Your Privacy Matters

Privacy Policy

Last updated: September 29, 2026

At Texloom Studio, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our textile design platform and services.

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support.

Personal Information:
- Name and email address
- Payment information (processed securely by our payment providers)
- Profile information you choose to provide

Usage Information:
- Images and designs you upload for processing
- Tool usage patterns and preferences
- Device information and IP addresses
- Cookies and similar tracking technologies

How You Found Us (only if you accept cookies):
- The page you first landed on, and the site that sent you (for example a search engine, or a link someone shared)
- Which of our tools you tried before creating an account

We use this to work out which of our articles and tools actually help people, so we
know what to make more of. It is a random identifier held in a cookie we set — not
your name or email — and we never buy it, sell it, or receive it from anyone else.
If you decline cookies we still count visits and tool usage in total, but with
nothing attached that could link those counts back to you.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process your transactions and send related information
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent transactions and abuse
  • Personalize and improve your experience

3. Information Sharing

We do not sell, trade, or otherwise transfer your personal information to outside parties except in the following circumstances:

  • Service Providers: We share information with third-party service providers who perform services on our behalf:
  • Razorpay — payment processing (cards, UPI, netbanking, wallets). Razorpay receives your billing details for invoice generation and fraud prevention.
  • Cloud storage provider — encrypted object storage for your uploaded images and AI-generated results.
  • Google Analytics 4 — aggregated, anonymized usage analytics (page views, click events). Set to anonymize IP addresses; no personal identifiers transmitted.
  • Microsoft Clarity — anonymous session-replay heatmaps for UX improvement. Configured with input masking so form fields, payment forms, and authentication screens are never recorded. Sessions are aggregated; no individual user is identified.
  • Email delivery provider — transactional email delivery (sign-in links, payment receipts, refund notifications). Recipient addresses only; no body content stored.
  • IP location lookup service — approximate location (city, region and country) for an IP address, shown only to our admins in four places: an account's sign-in sessions, the users-by-location report, the support inbox and the newsletter list. The IP address is sent over HTTPS. The answer also names the internet provider and says whether the connection looks like a VPN, proxy or Tor, and admin views show those too. It is held in server memory for up to an hour and never stored.
  • AI model providers — process only the input image required to generate your result, for that purpose alone, and are contractually forbidden from training on your data.
  • You can disable Google Analytics, Microsoft Clarity, and our own visitor identifier entirely via the cookie consent banner on first visit, or change your mind later via Cookie Settings in the footer. Declining stops all three; nothing about how you found us is recorded against you.
  • How-you-found-us data stays with us. The identifier described above is first-party: we set it, only our own servers ever read it, and it is never shared with any of the providers listed here or with advertisers. We block third-party advertising cookies outright, including the ad-network syncing that Google Analytics and Microsoft Clarity would otherwise attempt.
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you have given us explicit permission

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

  • All data transmission is encrypted using SSL/TLS
  • Uploaded images and results are deleted automatically when your plan's result window ends (see Data Retention)
  • We regularly review and update our security practices
  • Access to personal data is limited to employees who need it

5. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your personal data
  • Withdrawal: Withdraw consent at any time

The data export on your account settings page includes your profile, payments with their billing details, refund requests, generation history, stored result details, tool usage log, support messages, upload records, security events, sign-in history, tool activity, feedback, error reports linked to your account (the type, page and time of each error), coupons you used, poll votes and suggestions, workflow runs, saved workflows, notifications, and the reasons you gave when closing an account.

To exercise these rights, contact us at support@texloom.studio

6. Cookies

We use cookies and similar tracking technologies to:

  • Keep you logged in
  • Remember your preferences
  • Understand how you use our services
  • See which article or tool led someone to sign up, so we know what is worth making
  • Improve our services based on this information

Only the first three are set regardless of your choice — they are what make the site
work. The fourth needs your consent and is not set if you decline.

You can control cookies through your device settings, and change your decision at any
time via Cookie Settings in the footer. Declining stops the optional cookies and
deletes any identifier we had already set. See the Cookie Policy for
each cookie by name and what it does.

7. Data Retention

Different categories of data are kept for different periods. The table below is the source of truth — when this conflicts with other text on this page, this table wins.

