Privacy Notice v1.0 · effective 27 July 2026
Your data is for access, delivery and support.
KREYD LABS LTD, trading as GUMMY UI, is the controller for Gummy UI account, entitlement, support and website data. Stripe and Link are separately responsible for payment and transaction-support data they handle through Managed Payments.
1. Contact and scope
Controller: KREYD LABS LTD, company 17152066, 133 Whitmore Road, Harrow, United Kingdom, HA1 4AG. Privacy requests: support@kreydlabs.com.
This notice covers gummyui.dev, Gummy UI accounts, paid entitlements, downloads and support. The public GitHub repository and third-party services have their own notices where you use them directly.
2. Data we use and why
- Account and workspace: name, email, identity-provider identifier, session/security state, workspace, role and invitations. Used to perform the contract, secure access and administer seats.
- Orders and entitlements: Stripe customer/order references, plan, amount/currency, tax and payment status, invoice reference, licence, entitlement and download history. Used to perform the contract, prevent fraud and meet legal/financial record duties. We do not store full card details.
- Support and rights requests: email address, message, attachments you choose to send, order reference and our response. Used to answer the request, perform the contract and protect legitimate operational/legal interests.
- Technical and security: IP address, request time, route, browser/device information, authentication events, rate-limit state, errors and security/audit events. Used for necessary security, reliability, abuse prevention and legal claims.
- Preferences: theme preference is stored in your browser. Optional marketing is not part of the launch service and will require a separate choice if introduced.
We do not use customer data for advertising, sell personal data or make solely automated decisions with legal or similarly significant effects.
3. Providers
Gummy UI uses Vercel for hosting, WorkOS for sign-in and organisation access, Stripe Managed Payments for checkout, payment and tax support, Convex for application data and backend transactions, Resend for product email, Better Stack for monitoring, and Backblaze B2 for encrypted off-provider backups. Customer-facing payment and paid-download features remain unavailable until their complete production journeys pass.
Providers may process data outside the United Kingdom. Where required, we rely on an adequacy regulation or recognised contractual safeguards supplied by the provider. You may request more information using the privacy contact above.
4. Retention
- Account profile: while open, then normally removed within 30 days after a completed deletion request.
- Download grants and product-email delivery events: 90 days.
- Access, consent, security and audit events: 12 months unless needed longer for an active incident or legal claim.
- Support and closed-incident records: 24 months.
- Licence, order, invoice, refund, chargeback and tax evidence: six years after the relevant financial period or longer if law requires.
- Rolling operational backups: 35 days, subject to tested expiry and legal holds.
We may retain a minimal suppression, fraud or legal-claims record where deleting it would defeat a legal duty or security purpose.
5. Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or receive your data, and to object to processing based on legitimate interests. You may withdraw consent where consent is the basis. Rights can be limited by law, including financial-record and legal-claims duties.
Email support@kreydlabs.com. We may need proportionate information to confirm identity. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
6. Cookies, security and changes
Essential account cookies are used to keep a signed-in session secure. The theme setting uses browser local storage. Stripe and WorkOS may set strictly necessary checkout or authentication storage on their own hosted surfaces. We do not launch optional advertising or marketing cookies.
We use access controls, encryption in transit, restricted provider credentials, audit records and encrypted backups. No system is completely secure; report concerns through the security page.
We will update this notice before using personal data for a materially new purpose and will bring important changes to account holders' attention.