Privacy Policy

How Codifiq LLC collects, uses and protects information in Sartoria.

Version 2026-07-27 · Effective 27 July 2026

Overview

Codifiq LLC operates Sartoria, a product lifecycle management service for garment design at sartoria.codifiq.com. This policy explains what information we collect, why, who we share it with, and the choices you have. It covers the Sartoria application and the emails we send about it.

The short version: we collect the minimum needed to run a multi-tenant design tool — who you are, which company you belong to, and the designs you create. We use no analytics, no tracking pixels and no advertising. We do not sell personal information, and neither we nor our AI provider use your designs to train models.

Our role: controller and processor

Account data. For information about the people who hold accounts — names, email addresses, roles, sign-in records — we act as a controller and decide how it is handled.

Content you create. For everything you put into a workspace — sketches, renders, prompts, style records, libraries, tech packs and any personal data they happen to contain — we act as a processor on behalf of your organisation, which is the controller. We handle that content only on your organisation’s instructions, as set out in our Data Processing Addendum.

If your employer gave you the account. Your organisation’s administrators can see, change and delete the content in your workspace and can remove your account. Questions about how your employer uses the Service should go to them; we will direct requests we receive about workspace content to the relevant organisation.

Information we collect

Account
Your name, email address and role. Your password is set and stored by our authentication provider as a cryptographic hash; we never see or store it.
Organisation
Your company name, brand names, brand memberships and role assignments, and the email address, role and status of anyone invited to your workspace.
Design content
Uploaded sketches, reference photographs, print artwork and CAD files, generated renders, style records (name, category, department, season, stage, review status and review notes), colour, print and fabric libraries, colourways, and tech pack contents including bills of material, measurement points, construction notes and trims.
Generation records
The instruction you typed, the full prompt assembled from it, the stage and views requested, the provider and model used, any error returned, and timestamps. These give you the version history of a style and let us diagnose failures.
Agreement records
When you accept these documents at signup or when joining a workspace, we record the date and time, the versions accepted, the IP address the acceptance came from and your browser’s user agent string. This is our evidence that an agreement was formed, and we keep it even if the account is later removed.
Technical
Two cookies (see “Cookies”), and the request metadata our hosting and database providers process to deliver and secure the Service, which includes IP addresses and timestamps in their operational logs. Our application itself writes no analytics or IP logs.
Correspondence
Emails and messages you send us for support, and our replies.

We read one request header, the coarse time zone your hosting region reports, purely to say “good morning” rather than “good evening” on the dashboard. It is used in the moment and never stored.

What we do not do

  • No advertising, no ad networks, no marketing pixels, no cross-context behavioural tracking.
  • No analytics or session-replay tooling, and no third-party scripts that observe your use of the product.
  • No sale or sharing of personal information, and no monetisation of your designs.
  • No training of AI models on your content, by us or by our AI provider.
  • No collection of sensitive categories of personal data — health, biometrics, precise location, financial account or government identifiers. Please do not upload them.
  • No automated decision-making that produces legal or similarly significant effects about a person.

How we use information

  • To provide the Service: authenticate you, keep your organisation’s data separated from every other organisation’s, store and serve your files, and generate renders you ask for.
  • To operate and secure the platform: prevent abuse, investigate incidents, enforce our Terms and fair usage limits, and maintain backups.
  • To support you: answer questions, diagnose failed generations, and fix defects.
  • To communicate: account and transactional email such as confirmation, password reset, invitations and material changes to these documents. We do not send marketing email without your consent.
  • To improve the Service using aggregated, de-identified statistics such as error rates and generation timings, which do not identify you or reveal your designs.
  • To comply with law and to establish, exercise or defend legal claims.

Legal bases (EEA, UK and Switzerland)

Contract
Creating and running your account, providing the Service, and supporting you — processing necessary to perform our agreement with you.
Legitimate interests
Securing the Service, preventing abuse, keeping evidence of agreement, improving the product with aggregated statistics, and defending legal claims — balanced against your rights and interests.
Legal obligation
Retaining records and responding to lawful requests where the law requires it.
Consent
Anything optional we may add later, such as marketing email. You can withdraw consent at any time without affecting prior processing.

Where we process workspace content on behalf of your organisation, the legal basis is determined by that organisation as controller.

AI processing and Google Gemini

Generating a render requires sending your work to a third-party model. This section says exactly what leaves the Service, because it is the question designers ask first.

What we send. When you generate, we transmit to Google’s Gemini API the source image for that stage (your uploaded sketch or an earlier render), any reference photograph or detail image you attach to the request, and the composed text prompt, which includes your instruction and context such as the style name, garment category, season, department and the names of the colourway and fabric you selected. When you use a reference photograph to describe a garment, that photograph is sent for analysis and is not stored by us.

What we do not send. We do not send your name, email address, company identity or account identifiers to the model provider. Requests are authenticated with our own API credentials, not yours.

Training. We use the paid tier of the Gemini API. Under Google’s terms for paid services, Google does not use prompts or responses submitted through it to train or improve its models. Google may retain them for a limited period for abuse monitoring, security and legal compliance, and processes them as our subprocessor.

Human review. No one at Codifiq LLC reviews your designs as a matter of course. We access workspace content only when you ask us to for support, when we must investigate a security or abuse issue, or when the law requires it.