| Category | Retention | Why |
| --- | --- | --- |
| Account profile (email, phone, notes about the account) | While your account is open; anonymised 30 days after you close it yourself. If an admin closes it (a ban), kept so the ban can be reversed | A grace period in case you close it by mistake; a ban must stay reversible |
| Generated result images (cloud storage) | 24 hours (Starter) → 7 days (Pro) → 30 days (Studio) → 30 days (Enterprise) | Plan-tiered retention — see /refund-policy |
| Uploaded inputs | Same as the result they produced — purged with that result | We don't keep your uploads beyond the job that processed them |
| Payment records (invoices, transactions) | 7 years | Indian tax law; can't shorten |
| Audit logs (admin actions) | 1 year, in both places we record them. Records of an admin closing or restoring an account are kept longer, so we can tell a ban from an account you closed yourself | Forensic investigations + dispute resolution |
| Usage logs (which tool you ran, when, and — while signed in — the IP address and country it came from) | 90 days | Capacity planning + per-account analytics on /user → Overview; reviewing an account that is used from many places |
| Credit records (credits bought, granted, spent and refunded) | Kept as billing records; not deleted on a schedule | Balance questions, refunds and tax records |
| Upload records (file size, a fingerprint of the file, IP address, country, and whether it came from the studio or extension — never the image) | 30 days | Spotting abuse, such as the same file uploaded across many accounts |
| Security events (rate-limit hits, refund-limit trips, blocked signup bonuses, with IP address and country) | 30 days | Protecting accounts and credits from automated abuse |
| Sign-in history (time, IP address, device, sign-in method and country of each sign-in) | 180 days | Spotting sign-ins you did not make; shown to you in your account settings |
| Email delivery problems (a bounce, spam complaint or delay reported for an address, with the email's subject) | 180 days | So we stop sending to an address that bounces or complains |
| Payment and processing notifications (which notice our payment and AI processing services sent, and when; no card or bank details) | 180 days | So a notice delivered twice is never acted on twice, such as a payment credited twice |
| Raw copy of an AI result, taken before we finish it | Deleted as soon as the finished result is delivered. If it never is, kept while the job is kept, then deleted by a cleanup job once it is at least 7 days old | So a result you paid for is not lost if our finishing step fails |
| Visitor identifier (`tx_vid` cookie) | 180 days, refreshed while you keep visiting | Only set if you accept cookies. Lets us see which article or tool led someone to sign up |
| Arrival records (page you landed on, where you came from) | 365 days | Shows which pages bring people. Anonymous unless you accepted cookies |
| Where you first found us (page, source, campaign) | While your account exists | Recorded once at signup and never updated. Tells us which of our work actually reaches people |
| Support tickets and replies | 3 years from last activity, in full, including after you close your account | Reference for repeat issues + audit |
| Support email digest send timestamps | 30 days | Just enough to throttle the weekly cap |
| Newsletter subscription state | Until unsubscribed; record kept 30 days post-unsub | GDPR grace period to handle re-subscribe / dispute |
| Cookie consent decision | 13 months (per GDPR guidance) | Asks again after 13 months |

If you close your account yourself, we delete your stored results straight away (if a file can't be deleted then, a cleanup job deletes it later), and 30 days later we anonymise the rest of the account:

  • Your email address is replaced with a one-way hash, on your account, in our email delivery records and in our logs, and your phone number is removed
  • IP addresses and device details come off your sign-ins, usage logs and tool activity, and off error reports tied to you. One exception: when an error report groups your error with other people's, it can keep your IP address and device details until error reports are deleted, no later than 90 days after they were first recorded
  • Previews, links and settings saved with your past jobs are removed, and so are the comments on your poll votes and the names and result links of your workflow runs
  • Notes our support team wrote about your account, your notifications, saved workflows, sign-in links, pending invitations and newsletter subscription are deleted
  • Text you typed, such as feedback, a cancellation reason, a refund reason or a poll suggestion, is kept but no longer linked to you, with any email addresses and phone numbers in it removed

Upload records and security events are not part of that pass: they remain after deletion until their 30-day expiry, and are then deleted. Both are included in the data export on your account settings page.

If an email to you bounced permanently or you marked one as spam, we keep that address on our suppression list, including after anonymisation, so we never email it again.

Payment records and invoices are kept as tax law requires, including the billing name, email address, phone number and address, company and GSTIN on them; the UPI ID and device details are removed. We keep the IP address recorded with each payment and coupon redemption as evidence against fraud and chargebacks, including after anonymisation. Admin audit logs keep the IP address of the admin who acted.

Support tickets and replies are kept in full for 3 years and are not part of the anonymisation.

Accounts an admin closes (a ban) are not anonymised: we keep their data so the ban can be reversed, and their stored results expire on the normal schedule.

8. We Don't Train AI Models on Your Data

Texloom Studio does not use your inputs or outputs to train any AI model — neither ours, nor our AI model providers', nor any other party's.

  • Inputs you upload are sent to the AI model provider for the single purpose of returning your result
  • Outputs are stored only for the retention window your plan provides (see Data Retention above) so you can re-download them
  • No content is set aside for model improvement, fine-tuning, or evaluation
  • Our agreements with AI model providers explicitly forbid them from training on your data

Enterprise procurement reviews can request the relevant contract clauses by emailing support@texloom.studio — we'll share them under NDA.

9. Your Rights Under Indian Law (DPDPA, 2023)

If you are an Indian resident, the Digital Personal Data Protection Act 2023 (DPDPA) gives you specific rights as a Data Principal.

