Privacy Policy
1. Overview and Responsibility
Protecting your personal data is important to us. We process your data solely on the basis of the statutory provisions (GDPR, BDSG, TDDDG). In this privacy policy we inform you about the nature, scope, and purpose of the processing of personal data on this website.
The controller within the meaning of the GDPR is:
Leonie Roesmann
Gasselstiege 30l, 48159 Münster
Germany
Email: info@systrastudios.de
Phone: +49 151 11098288
2. Your Rights as a Data Subject
With regard to the data we process about you, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent (Art. 7 (3) GDPR)
To exercise your rights, an informal message to the controller named above is sufficient. A withdrawal or objection does not affect the lawfulness of the processing carried out up to that point.
3. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2 bis 4, 40213 Düsseldorf
www.ldi.nrw.de
4. Access Data and Server Log Files
This website is provided via the development and hosting platform Lovable, a service of Lovable Labs Incorporated with its European entity Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden. The site is delivered through the network of Cloudflare, Inc. (USA). When you access the pages, these providers automatically collect information that your browser transmits and store it in so-called server log files. This includes your IP address, the date and time of access, the page accessed, the amount of data transferred, the browser type, and the operating system.
This processing is necessary for the secure and stable provision of the website. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest). For security reasons the log files are stored for a limited time and then deleted. Data processing agreements pursuant to Art. 28 GDPR are in place with the hosting providers. Processing may also take place in the USA; the transfer is safeguarded by EU standard contractual clauses, and Cloudflare is additionally certified under the EU-US Data Privacy Framework.
5. SSL and TLS Encryption
For security reasons this website uses SSL or TLS encryption. You can recognize an encrypted connection by the browser's address bar and the padlock symbol. This means that the data you transmit to us cannot be read by third parties.
6. Cookies, Local Storage, and Analytics
For the operation of the website and your login, we use technically necessary cookies as well as your browser's local storage, for example for your session, favorites, or your cookie choice. This data is necessary for the website to function (Art. 6 (1) (f) GDPR, § 25 (2) TDDDG), generally does not leave your device, and can be deleted at any time via your browser settings.
Our hosting infrastructure uses the Cloudflare service to protect against automated access (bots). Cloudflare may set the technically necessary cookie “__cf_bm”, which is used for bot detection and expires after a short time (usually 30 minutes). The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure, stable operation) and § 25 (2) TDDDG, as the cookie is strictly necessary for providing the service.
For analytics, with your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). The required script (gtag.js) is loaded only after your consent; without consent, no connection to Google is made. Google Analytics uses cookies that enable an analysis of your use of the website. Google processes the IP address in truncated form; Google Signals and advertising features are disabled. The data may also be processed on servers in the USA; Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses are additionally in place.
The analytics scripts are only loaded if you have consented via the cookie banner (“Statistics” category). The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. You can withdraw your consent at any time with effect for the future by clicking “Cookie settings” in the footer and selecting “Only necessary”. If you choose “Only necessary”, no analytics take place.
7. Contacting Us
If you contact us by email or phone, we process your details to handle the request and in case of follow-up questions. The legal basis is Art. 6 (1) (b) GDPR insofar as your request is related to a contract, otherwise Art. 6 (1) (f) GDPR (legitimate interest in responding). We delete the data as soon as it is no longer required and no statutory retention obligations prevent deletion.
8. Newsletter Sign-Up
If you sign up for our newsletter, we store your email address and the time of sign-up in order to inform you about new components and content. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR.
You can withdraw your consent at any time with effect for the future, for example by sending us a short message. Storage takes place with our service provider Supabase (see the section on account and login), with whom a data processing agreement is in place. Before we actually send any newsletters, we use a double opt-in procedure and confirm your sign-up separately.
9. Submitting a Component
Through the component submission form you can send us proposals and contact details. We process the data provided there solely to review and handle your submission. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the further development of the library), and Art. 6 (1) (b) GDPR for contract-related requests.
Submissions are stored with our service provider Supabase (see the section on account and login). To protect against abuse, we limit the number of submissions per day; for this purpose we temporarily store a non-reversible check value (hash) of your IP address from which the address itself cannot be reconstructed. The legal basis for this is Art. 6 (1) (f) GDPR (protection against automated abuse).
10. Account and Login (Supabase)
For login and the management of your account, we use Supabase, a service of Supabase, Inc. (USA). This stores your email address, login data, and profile information (such as your premium status). The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). A data processing agreement is in place with Supabase; processing may also take place in the USA and is safeguarded by EU standard contractual clauses. The data is deleted when you delete your account.
In connection with your account we also send transactional emails, for example to confirm your email address, to reset your password, a welcome message, or a confirmation after purchasing premium access. These emails are part of account management and contract performance (Art. 6 (1) (b) GDPR); they are not advertising. Account emails (confirmation, password reset) are sent via the email infrastructure of our login provider Supabase; purchase confirmations and invoices are sent by our payment provider Lemon Squeezy (see the payment processing section). The required agreements are in place with both.
