CatchUI is operated by its sole operator, based in Hong Kong ("we"). This policy explains what data the Service handles and where it goes. The short version: CatchUI is local-first — without an account your library never leaves your browser; screenshots you scan are processed transiently by our AI provider and are not stored on our servers; payments are handled by Stripe and we never see your card number.
Without an account, your pattern library (cards, image crops, notes, review history) is stored in your browser's localStorage and never transmitted to us. Clearing browser data deletes it. We use no advertising or analytics cookies.
When you scan a screenshot, the image is compressed in your browser and sent to our API, which forwards it to our AI vision provider, Volcengine (ByteDance) "Ark", to produce recognition results. Our servers do not store your screenshots or the recognition output — the image is processed in memory and discarded when the response is returned. The AI provider may process the image on servers located in China; its handling is governed by Volcengine's own terms. Do not scan screenshots containing material you are not permitted to share.
If you sign in (email link, no password), we store: your email address and a user ID (managed by our auth/database provider Supabase), and — once you sync — your cards (including image crops), correction feedback, and review history, so your library follows you across devices. Cards you explicitly publish are stored as minimal public snapshots reachable only by their share link.
To enforce free-tier limits, anonymous scans are counted against a key derived from your IP address, stored in Upstash Redis and expiring within ~26 hours. Our server logs (hosted by Vercel) record request metadata with hashed IP addresses for abuse prevention and debugging. If the app crashes in your browser, an anonymous error report (error text, page path, browser version — never your library content or identity) is sent to us and kept for about a week.
Subscriptions are processed by Stripe. Your card details go directly to Stripe and never touch our servers. We store only your Stripe customer ID and subscription status (plan, period end) to grant Pro features. Stripe's processing is governed by its own privacy policy.
| Processor | Purpose | Data |
|---|---|---|
| Volcengine (ByteDance) | AI screenshot recognition | Screenshot image (transient) |
| Supabase | Auth & cloud sync database | Email, user ID, synced library |
| Stripe | Payments | Billing details (held by Stripe) |
| Vercel | Hosting, logs & cookieless page analytics | Request metadata, hashed IPs, anonymized page views |
| Upstash | Quota counters | IP-derived keys (≤26 h) |
| ImprovMX | Support email forwarding | Emails you send to support@ |
We do not sell your data, run ads, use tracking cookies, or profile you. We access synced data only as needed to operate the Service or as required by law.
Local data is yours to delete at any time (release cards, or clear browser storage). Synced data is kept while your account exists. To delete your account and all synced data, use the "Delete account" button in the app's account menu — deletion is immediate and also cancels any active subscription — or email support@catchui.com from your account email (verified requests completed within 30 days). The app's account menu also offers a JSON export of your library. Cancelling a subscription does not delete your account.
We are based in Hong Kong and use processors in the United States (Supabase, Vercel, Stripe, Upstash) and China (Volcengine, for screenshot processing only). By using the Service you acknowledge these transfers.
The Service is not directed to children under 13, and we do not knowingly collect their data.
We will post updates to this policy here and, for material changes affecting account holders, notify you in the app or by email.
The CatchUI Operator, Hong Kong · support@catchui.com