Skip to content

Hoverlab

Privacy Policy

The short version: you can browse and copy the entire catalog without an account and without telling us anything. If you make an account we store your email address and what you save. If you buy something, Polar handles the payment and we never see your card. We use PostHog to see which effects get copied. Nothing here is sold, and nothing here trains a model.

In effect from 22 August 2026. Questions about anything on this page go to TO BE SET — e.g. hello@yourdomain.com.

1. Who is responsible

TO BE SET — registered company or sole-trader name (trading as Hoverlab), at TO BE SET — registered address, is the data controller for the personal data described below. Contact us about anything on this page at TO BE SET — e.g. hello@yourdomain.com.

2. What we collect, and why

If you never make an account: nothing that identifies you is stored by us. The catalog, the designer tools, the CLI and the public API all work without one. Your browser keeps your favourites, recent items and preferences in its own local storage — that data stays on your device and is never sent to us.

If you make an account:

  • Email address and display name — to identify your account and to send account email such as a password reset. Legal basis: performance of a contract.
  • Password — held by Firebase Authentication as a salted hash. We never see or store the password itself.
  • Your saved state — favourites, bundle contents, playground remixes. Stored so it follows you between devices, and for nothing else.
  • Purchase records — which plan you hold, when it was bought, and the amount Polar reported charging. Needed to give you what you paid for and to keep our books. Legal basis: contract, and legal obligation for the accounting records.
  • Sign-in and usage records — passkey names and dates (the key itself stays on your device and only its public half is stored), a licence key held as a hash, and per-day counters that enforce the daily export limit. Legal basis: performance of a contract, and legitimate interest in protecting the service from abuse.

If you join the mailing list: we store the address, where on the site you signed up, the date, and the exact sentence you agreed to. Legal basis: consent. Every email carries a one-click unsubscribe link, and using it is the whole of what is required to leave.

Analytics: we record product events — an effect viewed, an effect copied, a checkout started — with PostHog, to learn which parts of the catalog are worth expanding. Signed in, those events are tied to your account id. Legal basis: legitimate interest in understanding how the product is used; you can opt out (section 6).

3. What we do not do

  • We do not sell personal data, and we do not share it for advertising.
  • We do not use your playground remixes, bundles or any other content you create to train machine-learning models.
  • We do not store IP addresses or user agents against a newsletter signup — neither is needed to send an email.
  • We do not run advertising trackers, retargeting pixels or social widgets.

4. Who else processes your data

These are the only third parties involved, and each is used for one thing:

  • Google Firebase (Authentication and Firestore) — accounts, and everything you save. Hosted in Google Cloud.
  • Polar — payments, as merchant of record. They receive your email address and take your payment details directly; we receive back only a record of what was purchased.
  • PostHog — product analytics.
  • Netlify — hosting. Netlify keeps standard server logs, which include IP addresses, for a limited period.
  • Resend — mailing list delivery, if and when a sending platform is configured. Until then, list addresses are stored only in Firestore.

Some of these process data outside your country. Where that involves a transfer out of the EEA or the UK, it is covered by the standard contractual clauses in each provider’s data processing terms.

5. How long we keep it

  • Account data and saved state: until you delete your account. Deleting it from your account page removes it immediately; if you ask us by email instead, within 30 days.
  • Purchase and invoice records: kept for as long as tax law requires, typically six to eight years, even after an account is closed. When you delete your account they stay but are cut loose from you: the link to your account is removed and only the order id, plan, amount, currency and date remain.
  • Mailing list entries: until you unsubscribe. An unsubscribed address is kept, marked as unsubscribed, so that we can prove you asked to leave and so you are not re-added by mistake. Deleting your account removes your entry entirely, including that marker.
  • Analytics events: retained by PostHog under its own retention settings.

6. Cookies and local storage

Three kinds of storage are in play, and only the first is essential:

  • A session cookie set when you sign in. Without it you cannot stay signed in, so it is strictly necessary and is not subject to consent. It is cleared when you sign out.
  • Your browser’s local storage — theme, reduced-motion preference, framework choice, recently viewed items, an anonymous favourites list, and the answer you give the cookie banner. This never leaves your device. Clearing site data removes it.
  • PostHog analytics storage — a cookie and a local-storage entry that give your browser a persistent anonymous id. This is not essential, so it is set only if you allow analytics, and never before.

The analytics library is not loaded until you answer the banner. Not loaded-but-silent: until then posthog.init has not run, so there is no id, no cookie and no request to it at all. Refusing stores one thing — the refusal — because the alternative is asking you again on every page.

You can change your cookie choice at any time, here or from Preferences in the site header, and turning it off clears what was stored. Do Not Track is honoured too: with it on, analytics stay off even if you accept. If you would rather we excluded you by hand, write to TO BE SET — e.g. hello@yourdomain.com and we will.

7. Your rights

If you are in the EEA or the UK, you have the right to access a copy of your data, to correct it, to have it erased, to restrict or object to processing, and to take it elsewhere in a portable format. Where we rely on consent — the mailing list — you can withdraw it at any time without giving a reason.

Two of these you can do yourself, straight away, from the account page: Download my data gives you a JSON file of everything we hold about your account, and Delete my account erases it. Deletion keeps purchase records without your identity, as section 5 explains, and it asks you to cancel a subscription first rather than leaving it charging a closed account. Polar, as merchant of record, keeps its own customer record; ask us if you want that closed as well.

For anything else — correction, restriction, objection, or if the tools above do not work for you — email TO BE SET — e.g. hello@yourdomain.com. We answer within 30 days. You can also complain to your local data protection authority; we would rather you told us first.

8. Security

Passwords are hashed by Firebase and never seen by us. Card details are never transmitted to our servers. Sessions are held in an HTTP-only cookie, and every route that returns account data verifies that session on the server rather than trusting the browser.

If a breach affects your data, we will tell you and the relevant authority as the law requires.

9. Children

The service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has made an account, tell us at TO BE SET — e.g. hello@yourdomain.com and we will delete it.

10. Changes

When this policy changes, the date at the top changes with it. A change that affects what we collect or who processes it will be announced on the site before it takes effect. The Terms of Service cover everything that is not about data.