Policy
Privacy Policy
Last updated 18 June 2026
The short version: uiscanner works anonymously. When you scan a page we store the URL and our own analysis of it (tokens, structure, a screenshot we capture), never the original site’s asset bytes. Website scans are public by default and may appear in Explore. We do not sell your data. Email misha@uiscanner.com to delete anything.
1. Who we are
uiscanner (“uiscanner”, “we”, “us”) operates the website and service at uiscanner.com, which lets you paste a public URL and get a design teardown: extracted design tokens, a section-by-section structure breakdown, and an AI-drafted build prompt. This policy explains what we collect and how we handle it for everyone who uses uiscanner: visitors, anonymous users who run a scan without an account, signed-in account holders, and programmatic (API key) users.
We are the data controller for the information described here. The service and our providers are based in the United States, so your information is processed in the US (see International transfers). Questions: misha@uiscanner.com.
2. Information we collect
We collect only what we need to run the service:
- Scan inputs. The URL you submit and the domain derived from it.
- Our analysis output. Design tokens, the section structure (including some heading text we read from the page), brand metadata (page title, favicon URL, theme color, detected tech), a screenshot we capture ourselves, and the generated build prompt. This is our own description and render of the page. We never copy or re-host the original site’s asset bytes (its images, fonts, logos, code, or copy).
- Account data (only if you sign up). Authentication is handled by Clerk; we store your email, an optional username, and your account id so you can find your saved teardowns and we can apply your plan.
- Billing data (only if you buy a plan). Payments run through Polar as merchant of record. We store a plan reference, not your card number. Card and invoice details live with Polar.
- API keys. If you create a programmatic key, we store only a one-way hash of it plus a short prefix. The full key is shown once and never stored.
- Technical and usage data. Your IP address, used for rate limiting and abuse prevention, and (if and when product analytics is enabled) basic events such as which actions you take. Analytics is currently dormant and sends nothing until we turn it on.
We do not knowingly collect special-category or sensitive personal data.
3. How we use your information
- Produce and return your teardown, and improve scan quality.
- Operate accounts and let you find your saved teardowns.
- Rate limiting, security, and abuse and SSRF prevention.
- Billing and plan enforcement.
- Optional product analytics and error monitoring to improve the service (when enabled).
- Transactional email such as receipts and account notices (when enabled).
- What we never do: we do not sell your data, and we do not use the URLs you scan for anything beyond producing and improving your results.
4. Legal bases (EEA / UK users)
If you are in the EEA or UK, we rely on these bases under the GDPR:
- Contract: running the scans you request, providing accounts, and billing.
- Legitimate interests: security, anti-abuse, rate limiting, and improving the product, balanced against your rights.
- Consent: non-essential analytics or cookies where applicable, which you can withdraw at any time.
- Legal obligation: keeping tax and accounting records for purchases.
7. Public teardowns and the URLs you submit
When you run a scan from the website, the teardown is public by default. Public, completed teardowns appear in our Explore gallery and at their own /t/<id> page, with a link preview. That means the domain you scanned, our screenshot, the extracted tokens, and the generated prompt can be visible to anyone. The owner’s account id is removed from public responses. Teardowns run with an API key are private to that key’s owner.
We only analyze pages that are publicly reachable and that you choose to submit. Our URL safety guard blocks attempts to reach private, internal, or cloud-metadata addresses, so internal or intranet pages cannot be scanned. If you want a teardown made private or removed, or you are a site owner requesting removal of a teardown of your site, email misha@uiscanner.com.
8. Data retention
- Teardowns are kept until you (or, for your account, we at your request) delete them. We do not currently auto-expire them.
- Account and profile data is kept for the life of your account and deleted on request.
- Rate-limit records are short-lived and used only for abuse prevention.
- Billing records are retained by Polar as long as legally required (for example, tax).
9. Security
We keep secrets server-side only (nothing sensitive is exposed to the browser), enforce row-level security on the database, store API keys only as hashes, guard every submitted URL against SSRF and abuse, rate-limit requests, and serve everything over encrypted connections. No method of transmission or storage is perfectly secure, but we work to protect your information and will act on any incident we become aware of.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict your data, to object to certain processing, to withdraw consent, and to opt out of any sale or sharing of personal information. California residents have these rights under the CCPA/CPRA, and EEA/UK residents under the GDPR, including the right to complain to your supervisory authority.
To exercise any right, email misha@uiscanner.com. You do not need an account to make a request. We honor Global Privacy Control signals as an opt-out of sale or sharing where applicable, and we will not discriminate against you for exercising your rights.
11. International transfers
uiscanner and its providers are based in the United States, so if you are outside the US your information is transferred to and processed in the US. Where required for transfers of EEA, UK, or Swiss data, we rely on appropriate safeguards such as Standard Contractual Clauses with our providers.
12. Children
uiscanner is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us information, email misha@uiscanner.com and we will delete it.
13. Changes to this policy
We may update this policy as the product evolves. We will post the new version here and update the date above, and for material changes we will provide a more prominent notice. We review this policy at least every 12 months.
14. Browser extension
The uiscanner Chrome extension reads the current tab’s URL only when you click its icon or a right-click menu item, to open that page on uiscanner.com for a teardown, the same as submitting the URL on the website and covered by the rest of this policy. It keeps a short list of your recent scans in your browser’s local storage, which never leaves your device. It does not track your browsing, read page content, sell your data, or run remote code.
15. Contact
Questions, a deletion request, or a takedown request: email misha@uiscanner.com. EEA/UK residents also have the right to lodge a complaint with their local data protection authority.