Privacy Policy

1. Controller and scope

BuildWithDeni is the controller of personal data processed through freemockup.video. This policy covers visitors, account holders, Free and Pro users, public sharing, and the free marketplace.

BuildWithDeni

Tirana, Albania

Phone: +355 69 996 6016

Email: contact@buildwithdeni.com

2. Data we process

  • Account and authentication: email address, account ID, authentication/session data, and—when Google OAuth is used—name, email, profile image, and provider identifiers made available by Google.
  • Profile and access: display name, role, use case, referral answers, plan, entitlements, account status, favorites, and legal acceptance versions.
  • Pro trial requests: the email address entered, request source, delivery status, and—when the same signed-in account email is used—the associated account ID.
  • Projects and uploads: project names, editor settings, snapshots, screenshots, video, images, audio, file metadata, checksums, storage paths, saved drafts, exports prepared locally, and public-share metadata.
  • Website capture: when you request a website capture, the submitted public URL and capture settings are processed transiently in an isolated AWS browser worker. We retain a short-lived job identifier linked to your account, sanitized processing stages and timings, output metadata, and the resulting capture in private storage. Submitted URLs and captured media are excluded from application and worker logs.
  • Marketplace: claimed free templates, imported project references, favorites, and related activity.
  • Product and website measurement: page views, button/link clicks, signup/login milestones, editor feature usage, Pro checkout milestones, marketplace template actions, referrer/UTM values, and basic device/browser information measured through Google Analytics and any active hosting analytics. We do not use these services to record keystrokes, session replay, heatmaps, complete payment-card details, private project contents, uploaded file contents, or raw upload filenames.
  • Billing: selected plan and email sent to Freemius, the internal account link used to match a verified purchase, provider user/license/subscription/plan/pricing identifiers, status, renewal/cancellation dates, and signed webhook/audit records. We do not receive your complete payment-card number.
  • Technical and communications: IP address and request/device/browser information available in hosting, security, and provider analytics logs; support messages; and information you voluntarily provide.
  • Export reliability: when anyone starts a video export, including anonymous and Pro users, we automatically record a random export ID, browser family/version, operating system, editor and mockup device choices, export settings, timing, progress, and reported outcome. Bounded diagnostics for failures and a small sample of successes include browser capabilities, classified errors, application-code locations, and API request categories, status codes, and durations. These records exclude uploaded media, project contents, filenames, raw console messages, private URLs, and authentication credentials. We store account tier, whether authentication was verified, and an opaque identifier to recognize repeat exports from a signed-in account or signed-out browser, without storing raw account IDs or emails. Signed-out browsers receive a first-party export-reliability cookie lasting 30 days. Guest and signed-in histories remain separate; guest identifiers identify browsers, not necessarily individual people. Blocking or clearing this cookie does not prevent exporting. A short-lived browser queue retries delivery; an expiring credential permits updates only to its export. Hourly salted request-address hashes limit abuse and are not used as visitor identifiers.

3. Sources

We receive data from you, your browser, Supabase authentication, Google when you choose Google OAuth or when Google Analytics measures website/product usage, AWS when you request website capture, Freemius for verified license and subscription lifecycle events, and hosting/security infrastructure. Public template metadata may be created by administrators.

4. Purposes and legal bases

  • Contract and requested steps: create accounts, authenticate, save/load projects, provide sharing, process Pro access, support billing, and respond to requests.
  • Pro trial communications: use the email you submit to deliver the requested Pro activation link and related access updates.
  • Legitimate interests: secure the service, prevent abuse, diagnose failures, measure aggregate performance, understand product funnels, maintain records, and improve usability, balanced against user rights.
  • Legal obligations: tax, accounting, consumer, fraud, dispute, lawful-request, and data-protection obligations.
  • Consent: optional third-party embeds or communications where consent is legally required. Consent may be withdrawn without affecting earlier lawful processing.

Account email and authentication data are required to create a cloud account. Uploads and onboarding answers are optional, although a requested feature may not work without the information it needs.

5. Recipients and processors

  • Supabase: authentication, Postgres database, and private object storage.
  • Vercel: website/API hosting, security/technical logs, and Web Analytics.
  • Freemius: Merchant of Record for checkout, taxes, receipts, license and subscription management, refunds, and payment disputes.
  • Google: OAuth when selected by the user and Google Analytics for website/product measurement.
  • Amazon Web Services: EU-region Lambda, SQS, Secrets Manager, and operational logging for website capture.
  • Cloudflare and other content delivery providers: delivery of public static assets where configured.
  • Professional advisers and authorities: only where reasonably necessary or legally required.

External links do not receive data from us merely because they are listed. Optional media embeds are loaded only after user action.

6. Storage, transfers, and security

Providers may process data in Albania, the EEA, the United States, and other locations where they operate. Where required, transfers rely on adequacy decisions, contractual safeguards, or another lawful mechanism offered by the relevant provider.

We use access controls, private storage buckets, signed expiring asset URLs, row-level security, encryption in transit, provider authentication, webhook signature verification, and least-privilege service credentials. No system can guarantee absolute security.

7. Retention

  • Account profiles, entitlements, saved projects, and private assets are retained while the account exists or until the user deletes them.
  • New public shares expire after 30 days and may be revoked sooner. Expired share assets are scheduled for deletion.
  • Incomplete uploads and drafts are removed after a short operational cleanup period.
  • Browser-local drafts remain on the device until used, deleted, or cleared through browser settings/account deletion.
  • Minimal billing, webhook, fraud, security, and dispute records are retained only as long as reasonably necessary for provider, accounting, legal, or claim obligations.
  • Pro trial requests are retained while they are pending and afterward only as long as reasonably necessary to deliver, administer, or document the requested access.
  • Website-capture jobs and temporary private outputs follow a short operational cleanup lifecycle; sanitized AWS worker logs are retained for seven days.
  • Vercel, Google, and AWS control retention for their platform logs and analytics under their service configuration and terms.
  • Export summaries, their opaque user identifiers, and failure diagnostics are scheduled for deletion after 30 days; sampled successful-export diagnostics after 7 days. Aggregate export counts are retained for up to 12 months. The browser delivery queue expires after 24 hours and is limited to five attempts. Request-limit hashes expire after two hours and are removed by daily maintenance. Retention runs daily, so deletion may occur at the next maintenance run.

8. Public sharing and marketplace

Anyone with a valid public-share link can view the project snapshot and uploaded media until the link is revoked or expires. Do not place confidential, sensitive, or third-party personal data in public shares. Free marketplace claims and imported copies are private to the claiming account unless separately shared.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability; withdraw consent; and complain to a supervisory authority. Profile controls provide data download and account deletion. You may also contact us using the details above. We may verify identity before fulfilling a request.

You may complain to Albania’s Information and Data Protection Commissioner or another competent authority where applicable.

10. Children

The service is for people aged 18 or older. We do not knowingly create accounts for children. Contact us if you believe a child has provided personal data.

11. Changes and contact

Material changes will be presented for renewed acceptance or otherwise communicated as required. Questions and rights requests should be sent to contact@buildwithdeni.com.

Version 2026-09-21. Effective and last updated: September 21, 2026.