Privacy Policy

Last updated: 27 July 2026

Mockbooth is a browser-based device-mockup studio. This policy explains, in plain language, what happens to your screenshots, your projects and your account data — and what does not happen to them.

The short version. Without an account, Mockbooth runs entirely in your browser and nothing is uploaded. With an account, your saved projects and the images in them are stored on our servers so you can reach them from another device. Product analytics are off unless you turn them on. There is no session recording, no screen recording, and we do not sell your data.

1. Who we are

Mockbooth ("Mockbooth", "we", "us") is the operator of the Mockbooth studio and this website. We are the controller of the personal data described below. Mockbooth is free to use; there is no paid plan and we do not take payments, so we never collect card or billing details.

2. Using Mockbooth without an account

You can open the studio, drop in a screenshot, frame it and export the result without signing in at all. In this mode the app shows a “Local only” indicator, and it means what it says:

3. What we collect, and why

Everything below applies only once you choose to sign in and save to the cloud. The "why" column is our lawful basis in plain English — under the GDPR these map to performance of a contract, your consent, and our legitimate interests in running a secure service.

Account identifiers (via Clerk)

Sign-in is handled by Clerk, our authentication provider. We never see or store your password. When you first sign in, Clerk gives us a verified token containing your user ID, your email address and your display name, and we store those on your account record so we can attach your projects to you and recognise you next time. Why: we cannot provide an account-based service without it.

Projects and uploaded images

When you save a project to the cloud we store the project name you typed, the scene configuration (device, background, padding, shadow, tilt, resolution and similar settings), a small preview thumbnail, timestamps, and the image files you uploaded — your screenshots and any background images. For each image we also keep technical metadata: file type, byte size and pixel dimensions. Why: this is the service you asked us to perform. We use these files only to store, render and return your own projects to you — never to train models, and never to build a profile of you.

Product analytics events

Only if you opt in. See section 4. Why: your consent, which you can withdraw at any time.

Server logs and abuse prevention

Our API writes ordinary request logs: the request method and path, the response status, how long it took, and the IP address the request came from. Authorization headers and cookies are redacted before anything is written. We also apply rate limiting, which counts recent requests per IP address in server memory. Why: our legitimate interest in keeping the service up, debugging failures and blocking abuse. These logs are not used for advertising or profiling.

4. Product analytics (opt-in)

Mockbooth can collect product analytics through PostHog to understand which parts of the studio people actually use. This is strictly opt-in:

When analytics are on, we record product events in these categories:

What analytics never contain. No session replay or screen recording — it is switched off in our code, permanently, precisely because your screenshots are on the canvas. No automatic capture of clicks or page views. No file names, image data, text you typed, project names or colour values. Event properties are limited to fixed options, numbers and true/false flags, and precise values such as file sizes and export dimensions are rounded into buckets. Your identity in analytics is your account ID only — no email address or name is attached.

PostHog stores analytics state in your browser's localStorage, not in cookies. PostHog processes these events on our behalf on servers in the United States and, like any web service receiving a request, sees the originating IP address.

5. Where your data is stored

Our providers may process data in the United States and elsewhere. Where personal data of people in the EEA or UK is transferred, we rely on our providers' standard contractual clauses and equivalent safeguards.

6. How long we keep it

7. Who else processes it

We keep the list of third parties deliberately short:

Service providers that may process your data on our behalf.
Provider What it does What it sees
Clerk Sign-in and session management Your login credentials, email, name, sign-in activity
Supabase Hosts our PostgreSQL database Account records, project names and scene settings
Object storage provider Stores uploaded images in a private bucket Your uploaded image files
PostHog Product analytics — only if you opted in The events described in section 4, keyed to your account ID
Our hosting provider Runs the website and API Ordinary request data, including IP addresses

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We may disclose data if the law requires it, or to protect the rights and safety of our users and the service.

8. Cookies and browser storage

Mockbooth sets no advertising or tracking cookies of its own, and our API sets no cookies at all. What the app does use is your browser's own storage:

Cookies and browser storage used by Mockbooth.
Name / key Type Purpose
Clerk session cookies Cookies, set by Clerk Keep you signed in. Strictly necessary — without them you cannot log in.
framed:analytics-consent localStorage Remembers whether you allowed or rejected product analytics.
framed:analytics-consent-owner localStorage Records which account gave that answer, so another account is asked afresh.
framed:ad-consent localStorage Remembers an advertising-consent answer. Reserved for the future — see section 10.
framed:scene localStorage Your current work-in-progress scene, so a reload does not lose it.
framed:projects:* localStorage Locally saved projects, their metadata and thumbnails.
framed:assets, framed:project-assets:* IndexedDB The images themselves, which are far too large for localStorage.
PostHog keys localStorage Only present after you opt in to analytics; PostHog uses no cookies here.

You can clear all of this at any time through your browser's "clear site data" controls. Clearing it removes any locally saved projects, which we cannot recover.

9. Your choices and rights

Depending on where you live — including under the GDPR in the EEA and UK, and the CCPA/CPRA in California — you have rights over your personal data. We extend the same handling to everyone:

Write to the address in section 15 to use any of these. We will respond within the time your local law allows, and we may need to confirm the email address on the account first. If you are in the EEA or UK you may also complain to your data protection authority.

This policy describes what we do; it is not a claim to hold any privacy certification, seal or third-party audit.

10. Advertising

Mockbooth shows no ads today. No advertising network is loaded and no ad-targeting data is collected. If we introduce advertising in the future, we will update this policy and tell you before it starts, and any personalised advertising would be subject to a separate consent choice you can reject.

11. Children

Mockbooth is a design tool for a general audience and is not directed at children under 13 (or the equivalent minimum age where you live). We do not knowingly collect personal data from children under 13. If you believe a child has created an account, contact us and we will delete the account and its contents.

12. Security

Traffic to the site and the API runs over HTTPS, and the database connection is encrypted. Uploaded images live in a private bucket reachable only through short-lived signed links scoped to your own account. Passwords are never handled by us — Clerk holds them. No system is perfectly secure, so we cannot guarantee absolute security; if a breach affects your data we will notify you as the law requires.

13. Changes to this policy

We may update this policy as Mockbooth changes. The "last updated" date at the top always reflects the current version. For material changes — a new category of data, a new purpose, or the introduction of advertising — we will give notice in the app before the change takes effect, and where the law requires it we will ask for your consent again.

14. Governing law

This policy is governed by the laws of the United Arab Emirates, without regard to its conflict-of-laws rules. Nothing here removes rights you have under the mandatory law of the country you live in.

15. Contact

Questions about privacy, or a request about your data? Write to us and say which email address your account uses.

Contact: support@mockbooth.com

See also our Terms of Service.