Your rights:

  • Information: Know what personal data we hold about you and how we process it
  • Correction: Have inaccurate or outdated data corrected
  • Erasure: Request deletion when the purpose for processing is over (subject to lawful retention requirements above)
  • Grievance redressal: Raise a complaint with our Grievance Officer
  • Nominate: Designate another person to exercise these rights if you become unable to

Grievance Officer:

  • Name: Texloom Support Team
  • Email: support@texloom.studio
  • Response time: Acknowledgement within 7 days; substantive response within 30 days

If you are not satisfied with our response, you may approach the Data Protection Board of India under DPDPA Section 27.

For users in the EU/EEA, UK, and California: the rights listed in the "Your Rights" section above (GDPR Articles 15–22, UK GDPR equivalents, CCPA/CPRA Sections 1798.100 et seq.) continue to apply. To exercise any right, email support@texloom.studio — we don't gatekeep behind a separate compliance form.

10. Image & Design Retention

Your uploaded images and generated designs are handled separately from account data, with retention based on how you use our tools:

Free tools on /free-tools (signed-out users):
- Browser-based tools — including Format Converter, Vectorize Studio, AI Color Extractor, Color Converter, Texloom Colour Library, Print Calculator, Fabric Yield, Seamless Checker, Image Diff, EXIF Metadata Viewer, Color Blindness Simulator, and similar utilities — process your image entirely in the browser. Your image is never uploaded to our servers, never stored, never copied, and never used to train AI models.
- AI tools that require our servers — including AI Image Upscaler, AI Image Sharpener, Background Remover, Watermark Remover, AI Texture Remover, AI Style Transfer, AI Color Transfer, AI Sketch Colorizer, AI Generative Fill, Inpaint Studio, Pattern Generator, Image-to-Image Editor, and any other tool that calls a cloud AI provider — accept your image only as long as needed to return a result. Images are kept no longer than 24 hours (for in-flight job recovery and download history), then deleted automatically.
- The exact list of browser-only versus AI-server tools may change as we add or migrate tools; the rule is constant: if the tool runs entirely on your device, your image never leaves it.

Studio (signed-in users):
- Free plan: generated results stored 24 hours, then automatically deleted.
- Starter plan: generated results stored 24 hours, then automatically deleted.
- Pro plan: generated results stored 7 days, then automatically deleted.
- Studio plan: generated results stored 30 days, then automatically deleted.
- Enterprise: generated results stored 30 days; download them before they are deleted.
- An image uploaded for an AI tool is kept with the result it produced and deleted with it, on the schedule above.

Across all tiers:
- We never use your images or designs to train AI models.
- We never share your images with third parties beyond the AI processor required to generate your result.
- You can manually delete any stored result from your account dashboard at any time.
- If you create a share link for a result, anyone with that link can view that one result until the link expires or is revoked.
- Closing your account yourself deletes all stored results straight away; if a file can't be deleted then, a cleanup job deletes it later. If an admin closes an account (a ban), its results expire on the normal schedule.

11. The Texloom Studio Chrome Extension

The extension is a separate piece of software you install into Chrome yourself. This
section is the disclosure that covers it, and it is deliberately narrower than everything above,
because the extension does far less than the site does.

It only acts when you ask it to. Nothing runs on a timer, on page load, or in the background.
Every action begins with you: a right-click, a click in the extension's own window, or the keyboard
shortcut.

What is sent to us. One thing: an image you have explicitly chosen. When you right-click a
picture and send it to a tool, that picture is read and handed to texloom.studio so the tool can
open it. That is the whole of it.

The list of tools in its menu. When you install or update the extension, open its window, or
use one of its menu entries, it also fetches the current list of tools for its right-click menu
from texloom.studio. That request carries no cookie and nothing about you or the page you are on.

What is never sent. The pages you visit, their text, links or form fields, your history, your
passwords, and anything you type. Picking a colour, pulling a palette out of a picture, checking a
repeat for seams and reading a print size are all worked out inside the extension itself and
transmit nothing at all.

What is kept, and where. An image waiting to be handed over (cleared after five minutes), the
last six things you sent, shown as small previews, colours you have recently picked, and palettes
you have saved. All of it sits in the extension's own storage on the computer you installed it on.
None of it reaches us. Removing the extension removes it.

Signing in. The extension holds no password, no token and no API key. It relies on the session
you already have with texloom.studio, which it cannot read. If you are not signed in it sends you
to the sign-in page and does nothing else.

Why it asks for access to every site. A designer can right-click a picture on any site, and we
cannot know in advance which one, so Chrome makes us ask for all of them at install. What limits it
is that the extension places no code of its own on any site other than texloom.studio, so on every
other page there is nothing of ours present until the moment you invoke it.

Questions about the extension specifically go to support@texloom.studio, the same address as
the rest of this policy.

12. International Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.

When we transfer your information internationally, we ensure appropriate safeguards are in place to protect your information in accordance with this privacy policy.

13. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

14. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date.

We encourage you to review this privacy policy periodically for any changes.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • Email: support@texloom.studio
  • Address: Batala, Punjab, India

For data protection inquiries in the EU, you may also contact your local data protection authority.