← Back to TestMyPaint

TestMyPaint

Privacy

Last updated: 6 August 2026

The short version: your room photo is used to make and store your renders, not for marketing. You control photo deletion, and this page names the providers that handle each part of the service.

Who this notice covers

This notice explains how TestMyPaint, operated by Bora Suda in Canada, handles information when you visit the site, create an account, upload a room photo, generate a render, buy credits, use Studio, or contact support.

Information we handle

Accounts and sign-in. We store your email address and, when available from Google sign-in, your name, profile image, and provider account details. We also keep session and verification records needed to sign you in.

Photos and product work. We store uploaded room photos, generated renders, selected colours, colour measurements, and the project, room, collection, catalogue, note, and branding details you choose to save.

Purchases. Stripe handles payment-card entry. We receive and store transaction identifiers, the credit pack, amount, currency, payment status, and the account that should receive credits. We do not receive or store your full card number.

Support and service protection. The support form sends us your email address and message. We also use a shortened, one-way hash of network information for free-credit, signup, and rate-limit controls; the raw address is not stored in those controls.

Product analytics. We record pageviews and a small set of product events, such as upload, render, signup, purchase, and download steps, along with click patterns and masked interaction replays. Typed inputs and room-image areas are blocked from replays, and recorded request addresses omit query strings. Events do not include your email address, room photo, or the colour code you entered. We do not link them to your account. If you answer the optional result question, we record your answer and the note you choose to send.

Why we use it

We use this information to provide sign-in, generate and store renders, maintain your credit balance and Studio work, fulfil purchases, deliver requested emails, answer support requests, protect the free service from abuse, understand whether the product works, and diagnose quality or reliability problems. We do not use room photos for marketing or to train our own models.

Service providers

We use providers only where they are needed to run TestMyPaint. Google Gemini receives the room photo, repaint instructions, and selected colour to generate the image. Vercel hosts the application and stores photos and renders in private Blob storage. Neon hosts the application database.

Stripe processes checkout and payment. Resend delivers sign-in links, support messages, and requested catalogue emails. Google handles optional Google sign-in. PostHog receives the cookieless pageviews, product events, and masked interaction replays described above. Our support mailbox receives messages submitted through the support form.

Photo retention and deletion

A room photo and its renders are scheduled for deletion 30 days after the photo is uploaded. If you put the photo in a Studio collection, that clock pauses while the photo remains in any collection. Removing it from its last collection starts a new 30-day period.

You can delete a single render or delete a room photo and all of its renders from Studio. Those actions remove the corresponding stored image files and product records immediately. We may inspect recent uploads and results on a restricted internal quality page before they are deleted.

Other retention

Account, credit, purchase, catalogue, support, and operational records are kept for as long as needed to provide the service, maintain transaction and security records, resolve disputes, and meet legal obligations. We do not state a fixed period where the product does not currently enforce one. You can ask us to delete your account; some transaction or legal records may need to be retained.

Cookies and your choices

Sign-in uses an essential session cookie. PostHog runs in cookieless mode and is configured not to store analytics identifiers in cookies, local storage, or session storage, and not to build person profiles.

Use Studio to delete photos or renders. For account deletion, access, or correction requests, contact us through the support form. We may need to verify that the account belongs to you before acting.

Questions and changes

Send privacy questions through our support form. If current practices change, this page will be updated and the date below will change. Material changes will be presented in a way appropriate to their effect on you.