Skip to content

Policy

Privacy Policy

Last updated 18 June 2026

The short version: uiscanner works anonymously. When you scan a page we store the URL and our own analysis of it (tokens, structure, a screenshot we capture), never the original site’s asset bytes. Website scans are public by default and may appear in Explore. We do not sell your data. Email misha@uiscanner.com to delete anything.

1. Who we are

uiscanner (“uiscanner”, “we”, “us”) operates the website and service at uiscanner.com, which lets you paste a public URL and get a design teardown: extracted design tokens, a section-by-section structure breakdown, and an AI-drafted build prompt. This policy explains what we collect and how we handle it for everyone who uses uiscanner: visitors, anonymous users who run a scan without an account, signed-in account holders, and programmatic (API key) users.

We are the data controller for the information described here. The service and our providers are based in the United States, so your information is processed in the US (see International transfers). Questions: misha@uiscanner.com.

2. Information we collect

We collect only what we need to run the service:

  • Scan inputs. The URL you submit and the domain derived from it.
  • Our analysis output. Design tokens, the section structure (including some heading text we read from the page), brand metadata (page title, favicon URL, theme color, detected tech), a screenshot we capture ourselves, and the generated build prompt. This is our own description and render of the page. We never copy or re-host the original site’s asset bytes (its images, fonts, logos, code, or copy).
  • Account data (only if you sign up). Authentication is handled by Clerk; we store your email, an optional username, and your account id so you can find your saved teardowns and we can apply your plan.
  • Billing data (only if you buy a plan). Payments run through Polar as merchant of record. We store a plan reference, not your card number. Card and invoice details live with Polar.
  • API keys. If you create a programmatic key, we store only a one-way hash of it plus a short prefix. The full key is shown once and never stored.
  • Technical and usage data. Your IP address, used for rate limiting and abuse prevention, and (if and when product analytics is enabled) basic events such as which actions you take. Analytics is currently dormant and sends nothing until we turn it on.

We do not knowingly collect special-category or sensitive personal data.

3. How we use your information

  • Produce and return your teardown, and improve scan quality.
  • Operate accounts and let you find your saved teardowns.
  • Rate limiting, security, and abuse and SSRF prevention.
  • Billing and plan enforcement.
  • Optional product analytics and error monitoring to improve the service (when enabled).
  • Transactional email such as receipts and account notices (when enabled).
  • What we never do: we do not sell your data, and we do not use the URLs you scan for anything beyond producing and improving your results.

5. Cookies and tracking

uiscanner’s own code sets no first-party cookies. When you sign in, Clerk sets a session cookie that is essential for authentication. Our analytics identifier (when analytics is enabled) is stored in your browser’s local storage, not a cookie. If we later enable analytics cookies, we will ask for consent where required and honor Global Privacy Control (GPC) browser signals. This section will be updated when that changes.

6. How we share information (subprocessors)

We share data with the service providers that run uiscanner. Each processes data only to provide their service to us:

ProviderWhat it handles
NetlifyHosting, CDN, and request handling (incl. IP)
SupabaseDatabase and screenshot storage
BrowserbaseRemote browser that loads the URL you submit
Anthropic (Claude)Generates the build prompt from extracted design data
ClerkAuthentication (email, session) for accounts
PolarBilling and payments, as merchant of record

When enabled, we may also use PostHog (product analytics), Sentry (error monitoring), Upstash (rate-limit storage), and Resend (transactional email). We may also disclose information to comply with the law or in connection with a business transfer. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Note: Browserbase loads the public page you submit so we can analyze it, and Anthropic receives the extracted design data (tokens, structure, brand title and tech) to write the prompt. Anthropic does not receive the raw URL or our screenshots.

7. Public teardowns and the URLs you submit

When you run a scan from the website, the teardown is public by default. Public, completed teardowns appear in our Explore gallery and at their own /t/<id> page, with a link preview. That means the domain you scanned, our screenshot, the extracted tokens, and the generated prompt can be visible to anyone. The owner’s account id is removed from public responses. Teardowns run with an API key are private to that key’s owner.

We only analyze pages that are publicly reachable and that you choose to submit. Our URL safety guard blocks attempts to reach private, internal, or cloud-metadata addresses, so internal or intranet pages cannot be scanned. If you want a teardown made private or removed, or you are a site owner requesting removal of a teardown of your site, email misha@uiscanner.com.

8. Data retention

  • Teardowns are kept until you (or, for your account, we at your request) delete them. We do not currently auto-expire them.
  • Account and profile data is kept for the life of your account and deleted on request.
  • Rate-limit records are short-lived and used only for abuse prevention.
  • Billing records are retained by Polar as long as legally required (for example, tax).

9. Security

We keep secrets server-side only (nothing sensitive is exposed to the browser), enforce row-level security on the database, store API keys only as hashes, guard every submitted URL against SSRF and abuse, rate-limit requests, and serve everything over encrypted connections. No method of transmission or storage is perfectly secure, but we work to protect your information and will act on any incident we become aware of.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict your data, to object to certain processing, to withdraw consent, and to opt out of any sale or sharing of personal information. California residents have these rights under the CCPA/CPRA, and EEA/UK residents under the GDPR, including the right to complain to your supervisory authority.

To exercise any right, email misha@uiscanner.com. You do not need an account to make a request. We honor Global Privacy Control signals as an opt-out of sale or sharing where applicable, and we will not discriminate against you for exercising your rights.

11. International transfers

uiscanner and its providers are based in the United States, so if you are outside the US your information is transferred to and processed in the US. Where required for transfers of EEA, UK, or Swiss data, we rely on appropriate safeguards such as Standard Contractual Clauses with our providers.

12. Children

uiscanner is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us information, email misha@uiscanner.com and we will delete it.

13. Changes to this policy

We may update this policy as the product evolves. We will post the new version here and update the date above, and for material changes we will provide a more prominent notice. We review this policy at least every 12 months.

14. Browser extension

The uiscanner Chrome extension reads the current tab’s URL only when you click its icon or a right-click menu item, to open that page on uiscanner.com for a teardown, the same as submitting the URL on the website and covered by the rest of this policy. It keeps a short list of your recent scans in your browser’s local storage, which never leaves your device. It does not track your browsing, read page content, sell your data, or run remote code.

15. Contact

Questions, a deletion request, or a takedown request: email misha@uiscanner.com. EEA/UK residents also have the right to lodge a complaint with their local data protection authority.

uiscanneruiscanner

Paste any public URL and keep what makes it look good. You get the tokens, the structure, and a prompt you can build from.

Scan another site

Paste any public URL and get its tokens, structure, and a build-ready prompt.

© 2026 uiscanner. All rights reserved.