Privacy Policy
Last updated: June 24, 2026
Data collection
FurnishPlan is a personal portfolio project. The core application does not require or collect personal data. No account, email address, password, or any personal information is needed to use it.
Room layouts are stored in a database under a randomly generated anonymous identifier tied to the browser. This identifier is a random string of characters with no connection to any name, email, device, or any other information that could identify a person. FurnishPlan has no way to determine who uses the app or to connect stored data to any individual.
Clearing browser data deletes the identifier and removes access to associated layouts.
User-entered text
FurnishPlan allows users to type labels for rooms, apartments, and furniture. No personal information is requested or required in these fields. If a user voluntarily enters personal information (for example, a full address as an apartment name), that text is stored as part of the layout data. FurnishPlan does not monitor, review, or process the content of these labels.
Shared links
Creating a shareable link saves a snapshot of the layout. The snapshot is accessible to anyone who has the link URL. Links are not listed publicly and cannot be found through search engines, but anyone with the URL can view the layout content. Users are responsible for the content they choose to share.
The app retains only the 3 most recent shared links per browser. Older links are automatically deleted when a new one is created.
Bot protection
FurnishPlan uses Cloudflare Turnstile to verify that visitors are human before allowing data to be saved. This verification is performed once per browser. On subsequent visits, the result is stored locally and the challenge is not repeated. The Cloudflare Turnstile script is loaded on each visit.
During verification, Cloudflare processes browser signals including the visitor's IP address, TLS fingerprint, and User-Agent header. These signals are used solely for bot detection. Cloudflare processes this data on behalf of FurnishPlan (as a data processor). FurnishPlan is the data controller for this processing. The legal basis is legitimate interest in preventing automated abuse (GDPR Article 6(1)(f)).
The visitor's IP address is forwarded to Cloudflare's verification endpoint during the check but is not stored by FurnishPlan.
For details, see the Cloudflare Turnstile Privacy Addendum and Cloudflare's Privacy Policy.
Analytics
FurnishPlan uses Cloudflare Web Analytics for aggregate, cookieless usage statistics. No IP addresses are stored, no individual visitors are tracked, and no browser fingerprinting is used. The collected data consists of aggregate metrics such as page views, referrer, browser type, screen size, and country. The legal basis is legitimate interest in understanding usage patterns (GDPR Article 6(1)(f)).
Infrastructure
FurnishPlan is hosted on Cloudflare (hosting, DNS, bot protection, and analytics). Layout data is stored by Supabase in the EU region. Both services process standard connection data (such as IP addresses) as part of normal web server operation. Cloudflare operates a global network, which means connection data may pass through servers outside the EU. International data transfers by infrastructure providers are safeguarded by Standard Contractual Clauses or an applicable adequacy decision.
Privacy policies of infrastructure providers:
Local storage
The app stores functional data in the browser's local storage. This includes the anonymous identifier, a verification status flag, and crash-recovery snapshots of room layouts. None of these items contain personal information. No cookies are used for tracking or advertising. Cloudflare Turnstile may use cookies for bot detection purposes as described in Cloudflare's privacy policy.
Data retention
Data associated with inactive anonymous identifiers is automatically deleted after 12 months of no activity. If an identifier has not been used to create or edit any layout for 12 months, all associated data (apartments, rooms, furniture, and shared links) is permanently removed.
Your rights
Under GDPR, individuals have rights including access, rectification, erasure, and data portability (Articles 15 to 20). Because all data in FurnishPlan is stored under anonymous identifiers with no connection to any person, FurnishPlan cannot determine which data belongs to which individual. Under GDPR Article 11, FurnishPlan is therefore exempt from fulfilling these rights unless the user can provide their specific anonymous identifier.
Clearing browser data removes the anonymous identifier from the browser, which permanently removes the ability to access the associated layouts. The data itself remains in the database as orphaned records until it is automatically deleted after 12 months of inactivity.
You also have the right to lodge a complaint with a data protection supervisory authority if you believe your data has been processed in violation of applicable regulations.
Contact emails
Personal information is only processed if a user voluntarily contacts FurnishPlan by email. In that case, the email address and message content are processed for the purpose of responding to the inquiry. Contact correspondence is retained for one year and then deleted.
Changes to this policy
Updates to this policy are posted on this page with a revised date. Significant changes may also be communicated through the in-app announcement banner.
Contact
contact@furnishplan.com