Privacy Policy
Last updated: August 2026
Alrom Works (“we”, “our”) operates the Alrom Studio application. This policy explains what personal data we collect, how we use it, who processes it on our behalf, and the rights you have over it under the GDPR and similar privacy laws.
What we collect
When you sign in with Google, we receive your name, email address, and profile picture. When you create a sign, we store the family name and apartment number you enter, the photo(s) you upload, the generated sign designs, and the material you choose. We also use a session cookie to keep you signed in. If you arrived from a partner’s referral link or QR code and you accepted optional cookies, then when that visit is linked to your account we also store which partner referred you and when, together with a keyed one-way hash of your IP address and your browser’s user-agent string. Those last two are used only to detect duplicate or fraudulent referrals — never to build a profile of you and never to track you across other sites — and are kept with the referral record for as long as a partner’s commission can still be verified or disputed; they are removed with the rest of your data if you request deletion. Vercel, acting as our processor through Speed Insights, also collects anonymous page-load metrics such as the route and URL viewed, country-level location, browser/device and network type, and Web Vitals attribution. With your consent to analytics, we use PostHog (EU region) as a processor for product-usage analytics and session replay — pages viewed, clicks and interactions, and visual recordings of your session (including the sign you design) to help us diagnose bugs and improve the product. Form inputs (including text you type and uploaded images before submission) are masked before recording. You can revoke consent at any time from the privacy page. For error monitoring we use Sentry (EU region) as a processor; error reports are collected to diagnose crashes and run on a legitimate-interest basis with personal data scrubbed before transmission. If you write to us through the contact form, we store the name, phone number, optional email address and message you enter, together with the language you were reading the site in, so that we can reply to you in the right language. If you were signed in at the time, the message is linked to your account.
How we use your data
We use your data only to run the service: authenticate you, generate and produce your sign, process and ship your order, and provide customer support. The lawful basis under the GDPR is performance of a contract (Art. 6(1)(b)) for order-related data, and consent (Art. 6(1)(a)) for optional analytics and session replay. We do not sell or rent your personal data, and we do not use it for advertising.
AI image processing
To turn your photos into silhouettes and compose them with your text into a finished sign, we send your uploaded images to OpenAI (image model) and Google Gemini via their APIs. Both are US-based processors with Data Processing Agreements in place. Images are transmitted over TLS, used only to generate your sign, and are not used to train the providers’ models (both have opt-out defaults for enterprise API traffic).
Where we store your data
Account, order, and design data is stored in Supabase (Postgres and object storage). Transactional emails are sent via Amazon Web Services (AWS SES). We retain uploaded photos only as long as we need them to fulfill your order and resolve any disputes; derivative silhouettes and sign images are kept with the order record for production and customer support. If you request account deletion, we remove all associated personal data promptly. Messages sent through the contact form are stored in that same database and are also delivered to our studio inbox by email through AWS SES; we keep them for as long as we need them to answer you and to handle any follow-up, and we delete them on request.
Cookies
We use one strictly necessary authentication cookie to keep you signed in, plus functional cookies (alrom-lang, sign-maker-locale, and, when enabled, sign-maker-dev) to remember your language and developer-mode preferences. If you arrived from a partner’s referral link or QR code and you accept optional cookies, we also set one referral cookie (alrom-ref) so that partner can be credited for your order; it records which partner, a single-use identifier and how the link was opened, and nothing about what you design or buy. We do not use advertising or cross-site tracking cookies and do not embed third-party analytics scripts on public pages without your consent. For performance monitoring we use Vercel Speed Insights, which collects anonymous page-load metrics (Core Web Vitals) without setting cookies or identifying individual visitors. Optional analytics (used only with your consent) is described below under ‘Your choices.’
Your choices
You can accept or reject optional cookies — analytics, and the partner referral cookie — at any time. On your first visit you'll see a consent banner with the choice; you can also change it later from this page (a Reset choice link will appear when a choice is recorded). Rejecting does not degrade the core sign-maker experience — it prevents anonymous usage data from being collected, and, if you arrived from a partner’s link or QR code, means we cannot credit that partner for your order. Strictly-necessary cookies (authentication, language) remain regardless because they are required for the app to work.
Photos of other people
If the photo you upload shows other people, you confirm that you have permission from each identifiable person (or from a parent or guardian for minors) to submit that image for this purpose. If you appear in a photo someone else uploaded and you want it removed, contact us and we will delete it.
Your rights
Under the GDPR you can request access to the data we hold about you, correction of inaccurate data, deletion, restriction of processing, data portability, and objection to processing. Email us to exercise any of these rights. You can also revoke Google sign-in access at any time via your Google Account settings.
Open-source software
Converting HEIC/HEIF photos (such as those taken on an iPhone) into a standard format happens entirely in your browser using libheif-js, an open-source library provided under the GNU Lesser General Public License v3.0 (LGPL-3.0). We use the library without modification.
View the libheif-js sourceContact
For privacy-related questions, or to exercise any of the rights above, email us at alrom.works@gmail.com