact form