/ LEGAL

Privacy Policy

We believe privacy policies should be readable. This one is. We cover what we collect, why, and how you stay in control.

Last updated: April 20, 2026
01

Who We Are

ResetUI is operated by Infynite Labs(“we”, “us”, “our”). We provide an AI-powered landing page redesign service that transforms your existing web pages into modern, production-ready designs with real, exportable code.

This Privacy Policy explains what personal data we collect, how we use it, and your rights over that data. We keep it plain so you can actually read it.

By creating an account or using ResetUI, you agree to the practices described here. This Policy is effective as of April 20, 2026.

02

Information We Collect

Account & Identity Data

  • Full name and email address (collected via Kinde authentication)
  • Profile picture if you sign in with Google or GitHub
  • Account creation timestamp

Usage & Product Data

  • URLs you submit for redesign
  • Generated designs and exported code files
  • AI chat messages sent within a project
  • Credit balance and transaction history
  • Feature usage (generation count, exports, chat messages)
  • Error logs and diagnostic events (anonymised)

Billing Data

  • Subscription plan and billing cycle
  • Last 4 digits of card and billing country (processed by Dodo Payments — we never see raw card numbers)
  • Invoice history and payment status

Technical Data

  • IP address and approximate geolocation (country-level) for fraud detection
  • Browser type and operating system
  • Session identifiers and authentication tokens
  • Request timestamps and response status codes
03

How We Use Your Data

Service Delivery

Processing your URLs, running AI analysis, generating redesigns, and enabling code export. Your submitted URL is fetched by our servers to capture the page — we do not store third-party page content beyond what is needed to complete the generation.

Account Management

Authentication, credit tracking, subscription management, and sending essential transactional emails (account confirmations, password resets, billing receipts). We do not send marketing emails without explicit opt-in.

Product Improvement

Aggregated, anonymised usage metrics help us understand which features are used, where errors occur, and how generation quality can be improved. Individual project data is never sold or shared with third parties for this purpose.

Fraud & Abuse Prevention

IP addresses and usage patterns are checked against rate limits and abuse signals. This protects all users from service degradation.

Legal Compliance

We may process or retain data as required by applicable law, court orders, or regulatory obligations.

04

Third-Party Services

We use a small set of carefully chosen sub-processors. Each receives only the data they need to perform their function.

ServicePurposeData Shared
KindeAuthentication & session managementEmail, name, user ID
Dodo PaymentsPayment processing & billingEmail, billing address, subscription data
VercelApplication hosting & edge networkRequest data, server logs
Supabase (Postgres)Primary database (via Prisma ORM)All structured user & project data
InngestBackground job orchestrationJob payloads (project IDs, user IDs)
AnthropicAI model inference (Claude)Page content submitted for analysis
OpenAIAI model inference (GPT models)Page content submitted for analysis
ResendTransactional email deliveryEmail address, email content

We do not sell your data to any third party. We do not use advertising networks or tracking pixels.

05

Data Retention

Account data

Retained for the lifetime of your account. Deleted within 30 days of account closure.

Project data (generated designs, code, chat history)

Retained as long as your account exists or until you delete the project. Deleted projects are purged within 7 days.

Credit logs

Retained for 2 years for billing and dispute resolution purposes.

Server logs and error reports

Retained for 90 days, then automatically purged.

Billing records

Retained for 7 years as required by accounting and tax regulations.

06

Your Rights

Depending on your location, you may have the following rights regarding your personal data. We honour these requests for all users regardless of jurisdiction.

Access

Request a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your data (right to be forgotten).

Portability

Receive your data in a structured, machine-readable format.

Restriction

Request that we limit how we process your data.

Objection

Object to processing based on legitimate interests.

To exercise any of these rights, email us at support@resetui.com. We will respond within 30 days. You can also delete your account at any time from your dashboard settings.

07

Cookies & Tracking

We use a minimal set of cookies necessary to operate the service. We do not use advertising cookies or cross-site tracking.

Session cookiesSet by Kinde to maintain your authenticated session. Expire when you sign out or the session times out.
CSRF tokensShort-lived tokens that protect form submissions from cross-site request forgery attacks.
Preference cookiesRemember lightweight UI preferences (e.g. onboarding completion status).
08

Children's Privacy

ResetUI is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe we have inadvertently collected data from a child, please contact us immediately at support@resetui.com and we will delete it promptly.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify you via email or an in-app notice at least 14 days before the change takes effect. Continued use of ResetUI after the effective date constitutes acceptance of the revised policy.

10

Contact

If you have any questions about this Privacy Policy or how we handle your data, please reach out:

Infynite Labs

Email: support@resetui.com

We aim to respond to all privacy-related inquiries within 5 business days.