Effective September 18, 2026
This policy explains what FinishProof collects, why, and what we deliberately do not collect. The short version: your part photos are processed entirely in your browser and are not uploaded unless you explicitly save a job to the cloud or send a proposal.
All photo editing and AI segmentation run locally in your browser. Photos never touch our servers during editing. Two explicit actions store content with us: (1) saving a job to the cloud stores that job's photos and design in your account so you can reopen it; (2) sending an approval link stores the rendered mockup images so your customer can view them. Deleting a job or account removes that stored content.
We use one essential cookie: your sign-in session. Preferences (like dismissed tips) live in your browser's local storage and stay on your device.
Stripe (payments and deposit payouts), Resend (transactional email such as password resets and approval notifications), our hosting provider, and Hugging Face's CDN (your browser downloads the AI model files from there; no photo data is sent). Each processes data only to provide their service.
When your customer opens an approval link, we process the name and comments they submit and, if they pay a deposit, Stripe processes their payment. We act as a processor of that information on your behalf; it is visible to you and used for nothing else.
Data is retained while your account is active. You can delete jobs anytime; account deletion (via support) removes your account data within 30 days, except records we must keep for legal or accounting reasons.
Passwords are scrypt-hashed, sessions are httpOnly cookies, traffic is encrypted in transit, and the database is backed up automatically. No system is perfectly secure; report concerns via support and we'll respond quickly.
Material changes will be announced in the app or by email. Questions or data requests: use the in-app support chat.