Skip to content

Privacy Policy

Last updated: 27 August 2026

What we collect

  • Your email address, used to sign you in and to contact you about your account. Sign-in codes are stored only as a keyed hash and expire after ten minutes.
  • Your Printify access token, encrypted at rest with AES-256-GCM. It is used only on our servers to call the Printify API, and it is never sent to a browser.
  • Your product data: artwork, titles, SKUs, variants, prices, and job history, so batches can be reviewed, retried, and managed.
  • Purchase records, being which pack was bought and when. Card details are handled by Stripe and never reach us.

What we do not do

We do not sell your data, use your artwork to train models, or share your product catalog with anyone. We do not use advertising trackers.

Artwork retention

Uploaded artwork is passed to Printify and, depending on your configuration, the original file is deleted from our storage once Printify confirms it has ingested the image. We retain the resulting Printify image reference, a checksum, and dimensions so batches remain reviewable.

Written listing copy

If you choose to have listing copy written for you, we send that design and a description of the blank it is printed on to OpenAI, and they return a title, a description, and tags. This only happens when you ask for it: every batch offers to write its own descriptions, to use one you wrote, or to leave them empty, and the default is not to use AI at all.

What is sent is the artwork itself, the blank's manufacturer details, the colors and sizes in your batch, and the voice you set for your shop if you set one. What comes back is stored on your products like any other copy, and you can edit or replace it.

OpenAI does not use data submitted through their API to train their models. We do not use your artwork or your copy to train anything, and we never send your Printify token, your email, or your customers' details.

For each request we keep a record of which model ran, how many tokens it used, what it cost, and whether it succeeded, so we can bill accurately and see whether the feature is working. Those records carry no artwork and no listing text. When a request fails, the provider's own error message can quote the request back to us, so it is written to our server logs, which expire, and never into our database.

Sub-processors

  • Printify, for product and catalog operations you initiate
  • Stripe, for payment processing
  • Resend, for delivery of sign-in code emails
  • Supabase, for database and file storage
  • PostHog, for product analytics, so we can see which parts of the tool work
  • OpenAI, only when you ask for listing copy to be written, as described above

Analytics

We record how the product is used: pages viewed, steps completed, batches created, and where people get stuck. Your email address is stored against your analytics profile so we can support you; it is not attached to individual events. We do not record your artwork, product titles, or SKUs in analytics, and we do not use advertising trackers or sell this data.

Your rights

You can ask for a copy of your data, correct it, or have it deleted. Deleting your account removes your stored artwork, product records, and job history from Productify; products already created in your Printify account belong to you and stay there. Email support@useproductify.com and we will respond within 30 days.

Security

Access tokens are encrypted at rest, sessions use signed HttpOnly cookies, and every request is authenticated before any data is read. Each account's data is isolated at the database layer.

Contact

Privacy questions: support@useproductify.com