Privacy Policy
1. Who we are
Mockvid is operated by LARGUIER MICKAEL (EI), a sole trader registered in France. Contact: contact form.
2. Data we process
Mockvid is designed to collect as little data as possible:
- IP address: used server-side solely to enforce rate limits (max renders per day). For free-tier usage, not stored beyond the current server session and reset on restart.
- URLs you submit: processed in memory to perform the capture. For free-tier usage, not stored or logged after the request completes.
- Licensed (paid) usage audit log: when a request carries a valid license key, we additionally record the IP address, the captured domain/URL, and export metadata (file size, format, resolution) in an internal log, kept for up to 12 months. This is used solely to investigate refund disputes and abuse, and is never used for marketing or shared with third parties.
- Figma links, frame identifiers and access tokens: if you use the Figma capture feature, your Figma link, selected frame identifiers and access token are sent to our server only to list frames and export the selected frame for that request. We do not store your Figma access token on our servers, and we do not log it.
- Temporary render files: video and screenshot files are automatically purged within 72 hours.
- Shareable 3D links (embeds): when you publish a shareable link, the associated scene data is stored on our server for as long as the link exists. Embeds are kept indefinitely, subject to an internal storage cap; oldest files are evicted first if that cap is ever reached. We also store a one-way cryptographic hash of your license key alongside the embed (never the key itself), solely to let you prove ownership later (we have no accounts, so this is the only way to verify it's really yours). You can list, edit, or delete your embeds at any time from the Saved renders menu in the app (your license key is required and is never sent anywhere but our server).
We do not require an account. We do not collect your name, email, or any personal identifier to use the free tier.
3. Paid purchases
Payments are processed by Polar (Polar Software Inc.), our payment provider. When you purchase a plan, Polar collects your payment details and email address in accordance with their privacy policy. We receive the license key, the domain you purchased for, and your email address, which we use to send you a single transactional email containing your license key and usage instructions (delivered via Resend, see Section 5). No payment card data is stored on our servers.
4. Cookies & analytics
The app uses localStorage to remember your last settings, license key and, if you choose to use Figma capture, your Figma access token locally in your browser. License keys and Figma tokens are sent to our server only when needed to verify access, restore paid features, list Figma frames or export a selected Figma frame.
With your consent, we use Google Analytics 4 to understand how Mockvid is used (pages visited, approximate location from IP, device type). This is opt-in: no analytics cookie is set and no data is sent to Google until you accept it in the cookie banner shown on your first visit (we use Google's Consent Mode signal to block data collection by default). You can withdraw consent or change your choice at any time via Cookie settings. The embeddable viewer (/v/:id) never loads analytics or shows this banner, regardless of where it is embedded.
Google Analytics is provided by Google Ireland Ltd. in accordance with Google's privacy policy.
With the same consent, we also use PostHog for product analytics and session replay, which help us understand how features are used and where the app is confusing. Session replay records a playback of your interactions with the app (clicks, navigation, scrolling); form fields and other text inputs are masked by default and their contents are not captured. Like Google Analytics, this is opt-in: nothing is loaded or sent to PostHog until you accept analytics in the cookie banner, and you can withdraw at any time via the same Cookie settings. PostHog data is hosted in the European Union (PostHog Cloud EU), and the embeddable viewer (/v/:id) never loads it.
5. Third-party services
- Polar: payment processing and license management.
- Figma (Figma, Inc.): optional design-frame retrieval when you use the Figma capture feature. Your Figma access token is used only to call Figma's API for your requested file or frame and is processed in accordance with Figma's privacy policy.
- Resend (Resend, Inc.): transactional and support email. We use it to send you your license key after a purchase, and to receive the messages you send to our support address or through the in-app feedback and contact forms. Your email address and message content are processed in accordance with Resend's privacy policy.
- Cloudflare Turnstile: anti-bot verification on the contact form. It processes technical browser signals to distinguish humans from bots, with no advertising use, in accordance with Cloudflare's privacy policy.
- Google Fonts: fonts loaded on the landing page (standard Google CDN request).
- Google Analytics 4: usage analytics, only after your consent (see Section 4).
- PostHog (PostHog, Inc.): product analytics and session replay, hosted on PostHog Cloud EU, only after your consent (see Section 4). Processed in accordance with PostHog's privacy policy.
No advertising networks or data brokers receive your data.
6. Hosting
Mockvid is hosted on servers operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Server logs (access logs) may be kept by the hosting provider in accordance with their standard practices.
7. Your rights (GDPR)
If you are in the EU/EEA, you have the right to access, correct, or delete any personal data we hold. Our own servers store no personal data beyond transient IP-based rate limits, temporary render files, optional embed/saved files, and — for licensed (paid) usage only — the audit log described in Section 2; if you made a purchase, your email address and purchase-related messages are held by our processors Polar and Resend, and if you accepted analytics, usage and session-replay data is held by PostHog. Figma tokens are not stored on our servers. We will relay any access or deletion request to the relevant processors where appropriate. For any question, contact us.
8. Data retention
Render files: auto-deleted within 72 hours. Temporary Figma export files are treated as render files and purged on the same schedule. Rate-limit counters: reset on server restart. Saved files: stored indefinitely, subject to an internal storage cap, evicted oldest-first if that cap is ever reached. Licensed-usage audit log (IP, captured domain/URL, export metadata): kept up to 12 months, then purged (see Section 2). No database of users is maintained.
9. Changes
We may update this policy. The effective date above will reflect the latest revision.