11. Sign-In with Google
For login you can optionally use the „Sign in with Google“ feature. If you choose this option, you are redirected to Google. Google processes your login there and then transmits basic profile data (such as email address, name, and your Google account id) to our application so that your account can be created or you can be authenticated. Google Ireland Ltd. is the controller for the processing on Google's side.
The purpose is authentication and the creation of your account. The legal basis is Art. 6 (1) (b) GDPR (performance of the sign-in you requested) and, where applicable, your consent pursuant to Art. 6 (1) (a) GDPR. Using Google sign-in is voluntary. Alternatively, you can register and log in with your email address and password at any time.
12. Payment Processing (Lemon Squeezy)
Premium access is processed via the payment service provider Lemon Squeezy. When you make a purchase, Lemon Squeezy processes the data required for payment (name, email address, payment information) as an independent controller. We receive a customer reference and the subscription status from Lemon Squeezy. The legal basis is Art. 6 (1) (b) GDPR.
You can also buy without an existing account. In that case we automatically create an account after the payment using the email address Lemon Squeezy reports for the order, and unlock access on it. The legal basis is Art. 6 (1) (b) GDPR (performance of the purchase contract). So that you are signed in right after paying, your browser generates a random number before checkout and sends it along; of that we store only a non-reversible check value (hash) next to your account. It is valid once and for at most 30 minutes, and is invalidated afterwards.
13. Feedback Form
On the „About“ page you can send us feedback about the library through a form. Only your message is required. Name, role or company, email address and a star rating are optional. We process this information in order to read your feedback, take it into account as we develop the library and reply if anything is unclear. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving our offering).
If you tick the corresponding checkbox, we may publish your feedback together with the name and role you provided as a review on this website. The legal basis for this is solely your consent under Art. 6 (1) (a) GDPR. Without this consent your feedback is not shown publicly. We never publish your email address. You can withdraw your consent at any time informally by email to info@systrastudios.de; we will then remove the review from the website. This does not affect the lawfulness of processing carried out before the withdrawal.
Feedback is stored with our service provider Supabase (see the section on account and login). To protect against abuse, we limit the number of submissions per day; for this purpose we temporarily store a non-reversible check value (hash) of your IP address from which the address itself cannot be reconstructed. The legal basis for this is Art. 6 (1) (f) GDPR (protection against automated abuse).
14. Style Extractor
With the Style Extractor you can analyze publicly accessible websites. For this, we process the address you enter and store the result of the analysis. Beyond the address you enter and the standard request data, no personal data of yours is intentionally transmitted. The legal basis is Art. 6 (1) (b) and (f) GDPR (performance of the analysis you requested and legitimate interest in providing the feature).
To provide this feature we use specialized service providers: the website you enter is retrieved via a scraping service (Firecrawl), and an external AI service (the Lovable AI Gateway, which accesses a Google language model, Gemini 2.5 Flash) analyzes the page and prepares the result (colors, typography, design tokens). Only the public address you enter and the page content retrieved for analysis are transmitted, no personal data from your account. The required data processing agreements are in place with these providers. Firecrawl and Google are US providers; processing may therefore also take place in the USA and is safeguarded by EU standard contractual clauses, and Google is additionally certified under the EU-US Data Privacy Framework.
We store the result of the analysis: the detected colors, fonts and design tokens, the address you entered, the name, short description, favicon and logo of the site, and an image capture of the page that serves as the preview. We do not store the HTML or CSS source of the analyzed page. Results are tied to your account and are not public unless we approve them for the gallery after you propose them. You can delete individual results in your account at any time; at the latest, deleting your account removes every entry. Analyses created while signed out are deleted after 30 days.
The number of analyses per day is limited. For signed-in users we count against your account; when you are not signed in we temporarily store a non-reversible check value (hash) of your IP address from which the address itself cannot be reconstructed. The legal basis for this is Art. 6 (1) (f) GDPR (protection against automated abuse).
15. Fonts
The fonts used on this website are embedded locally on our own server (self-hosted) and delivered from there. No connection to Google's servers or other third-party providers is established, and your IP address is not transmitted to any third party in order to load the fonts.
16. Image Delivery via wsrv.nl
For fast and data-efficient delivery of images we use the external image service wsrv.nl (images.weserv.nl, operated on the basis of Cloudflare). Images are computed and delivered in the appropriate size on demand. When such an image is loaded, your IP address is transmitted to this service, together with the requested image URL and the standard request metadata (such as the browser type and the time of the request).
The purpose is server-side resizing and the fast delivery of the images. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a fast, bandwidth-efficient presentation of the content). The service does not set its own cookie for this.
17. Storage Period
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods. If the purpose no longer applies and there are no retention obligations, the data is deleted or anonymized.
18. Changes to This Privacy Policy
We adjust this privacy policy whenever changes to our services or the legal situation make it necessary. The version published on this page applies. Last updated: August 5, 2026.