Privacy

Discretion is
part of
the service.

Last updated 1 August 2026

CATWLK is local-first, uses explicit migration and sharing, and does not sell personal information.

01

Data held locally

On supported retailer pages, CATWLK reads product details needed for the analysis. Products, comparisons, notes, preferences, local client work, and reports can remain in Chrome storage; small preferences may use Chrome Sync. CATWLK does not read payment details, carts, passwords, contacts, precise location, or unrelated browsing history. Signing in does not upload existing extension data.

02

Data held by CATWLK

A client moves to CATWLK only after the stylist previews and confirms an explicit migration. Published reviews contain the selected client-facing snapshot plus the workspace reference IDs needed to connect responses to the edit. Selected workspace data is stored in PostgreSQL, and private file objects use MinIO-compatible storage when file features are enabled. Unselected local clients remain local.

03

Identity and access

Makepad Keycloak authenticates stylists using Authorization Code Flow with PKCE. Clients respond without accounts through revocable, expiring links. Raw bearer tokens remain in the URL fragment and CATWLK stores only their cryptographic hashes. Review links expire after 30 days and intake links after 14 days unless revoked earlier.

04

Providers and tracking

CATWLK has no advertising network, does not sell personal information, and does not track general browsing. On catwlk.com, OpenPanel measures public-site visits, duration, referrer, browser and device characteristics, broad location, campaign parameters, outbound links, CTA clicks, demo interactions, and account-funnel outcomes. It does not collect registration fields, client records, private review or intake links, authentication tokens, or session replay. Global Privacy Control and Do Not Track disable this public-site measurement. The server separately records only operational events needed for edits, reviews, intake, synchronization, reliability, and security. Paid checkout remains disabled during validation.

05

Control and deletion

Users can delete supported local records and extension data. Stylists can revoke review and intake links and can separately make a delivered review view-only. Account-wide cloud export and deletion are not yet self-service, and a formal backup and object-retention schedule must be completed before public self-service access.