Privacy policy
In force from 4 October 2026
This says what suchnesss.com keeps about you, why, where, for how long, and what you can do about it. The site is run from India, and suchnesss decides how your data is used (the "data fiduciary" under India's Digital Personal Data Protection Act, 2023, and the "controller" under the EU and UK GDPR). Questions go to [email protected].
In short: the site keeps your email, a protected form of your password, and what you make in the Studio. It keeps nothing to advertise to you, sells nothing, shares nothing beyond the services that run the site, and trains no model on your data.
1. What is kept, why, and for how long
| What | Why | Kept |
|---|---|---|
| Your email address | To sign you in, and to answer you if you write | Until you delete the account |
| Your password, as a salted, keyed PBKDF2 hash (the password itself is never stored and cannot be read back) | To check it is you | Until you change it or delete the account |
| When the account was made and last signed in to; wrong password attempts and any lock they set; which version of these terms you agreed to, and when | Security, and a record of your agreement | Until you delete the account |
| Sessions: a fingerprint (SHA-256) of the random sign in token in your cookie, with when it began, was last used and ends | To keep you signed in | Until you sign out, or 30 days unused, and never past 90 days from signing in |
| Your designs: the cloth, garment and light, the work stitched, painted and dyed on it, and for a kept piece its name, story and picture | To keep your work for you | Until you delete the design or the account |
| Use counts: the time of each request to a part of the site that has a limit, under your account's id or, before you sign in, a keyed hash of your internet address (it cannot be turned back into the address) | To stop floods, password guessing and runaway costs | About 48 hours |
Nothing else is stored. In particular:
- Questions to the chat and requests to the Studio are sent to the AI model to answer and are not stored by the site. The chat's conversation lives only in your open page.
- Photographs sent to Look are made smaller and re-encoded on your own device first, which removes the hidden data a camera writes into them (such as where the photo was taken). The picture is sent to the vision model, judged, and not stored.
- The site uses no advertising, no tracking across other sites, and no profiling.
2. Why the site may use it
Under India's DPDP Act, on the consent you give when you make the account (and again when these terms change), which you can withdraw at any time by deleting the account. Under the GDPR, to provide the service you asked for (Article 6(1)(b)), and for the site's security and the prevention of abuse, a legitimate interest that does not override your rights (Article 6(1)(f)).
3. Who handles it for the site
Only these services, each only for the work described, and none of them is allowed to use it for its own purposes:
- Cloudflare, Inc. hosts the site and its database (Cloudflare Pages and D1), runs every AI model (Workers AI), carries every request and protects the site from attack, and counts page visits without cookies (Cloudflare Web Analytics). The models it runs for the site are Google's Gemma, Meta's Llama, Alibaba's Qwen and Mistral's Mistral Small, on Cloudflare's own servers: your words and pictures go to Cloudflare, not to those companies. See Cloudflare's privacy policy.
- Have I Been Pwned (Pwned Passwords) checks, when you choose a password, whether it has appeared in a public breach. Only the first 5 of the 40 characters of the password's SHA-1 fingerprint are sent, so neither the password nor its fingerprint ever leaves the site.
Your data is never sold or rented, and is never given to anyone else unless the law requires it (a valid order from a court or authority), in which case only what is required is given.
4. Where it is kept
Cloudflare keeps the database in its data centres and carries requests through its network around the world, so your data may be handled outside India and outside your own country. Cloudflare's agreements include the safeguards the GDPR requires for such transfers (the EU standard contractual clauses and the EU-US Data Privacy Framework).
5. Cookies and storage in your browser
One cookie, __Host-suchnesss, holds your sign in. It is strictly necessary, cannot be read by the page's scripts, is sent only over HTTPS to this site, and lasts 30 days from its last use. There are no advertising or tracking cookies, and Cloudflare Web Analytics sets none. Cloudflare may set a short-lived cookie of its own to tell people from automated attacks. The site stores nothing else in your browser.
6. Your rights
You can, at any time:
- see and take your data: the account page downloads everything the account holds as one file;
- delete it: the account page deletes the account and everything made in it, at once; a single design can be deleted in the Studio;
- correct it: change your password on the account page, or write to change your email;
- withdraw consent: delete the account; what was done before stays lawful;
- object, or ask for use to be restricted, under the GDPR;
- nominate someone to use these rights for you if you die or cannot, under the DPDP Act;
- complain: first to the grievance officer below. If the answer does not satisfy you, in India to the Data Protection Board of India, and in the EU or UK to your data protection authority.
Write to [email protected] from the email on your account for anything the account page does not do. You will be asked nothing beyond what proves the account is yours.
Deleted data leaves the live database at once. The database's own recovery history, kept by Cloudflare for restoring after a failure, holds it for up to 30 days more and is then gone.
7. Children
The site is open to everyone, children included. If you are under 18, a parent or guardian agrees to these terms for you when the account is made. It shows no advertising and does no tracking or profiling of anyone. A parent or guardian can ask for a child's account to be deleted by writing in, and it will be.
8. How it is protected
Every connection is encrypted (HTTPS only, with HSTS). Passwords are stored only as salted, keyed PBKDF2 hashes; sign in tokens only as fingerprints. Each account can reach only its own work. The pages allow no scripts to run but the site's own and Cloudflare's page counter. Requests are limited per person and across the site, and repeated wrong passwords lock an account for a while. If a breach of your data ever happens, you will be told, and the Data Protection Board of India and other authorities will be told as the law requires.
Found a weakness? See reporting a security problem.
9. Changes
When this policy changes in substance, the date above changes and you are asked to read and agree to it again before you go on using the site.
10. Contact and grievance officer
Write to the grievance officer at [email protected].