Privacy policy

In force from 4 October 2026

This says what suchnesss.com keeps about you, why, where, for how long, and what you can do about it. The site is run from India, and suchnesss decides how your data is used (the "data fiduciary" under India's Digital Personal Data Protection Act, 2023, and the "controller" under the EU and UK GDPR). Questions go to [email protected].

In short: the site keeps your email, a protected form of your password, and what you make in the Studio. It keeps nothing to advertise to you, sells nothing, shares nothing beyond the services that run the site, and trains no model on your data.

1. What is kept, why, and for how long

WhatWhyKept
Your email addressTo sign you in, and to answer you if you writeUntil you delete the account
Your password, as a salted, keyed PBKDF2 hash (the password itself is never stored and cannot be read back)To check it is youUntil you change it or delete the account
When the account was made and last signed in to; wrong password attempts and any lock they set; which version of these terms you agreed to, and whenSecurity, and a record of your agreementUntil you delete the account
Sessions: a fingerprint (SHA-256) of the random sign in token in your cookie, with when it began, was last used and endsTo keep you signed inUntil you sign out, or 30 days unused, and never past 90 days from signing in
Your designs: the cloth, garment and light, the work stitched, painted and dyed on it, and for a kept piece its name, story and pictureTo keep your work for youUntil you delete the design or the account
Use counts: the time of each request to a part of the site that has a limit, under your account's id or, before you sign in, a keyed hash of your internet address (it cannot be turned back into the address)To stop floods, password guessing and runaway costsAbout 48 hours

Nothing else is stored. In particular:

2. Why the site may use it

Under India's DPDP Act, on the consent you give when you make the account (and again when these terms change), which you can withdraw at any time by deleting the account. Under the GDPR, to provide the service you asked for (Article 6(1)(b)), and for the site's security and the prevention of abuse, a legitimate interest that does not override your rights (Article 6(1)(f)).

3. Who handles it for the site

Only these services, each only for the work described, and none of them is allowed to use it for its own purposes:

Your data is never sold or rented, and is never given to anyone else unless the law requires it (a valid order from a court or authority), in which case only what is required is given.

4. Where it is kept

Cloudflare keeps the database in its data centres and carries requests through its network around the world, so your data may be handled outside India and outside your own country. Cloudflare's agreements include the safeguards the GDPR requires for such transfers (the EU standard contractual clauses and the EU-US Data Privacy Framework).

5. Cookies and storage in your browser

One cookie, __Host-suchnesss, holds your sign in. It is strictly necessary, cannot be read by the page's scripts, is sent only over HTTPS to this site, and lasts 30 days from its last use. There are no advertising or tracking cookies, and Cloudflare Web Analytics sets none. Cloudflare may set a short-lived cookie of its own to tell people from automated attacks. The site stores nothing else in your browser.

6. Your rights

You can, at any time:

Write to [email protected] from the email on your account for anything the account page does not do. You will be asked nothing beyond what proves the account is yours.

Deleted data leaves the live database at once. The database's own recovery history, kept by Cloudflare for restoring after a failure, holds it for up to 30 days more and is then gone.

7. Children

The site is open to everyone, children included. If you are under 18, a parent or guardian agrees to these terms for you when the account is made. It shows no advertising and does no tracking or profiling of anyone. A parent or guardian can ask for a child's account to be deleted by writing in, and it will be.

8. How it is protected

Every connection is encrypted (HTTPS only, with HSTS). Passwords are stored only as salted, keyed PBKDF2 hashes; sign in tokens only as fingerprints. Each account can reach only its own work. The pages allow no scripts to run but the site's own and Cloudflare's page counter. Requests are limited per person and across the site, and repeated wrong passwords lock an account for a while. If a breach of your data ever happens, you will be told, and the Data Protection Board of India and other authorities will be told as the law requires.

Found a weakness? See reporting a security problem.

9. Changes

When this policy changes in substance, the date above changes and you are asked to read and agree to it again before you go on using the site.

10. Contact and grievance officer

Write to the grievance officer at [email protected].