Privacy Policy
Last updated 10 August 2026
Approvd is a tool for sending creative work out for review and getting a clear, recorded decision back — without a client needing an account. This page explains what we collect to make that work, why, and what we don’t do with it.
Who this covers
This policy covers two different people, because Approvd works differently for each:
- Account holders — the studios, freelancers and teams who sign up, upload work and share review links.
- Reviewers — the people an account holder invites to look at that work via a review link. Reviewers never create an Approvd account; nothing here requires them to.
Information we collect
From account holders:
- Name, email address and password, to create and secure your account.
- Your studio name and any branding you choose to add — a logo and an accent colour — used to show your work under your own identity rather than ours.
- The projects, files, versions and comments you create or upload, and any clients, invoices or rate-card details you enter for your own bookkeeping.
- Billing information if you upgrade to a paid plan. Card details are handled directly by our payment processor, Stripe — we never see or store your card number. We keep only what’s needed to know which plan you’re on and manage your subscription.
From reviewers:
- The name you enter when you open a review link, and an email address if the account holder has asked for one or if you choose to add one.
- The comments, markup and annotations you leave on a proof.
- A record of your decision — approved or changes requested — along with the time it was made.
- If the studio requires verified approval, the one-time code we email you to confirm it’s really you. That code is discarded shortly after use or after 10 minutes, whichever comes first.
Error monitoring and product analytics
We use three additional tools to keep Approvd working and to understand which parts of it actually get used: Sentry for error monitoring, and Vercel Analytics and Vercel Speed Insights for traffic, product usage and page performance.
What this can include:
- When something breaks: technical details of the error itself — what kind of error it was, roughly where in the app it happened, and enough surrounding context to diagnose it.
- Which major steps of the product get used and how far people get through them — for example, that a project was created, a review was shared, or a version was approved — along with a small amount of non-identifying context like which plan an account is on or what file type was involved.
- Aggregate page-load and performance figures.
This deliberately never includes:
- The content of comments, uploaded proofs, invoices, or anything you or a reviewer typed into a form.
- Names, email addresses, review links or share tokens, or approval codes.
- Passwords or session/authentication tokens.
This is an engineering choice, not just a policy one: the code that reports errors and the code that records product events are both built to strip or simply never collect the fields above before anything is sent, rather than relying on remembering to redact them case by case.
None of these three tools sets a cookie or another persistent browser identifier to track you individually — Vercel’s analytics is built to work in aggregate without one. Data is retained by each provider under their own standard retention period, after which it’s deleted.
Why we process this information
To operate the service: to show you your own projects, deliver review links to the people you share them with, record their feedback and decisions, send the email notifications you or your reviewers would reasonably expect, and process payment if you’re on a paid plan. We don’t use your data, or your clients’ data, for anything beyond that.
Ownership of uploaded work
Approvd does not take any ownership of, or rights over, the creative work you upload. It remains yours (or your client’s, as agreed between you). We store and display it only to provide the review service you’ve asked for.
How your information is handled
We rely on a small number of infrastructure providers to run Approvd, each processing only what’s needed for their part of the service:
- Supabase — authentication, database and file storage for your account and uploaded proofs.
- Stripe — payment processing for paid plans. Stripe, not Approvd, holds your card details.
- Resend — delivery of the transactional emails Approvd sends (comment notifications, approval codes, invoices and similar). We don’t use this for marketing email.
- Vercel — hosting for the application itself, and its own cookie-free Analytics and Speed Insights tools (see “Error monitoring and product analytics” above).
- Sentry — error monitoring, so we can find and fix bugs. See above for exactly what this does and doesn’t include.
We don’t sell personal information, and we don’t share it with any other third party except where needed to provide the service above or where we’re legally required to.
Data retention and deletion
We keep your account’s data for as long as your account is active. You can permanently erase all of your projects, invoices, clients and settings at any time from Settings → Erase all data — this takes effect immediately and can’t be undone. To close your account entirely, including your login, contact us at the address below and we’ll remove it.
Free trial accounts created through our “View demo” button are automatically deleted after 24 hours, along with any review links they created.
When a project or account is deleted, its associated review links stop working immediately.
Our approach to security
Every account’s data is kept separate from every other account’s — your projects, clients and invoices are only ever reachable by you (and anyone you’ve invited to your team), enforced at the database level rather than relying only on the app’s own logic. Review links use a unique, hard-to-guess address rather than a predictable one, and a studio can require an emailed one-time code before a named approver’s decision counts as final. All traffic to Approvd is encrypted in transit (HTTPS).
No system is perfectly secure, and we won’t claim otherwise. If you believe you’ve found a security issue, please tell us at the address below before disclosing it anywhere else.
Your rights
Depending on where you’re based, you may have the right to access, correct, export or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these, contact us at the address below — for account holders, many of these are also available directly in Settings.
International processing
Our infrastructure providers (see above) may process and store information in countries other than your own, including outside the UK/EEA. Where that happens, it’s under those providers’ own safeguards for international transfers.
Changes to this policy
If we make a material change to this policy, we’ll update the date at the top of this page. We won’t reduce your rights under this policy without telling you.
Contact
Questions about this policy, or a request relating to your data, can go to hello@useapprovd.app. This service is operated by Approvd.