Sharing and subprocessors

Within your organisation. Content is visible to members of your organisation according to their brand memberships and role. Administrators can see and manage everything in the organisation.

Service providers. We share information with a short list of vendors that host, secure and operate the Service: Vercel (application hosting), Supabase (database, authentication and file storage), Google (AI generation) and Resend (delivery of authentication email). Each processes data on our instructions under a written agreement. The current list, with the purpose and data categories for each, is published on our subprocessors page.

Legal and corporate. We may disclose information where required by law or valid legal process, to enforce our Terms, or to protect the rights, safety and property of Codifiq LLC, our customers or the public. Where lawful, we will tell you first. If we are involved in a merger, acquisition or sale of assets, information may transfer as part of it, subject to this policy.

Never. We do not sell personal information, share it for cross-context behavioural advertising, or make it available to data brokers.

International transfers

The Service is hosted in the United States, and our providers are United States companies with global infrastructure. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to and processed in the United States.

For those transfers we rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, incorporated into our Data Processing Addendum and into our agreements with our providers. Where a provider is certified under the EU-US Data Privacy Framework, we may also rely on that certification. We take account of the safeguards described in our Security section when assessing these transfers, and we will provide a copy of the relevant clauses on request to privacy@codifiq.com.

How long we keep information

Account data
For as long as the account exists, and for a reasonable period afterwards to complete offboarding.
Workspace content
Until you delete it or your organisation is closed. Archived styles are hidden from lists but retained, so archiving is not deletion.
Generation records
For the life of the style they belong to, since they are its version history.
Invitations
Until accepted or revoked, and then as a record that access was granted.
Agreement records
For as long as needed to establish or defend a legal claim, normally no more than six years after the account closes.
Backups
Copies persist in our providers’ encrypted backups and are overwritten on a rolling schedule after deletion from active systems.
Correspondence
Support email for as long as needed to handle the matter and keep a service history.

After termination we keep Customer Content for a thirty (30) day export window, then delete it from active systems within a reasonable period, unless the law requires us to keep it.

Deleting your data

What you can delete yourself. Administrators can remove a member, which deletes their account and profile; delete a brand that holds no styles; remove colours, prints and fabrics from a library when no style uses them; and delete individual studio iterations. Styles can be archived from the app.

What needs a request. Permanently deleting an archived style, an entire brand’s history or your whole organisation is not yet self-service. Write to privacy@codifiq.com from an administrator address and we will carry it out, confirm when it is done, and tell you what, if anything, we must retain and why.

Honesty about backups. Deletion removes content from the live Service immediately. Copies in encrypted backups disappear as those backups rotate out, and we do not restore deleted content from them except to recover from an incident.

Your privacy rights

Everyone. You may ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to privacy@codifiq.com from the address on your account, or tell us enough to verify who you are. We respond within thirty (30) days, and will tell you if we need longer.

EEA, UK and Switzerland. You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, including objection to processing based on legitimate interests, and the right to withdraw consent where we rely on it. You may also lodge a complaint with your supervisory authority; we would appreciate the chance to address it first.

California. Under the CCPA as amended by the CPRA you may request the categories and specific pieces of personal information we collected, the sources, the purposes and the categories of recipients; request correction or deletion; and opt out of sale or sharing. We do not sell or share personal information and have not done so in the preceding twelve months, and we do not collect sensitive personal information, so there is nothing to opt out of or limit. We will not discriminate against you for exercising a right. An authorised agent may act for you with written permission we can verify.

Other United States states. Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah and Texas, have comparable rights of access, correction, deletion, portability and appeal. Use the same address, and if we decline a request you may appeal by replying to our decision.

Requests about workspace content. If your request concerns content inside an organisation’s workspace, we act as processor and will refer you to that organisation, and assist them in responding.

Cookies

We use two cookies, both strictly necessary, and no others:

Session
Set by our authentication provider to keep you signed in and to refresh your session as you navigate. Removing it signs you out.
active_brand
Remembers which brand you are working in so the app shows the right library and styles. A preference, not a tracker.

Because we run no analytics or advertising cookies, there is nothing to consent to and we show no cookie banner. If that ever changes, we will ask first.

Security

  • Data is encrypted in transit with TLS and at rest by our database and storage providers.
  • Every organisation’s rows are isolated at the database level by row-level security, not only by application code, so a query cannot reach another tenant’s data.
  • Uploaded and generated files live in a private storage bucket with no public URLs. Images are served through short-lived signed links that expire after an hour.
  • Passwords are hashed by our authentication provider; we never handle them. Sign-in, invitation and password reset flows are email-verified.
  • Administrative credentials are held server-side only and never exposed to the browser.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any regulator without undue delay as the law requires, and, where we act as your processor, within the timeframe set in our Data Processing Addendum. Report a vulnerability to security@codifiq.com.

Children

The Service is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, write to privacy@codifiq.com and we will delete it.

Changes to this policy

We will update this policy as the Service changes. The version and date at the top of the page always reflect the current text. For material changes we will give notice by email or in the Service before they take effect, and where the law requires it we will ask for your consent.

Contact us

Controller
Codifiq LLC
Privacy
privacy@codifiq.com
Security
security@codifiq.com
Address
[Codifiq LLC registered address — to be completed]
EU representative
[To be appointed under Article 27 GDPR — contact privacy@codifiq.com in the meantime]