Privacy

Discretion is
part of
the service.

Last updated 20 August 2026

This policy applies to CATWLK 0.12.0, catwlk.com and the CATWLK professional workspace. CATWLK is local-first and does not sell personal information.

01

Purpose and scope

CATWLK helps professional stylists capture clothing products, organize client edits, compare options and share selected decisions with their clients. The browser extension can also be used without an account for personal product analysis and organization. CATWLK has no advertising network, does not sell personal information and does not use information for credit or lending decisions.

02

Product-page information

On supported Zara, H&M, Mango, Uniqlo, COS, Massimo Dutti, ARKET, & Other Stories, Sézane, ASOS, Weekday, GANNI, Abercrombie & Fitch, Reformation and Zalando domains, CATWLK’s packaged reader checks the current URL when the page loads to determine whether it is a recognized product page. Only on a recognized product URL may it read the retailer, product title, displayed price, image URL, retailer-declared fiber composition, care instructions and structured product data. CATWLK uses this website content for product capture, material and care analysis, comparison, sourcing and cost-per-wear features.

On category, cart, account, checkout and other non-product routes for a supported retailer, CATWLK does not inspect page content or form fields. On another retailer, generic capture runs only when the user invokes CATWLK on the active tab and may inspect visible page text and structured product data to attempt a product capture. CATWLK does not read values entered in form fields, passwords, payment-card or bank-account credentials, contacts, precise location or browser history outside the supported or user-invoked active page.

03

Information categories

Depending on the features a user chooses, CATWLK may handle identity and work contact information for stylists and clients; authentication tokens; client comments, feedback and other workflow communications; optional general location, climate or timezone; optional measurements, comfort, mobility or sensory needs, allergies and material sensitivities; budgets, purchase dates, purchase prices and wear records; captured product URLs and product-page content; and activity needed to operate edits, reviews, intake, synchronization and abuse protection.

Website history is limited to recognized supported product pages, supported-domain URLs used for page classification and product URLs the user explicitly captures. General location is user-supplied and does not include precise GPS location. Optional health-related information is used only to adapt fit, comfort and material recommendations. Financial information is limited to user-entered budgets and purchase records plus retailer-displayed product prices; CATWLK does not collect payment-card numbers, bank-account credentials, credit ratings or financial statements.

04

Local storage and browser sync

Products, comparisons, notes, tags, purchase and wear records, preferences, local client profiles, edits, recommendations, reports, branding and interface state may be stored in the browser’s local extension storage. Wardrobe summaries are calculated on the device. Authentication refresh tokens and raw review or intake tokens use a separate local secrets record excluded from backups, diagnostics, reports and browser sync.

Material preferences, limits and display settings may use the browser’s extension sync storage when available; the browser vendor controls that synchronization. Where sync storage is unavailable, CATWLK falls back to local storage. Removing CATWLK deletes local extension storage, subject to the browser’s own sync behavior.

05

Accounts and professional workspace

CATWLK does not automatically transmit local product, browsing, preference or client records. Approved users authenticate through Makepad Keycloak using Authorization Code Flow with PKCE where the browser exposes an identity API and Device Authorization Grant on supported mobile and Safari targets. They can use a CATWLK password account or continue with Google or Apple. For social login, Keycloak receives the provider identifier, a provider-verified email address and an optional name; CATWLK does not store the Google or Apple access token. Matching accounts are not linked from email alone and require password-based ownership confirmation.

Before connecting an account, CATWLK asks the user to acknowledge the cloud data categories described here and records the policy version and acceptance time locally. Signing in does not migrate existing extension records. A client moves from local extension storage only after an explicit migration or sharing action. For an explicit migration, CATWLK previews record counts and verifies a SHA-256 checksum before PostgreSQL becomes authoritative for that client. Cloud-managed captures and offline changes are written locally first and then synchronized with idempotency protection. Unselected local clients remain local. All extension communication with CATWLK and its authentication service uses HTTPS.

06

Reviews, intake and other sharing

When a stylist publishes a review, CATWLK stores the selected client-facing snapshot and the workspace references needed to connect responses to the edit. An intake stores the context selected by the stylist, the answers submitted by the client and the privacy-policy version and acceptance time confirmed before submission. Clients can respond without an account. Private review and intake links are expiring and revocable. Bearer tokens remain after the URL fragment marker and PostgreSQL stores only their cryptographic hashes. Internal profile notes and unrelated clients are not added to a shared snapshot. Private files use MinIO-compatible object storage when file features are enabled.

A Copy action writes only the requested analysis, comparison, diagnostic or private client link to the clipboard. Diagnostics omit saved products, notes, client records and preferences. A product URL is included only when the user opts in. Retailer images remain referenced by their source URL, so opening a saved product or shared review may make an ordinary request to that retailer.

07

Browser permissions and network access

CATWLK uses a side panel on supported Chromium desktop browsers, a native sidebar on Firefox desktop, and a full-page extension tab on Safari and supported mobile browsers. It uses activeTab and scripting for user-invoked generic capture; storage for the records described above; clipboardWrite for explicit Copy actions; and browser identity where available or device authorization elsewhere for Makepad Keycloak sign-in. Optional alarms and notifications are requested together only when a stylist enables local follow-up reminders. Reminder notifications show a count and do not include client names or product details.

Required host access is limited to supported retailer domains and the image hosts needed to read or display their product information, catwlk.com for the CATWLK API and workspace, and auth.catwlk.com for Makepad Keycloak. CATWLK requests optional access to api.lemonsqueezy.com only if paid activation is enabled and the user chooses a license action. CATWLK does not download or execute remote code.

08

Applications, measurement and providers

The design-partner application asks for identity and work contact information, practice and market, an optional portfolio, recent client and sourcing activity, retailer and workflow information, current tools, client constraints, intended use and pilot availability. Validated applications are delivered through a private server-side Slack webhook for personal review and are used only to evaluate design-partner fit and contact the applicant about CATWLK.

OpenPanel measures public-site events such as page visits and CTA outcomes without application names, emails, handles, free text or form answers. CATWLK does not use session replay for the application. Global Privacy Control and Do Not Track disable public-site measurement. Keycloak provides authentication; Google and Apple process optional social authentication under their own privacy terms; PostgreSQL stores selected workspace data; MinIO-compatible storage holds private objects when enabled; and Lemon Squeezy processes optional licensing when enabled.

09

Retention, export and deletion

Design-partner applications are retained for 90 days unless the applicant joins the pilot. Review links expire after 30 days and intake links after 14 days unless revoked earlier. Users can delete supported local records or remove the extension. A signed-in stylist can export data or delete their cloud account from CATWLK Settings. CATWLK removes that user’s active workspace records, sessions, private links and stored objects. In a genuinely shared workspace, CATWLK removes the membership and transfers ownership rather than deleting other members’ work.

CATWLK then opens the secure identity page so the user can confirm deletion of the Keycloak sign-in identity. CATWLK does not keep a separate application-level backup copy of deleted account data.

10

Contact and changes

Material changes will be reflected here and in the extension’s release notes before distribution. For access, correction, export, deletion, privacy or support requests, email CATWLK support or visit the CATWLK help page.

Information received from Google APIs is handled under applicable browser-store and Google API user-data policies, including Limited Use requirements.