Privacy Policy.
Last updated: 23 May 2026
This policy describes what data Setpiece collects, how it is used, who it is shared with, and the rights you have over it. It is written to be read, not to be hidden behind. If anything here is unclear, email privacy@getsetpiece.com and we will explain or fix it.
Who we are
Setpiece is an independent product operated by an individual sole proprietor based in Australia. There is no parent company, no investors, and no third-party data buyers.
What we collect
We collect the minimum data needed to operate the service.
When you visit the site without signing in
- A hashed version of your IP address (one-way SHA256, never stored in raw form)
- A browser fingerprint hash, derived from publicly available browser properties (canvas signature, screen dimensions, timezone)
- A signed cookie containing a random session identifier
- The photo you upload, if you choose to upload one
- The render generated from that photo, if you complete a render
- Any feedback you provide on the render
When you sign in with email
- Your email address
- A timestamp of each sign-in
- The renders you generate, tied to your account
- Any feedback you provide
- Any renders you choose to publish to the public feed
We do not collect: your real name (unless you include it in feedback), your physical address, your phone number, your IP address in raw form, your browsing history outside Setpiece, your social media identifiers, or any payment information (the free tier does not require payment).
What we do with your photo
When you upload a photo to Setpiece, it is sent to a third-party AI provider (fal.ai) for processing. fal.ai runs the AI model that generates your rendered output. The photo is also briefly analyzed by an image-captioning model (Florence-2) to detect whether you've uploaded a desk setup or an empty room, so we can suggest the right mode.
Photos and renders are stored in our own database (Supabase) so that you can view them in your gallery and so the public feed can display public renders. Renders are watermarked with the Setpiece lockup.
If you mark a render as private, it is not shown on the public feed. The public-feed setting is per-render, not per-account.
What we do with your email
Your email is used to send you a one-time sign-in code (a six-digit OTP) when you sign in. We may also send transactional emails about your account, such as a welcome message or a notice that your daily render limit has reset. We do not send marketing emails. We do not share your email with third parties.
Transactional emails are sent via Resend (resend.com), which acts as our email delivery provider. Resend has access to your email address solely for the purpose of delivering messages from us.
Third parties we share data with
Setpiece relies on the following third-party services to operate. Each processes some user data on our behalf:
- fal.ai — runs the AI image generation and image captioning models on your uploaded photo
- Supabase — provides authentication, database storage, and image storage
- Vercel — hosts the website and the API endpoints
- Resend — sends transactional and authentication emails
- Cloudflare — provides DNS, security, and content delivery for the website
We do not sell, rent, license, or trade your data with any party for marketing or advertising purposes. The companies above process your data only to provide the services Setpiece relies on.
How long we keep data
- Anonymous browser fingerprint hashes: retained indefinitely while the service operates, to enforce the one-lifetime-render limit for non-signed-in users
- Photos and renders: retained for as long as your account is active. If you delete your account, your renders are deleted within 30 days.
- Feedback: retained indefinitely in aggregated, anonymized form for product improvement
- Sign-in records: retained for the lifetime of your account, deleted with your account
Your rights
You can:
- Sign in and view all renders associated with your account in your gallery
- Opt any render in or out of the public feed at the moment of creation
- Email privacy@getsetpiece.com to request deletion of your account and all associated data
- Email privacy@getsetpiece.com to request a copy of your data
- Email privacy@getsetpiece.com to ask any other question about your data
We aim to respond to data requests within 14 days. If you are in the European Economic Area, the United Kingdom, or California, you have specific statutory rights under GDPR, UK GDPR, or CCPA respectively; emailing the address above is the way to exercise them.
Children
Setpiece is not designed for or marketed to people under 16. If you are under 16, please do not use Setpiece. If you are a parent or guardian and believe a child has uploaded data to Setpiece, email privacy@getsetpiece.com and we will delete it.
Changes to this policy
If we change this policy, we will update the “Last updated” date at the top of the page and, for material changes, send a notice to signed-in users by email. We will not retroactively make worse the policy that applied to data we already collected.
Contact
For any privacy question, data request, or concern, email privacy@getsetpiece.com.