The short version
SetupViz works without an account. Your selected setup, optional budget target, and manual planned or purchased marks are kept in your browser so they can be restored on the same device. Guest mode does not ask for an email address.
Optional account sync appears only when its complete Supabase and anti-abuse configuration is available. You can then request an email magic link and choose to keep one private setup with your account. SetupViz does not ask for your name, password, payment details, shipping address, or retailer credentials.
Shopping happens on the retailer's site. The current SetupViz app does not receive or process your retailer checkout information.
Optional account and cloud copy
If account sync is available and you request it, Supabase Auth processes your email address, creates an Auth user ID, and manages confirmation and session records. The configured email provider processes the recipient address and delivery details to send the one-time link. Cloudflare Turnstile may process normal anti-abuse connection and challenge data before the request is accepted. SetupViz does not store the challenge token after that request.
Your private cloud row contains the Auth owner ID, the same v2 setup fields described above, a revision number, and created and updated times. It does not contain your email address, retailer destination URLs, retailer price snapshots, calculated price differences, share URLs, retailer click history, or retailer purchase confirmation. There is at most one cloud setup per account.
Signing in does not automatically upload, merge, or replace either copy. When the device and account copies differ, SetupViz asks you to use one complete copy. Changes save on the device first; if a cloud request fails, the device copy remains and SetupViz reports that sync did not finish.
Authenticated setup, export, and deletion requests include the current Auth user ID as an expected-account guard. SetupViz compares it with a fresh Auth user result to stop an in-flight request if the signed-in account changed. The guard never chooses another account or database row and is not stored as a separate record.
Auth and live cloud data remain until you delete the cloud copy or account. A cloud-only deletion leaves the account and device copy; account deletion revokes refresh sessions, deletes the Auth user, and cascades the live cloud row, but still leaves the device copy until you clear it separately. Already issued access tokens can remain valid until they expire. Operational logs and backups follow the reviewed provider settings; before public account availability, their exact windows must be listed in the production data register, with a SetupViz target of no more than 30 days and a restore procedure that reapplies later deletions. Deleting an account does not erase an active anti-abuse window: its keyed digest stops being valid at the fixed expiry, no later than 24 hours, and is removed by a later limiter request.
What stays in your browser
SetupViz uses browser local storage to remember the gear you add. The saved record contains catalog product IDs, a unique instance ID for each saved item, the time it was added, and a storage-format version. It may also contain one validated catalog retailer-offer ID for each item, an optional budget target, and a manual planned or purchased mark for each item. These marks are a personal checklist; SetupViz does not verify them against a retailer order. The record does not contain retailer destination URLs, retailer price snapshots, calculated price differences, free-form notes, or contact information.
Choosing Clear this devicepauses account sync and asks the browser to remove both current and legacy saved setup records. It does not delete the separate cloud copy. If the browser denies removal, SetupViz clears the current session and tells you that saved data may remain; clearing this site's browser storage removes it. If local storage is unavailable, the builder remains usable for the current visit but may not restore your choices later.
What happens when the site loads
Like any website, the infrastructure serving SetupViz receives technical request data needed to return a page and protect the service. That can include an IP address, browser or device information, requested page, referrer, and request time. Retention depends on the hosting configuration in use for the deployed site.
If you use optional account sync, the Auth provider and SetupViz receive the requests needed to send and complete the magic link. The callback briefly processes a bounded, browser-bound one-time code, uses a fixed redirect back to the builder, and removes that credential from the visible URL. Transferable token-hash callbacks are rejected. SetupViz application code must not log the full callback URL, session cookie, email address, or setup payload.
To enforce account-route limits across server instances, SetupViz converts the hosting platform's trusted IP address and, after authentication, the Auth user ID into separate server-keyed digests. The rate-limit row stores only the route scope, whether the digest is for an account or IP, a request count, and window start and expiry times. It does not store the raw IP address, Auth user ID, email address, callback credential, or setup contents. A bucket stops being valid when its fixed window ends, no later than 24 hours, and expired rows are removed by later limiter requests.
When you choose a retailer link, that retailer receives the request and applies its own privacy practices. SetupViz does not control the retailer's checkout, cookies, account, or order records. SetupViz does not receive confirmation that an item was added to a cart or purchased; any purchased mark in the builder is entered manually on this device.
Product and performance measurement
On a non-local deployment where Vercel Analytics is configured, SetupViz may send first-party page-view and product-flow events. These help answer practical questions such as whether people reach the builder, add gear, complete a setup, request a share link, or choose an outbound shopping link.
Where Vercel Speed Insights is enabled, SetupViz may also report page-performance measurements such as loading speed, responsiveness, and visual stability, together with the limited route and technical context needed to understand those measurements. This is used to find slow or unstable parts of the experience, not to build a SetupViz user profile.
Event details are limited to product-use context such as CTA placement, builder entry source, product IDs, item counts, reference setup value in cents, and whether affiliate tracking is enabled. Each custom event has at most two properties. SetupViz does not add names, email addresses, selected retailer-offer IDs, retailer destination URLs, or the contents of a share link to those event payloads. Auth user IDs, setup revisions, sessions, cloud payloads, budget targets, and manual planned or purchased marks are also excluded. The analytics boundary does not read or set cookies or local storage itself. The configured providers still receive normal connection data needed to process a web request and apply their own configured retention and privacy practices.
Custom SetupViz events are inactive on localhost. Reporting on a deployed site depends on the analytics configuration for that deployment.
Your choices and privacy requests
You can pause sync and remove the setup, budget target, and manual shopping marks stored on this device with Clear this device; your cloud copy remains until you use the separate cloud deletion action. If you use an account, its tools let you export the email, account creation time, and cloud setup held for you; delete only the cloud copy; sign out while keeping or clearing the device copy; or delete the account after a recent sign-in. That recent sign-in check uses a signed non-refresh authentication-method time, not the time an access token was refreshed. Setup data can be corrected by editing it. Until verified email change is self-service, contact support for email correction or export, delete, and recreate the optional account. The self-service export does not include short-lived anti-abuse counters; contact support with an access or correction question about them.
You can copy only catalog choices into a share link when you choose. A copied share link cannot be recalled from someone who already received it, and deleting an account does not remove copies of that link from other people, messages, clipboards, or browser histories.
For a privacy, accessibility, or support request, email privacy@setupviz.com. Sending an email provides its sender address and message so the request can be answered; those details are kept only as long as operationally necessary. Include only the information needed to understand your request. SetupViz does not need your retailer password or payment details.
When this notice changes
This notice describes guest mode and the optional one-setup account feature. It will be revised before SetupViz introduces additional account fields, multiple setups, collaboration, additional analytics, cookies, advertising, an on-site support form, or other uses of personal information.
Material changes will be reflected here with a new update date. Review this page again when returning after a significant product release.