Styde

Privacy Policy

Last updated 27 July 2026

This policy covers styde.app, the Styde pre-launch page. The only thing you can do here is join the waitlist, and the only thing we ask you for is an email address.

Who we are

Styde is a product in development, operated by [registered company name and address], the data controller for everything described below. There is no Styde app yet — nothing on this site describes something you can use today.

For anything about your data, including having it deleted, email privacy@styde.app. [data protection officer or EU representative, if required]

What we collect

We run no database of our own. Everything below is held by the three providers named further down.

  • Your email address. The only thing the form asks for. Used to put you on the Styde waitlist and to email you when early access opens.
  • Four optional answers. After you join we ask about gender, age range, what you want Styde for, and the style you lean towards. Every one is skippable, and skipping them changes nothing about your place on the list. We read them in aggregate, to decide what to build first.
  • Your country. A two-letter country code, which our hosting provider derives from your IP address and we store alongside your contact. We never ask for it, and we never keep anything more precise than the country.
  • Where you came from. The utm_source on the link you arrived through, or directif there wasn’t one. It tells us which post or campaign brought people in.
  • Whether you answered the optional questions. A yes/no flag, so we can tell how many people do.
  • How the page is used. Pages viewed, clicks, which sections you scrolled to, and a fixed set of named events for the steps of the signup. Collected under an identifier stored in your browser. Before you sign up it is anonymous; once you do, your email becomes that identifier, so the analytics profile and the waitlist contact are the same person.
  • Your IP address.Seen by our hosting and analytics providers on every request, as it is by every website you visit. We use it for exactly one thing of our own: counting requests per address over a ten-minute window so the signup form can’t be flooded. That count is held in memory and never written down.

We do not collect payment details — there is nothing to pay for — a name, a phone number, anything about your location beyond the country code, or anything at all from other websites. We do not record your screen, your typing or your mouse movements: session replay is switched off for this project.

Why, and on what legal basis

  • Your email address and the optional answers — to run the waitlist and tell you when access opens. Consent, given by submitting the form. You can withdraw it at any time, and withdrawing it means we delete the contact.
  • Country and where you came from — to understand where demand is and which channels work. Consent, as part of the same signup.
  • Usage analytics — to see which parts of the page work and where people drop out of the signup. [legal basis for analytics — consent or legitimate interests]
  • Rate limiting and anti-abuse — to keep automated signups out of the list. Legitimate interests: without it the waitlist stops describing real people.

Who else sees it

Three providers, each processing on our instructions and nothing more. None of them sells your data, and neither do we. There are no advertising networks, data brokers, ad pixels or social trackers on this site.

  • Loops — our email and audience tool. Receives your email address, the four optional answers, your country code, where you came from, and the waitlist flags. Loops is based in the United States, so this is a transfer of personal data outside the EU and the UK, made under [transfer mechanism for Loops — SCCs or the EU-US DPF].
  • PostHog — product analytics. Our project runs in PostHog’s EU region, so the analytics data stays in the EU. Receives the usage data above and your IP address, and after you sign up, your email address as your identifier.
  • Vercel — hosting. Serves every page and runs the signup endpoint, so it sees your IP address, your browser’s user agent and the requests you make, in its operational logs.

Cookies and browser storage

Two things, both first-party:

  • A cookie set by PostHog on styde.app, holding the analytics identifier described above. No other site can read it.
  • One sessionStorage entry holding the utm_* values from the link you arrived through. It is gone when you close the tab.

That is the whole list. No advertising cookies, no cross-site tracking, no fingerprinting. Clearing site data for styde.app removes both, and you can have the analytics profile deleted by emailing us. [whether a consent banner is required before analytics loads, and its wording]

How long we keep it

  • Your waitlist contact — until you ask us to delete it, or until we retire the waitlist, whichever comes first. [a maximum retention period for waitlist contacts]
  • Analytics events — retained for 84 months on our current PostHog plan, then deleted by PostHog.
  • Screen recordings — none exist. Session replay is off.
  • Rate-limit counts — in memory, at most ten minutes.
  • Hosting logs — kept by Vercel under its own retention schedule, not ours.

If you are under 18

“Under 18” is one of the age options in the optional questions, and we use that answer only to decide what we may send you. [the policy for under-18 signups, including marketing exclusions] If you are under 18 and would rather not be on the list, email us and we will remove you — we won’t ask why.

Your rights

If you are in the EU or the UK, the GDPR gives you the right to each of the following, free of charge:

  • Access — a copy of the data we hold about you.
  • Rectification — correction of anything inaccurate.
  • Erasure — deletion of your data.
  • Restriction — a pause on our processing while a dispute is resolved.
  • Portability — your data in a machine-readable form.
  • Objection — to processing based on legitimate interests, and to marketing at any time.
  • Withdrawing consent — at any time, without giving a reason. It does not affect processing that already happened.
  • Complaining — to the data protection authority in your country, whether or not you raise it with us first.

To use any of them, email privacy@styde.app. Deletion takes one email and no explanation; we reply within 30 days and usually much sooner. Every email we send also carries an unsubscribe link, which stops the mail — email us if you want the contact deleted as well.

Changes to this policy

The product is being built, so this will change. When it does we update the date at the top of this page, and if the change is significant and we hold your email address, we tell you by email rather than leaving you to find it.

Contact

privacy@styde.app for anything about data; hello@styde.app for everything else. Postal address: [registered company name and address]

Styde© 2026 — All rights reserved
PrivacyTermsContactInstagramTikTok