🚧 Cozzify is currently in beta — some features are still being polished and you may encounter bugs. Thanks for trying it out!

Privacy Policy

Last updated: April 2026

1. Controller

The controller within the meaning of Art. 4 (7) GDPR is:
Bai Xu (Cozzify)
Bai Xu, c/o POSTFLEX PFX-008-567, Emsdettener Straße 10, 48268 Greven, Germany
Email: HelloBaixu@gmail.com
VAT ID: DE459892016

Full provider information is available in our Legal Notice.

2. Data we process

Payment data (card numbers, billing address) is collected and processed directly by our Merchant of Record Paddle. We do not see your full payment details.

3. Purposes and legal bases

PurposeLegal basis
Account, authentication, providing the serviceArt. 6 (1) (b) GDPR (performance of a contract)
Running AI analyses on your photosArt. 6 (1) (b) GDPR (performance of a contract)
Payment processing, invoicingArt. 6 (1) (b) and (c) GDPR (contract and legal obligations, in particular tax law)
Security, abuse and fraud preventionArt. 6 (1) (f) GDPR (legitimate interest)
Optional analytics / marketing cookiesArt. 6 (1) (a) GDPR in conjunction with §25 (1) TTDSG (consent)
Responding to support requestsArt. 6 (1) (b) and (f) GDPR

4. Recipients and processors

We use carefully selected service providers. We have data processing agreements in place with all processors under Art. 28 GDPR.

RecipientFunctionLocation / processing
Paddle.com Market LimitedMerchant of Record, payments, taxes, invoicesIreland (group also UK / USA)
Supabase Inc. ("Lovable Cloud")Database, authentication, file storage (photos, analyses)EU region; parent in USA
Cloudflare, Inc.Hosting, CDN, DDoS / bot protectionUSA / global edge network
Google LLC (Gemini models)AI analysis of uploaded photosUSA
OpenAI, L.L.C. (GPT models)AI analysis as alternative / fallback providerUSA
Transactional email providersAccount emails (verification, password reset, receipts where applicable)EU / USA
PostHog (PostHog Inc.)Product analytics, error tracking and session replay (with PII masked client-side); only active after you opt in via cookie settingsEU (Frankfurt); parent company in USA

We do not sell your personal data. Uploaded photos are not used to train third-party AI models; our AI providers are contractually required not to use submitted content for model training.

5. International transfers

Some recipients are based in the USA. Where personal data is transferred to third countries, we rely on appropriate safeguards under Art. 46 GDPR, in particular the EU Standard Contractual Clauses (SCCs), as well as supplementary technical and organisational measures (e.g. transport encryption, access controls). Where a recipient is certified under the EU–US Data Privacy Framework, we additionally rely on the corresponding adequacy decision of the European Commission.

6. Retention

7. Cookies and local storage

We use strictly necessary cookies and local-storage entries for session management. Optional categories (analytics / marketing) are only enabled with your consent under §25 TTDSG and can be withdrawn at any time via the .

NamePurposeProviderRetentionCategory
cozzify.cookie-consentStores your cookie choicesCozzify (1st-party)12 monthsstrictly necessary
sb-* (auth tokens)Keeps you signed inLovable Cloud / Supabasesession / 7 daysstrictly necessary
pending_credit_purchaseLinks the checkout return to your session (sessionStorage)Cozzify (1st-party)active session onlystrictly necessary
ph_*_posthogAnonymous distinct id, feature flags and session replay state. Only set after you opt in to analytics.PostHog (EU)up to 12 monthsanalytics (consent)

If you enable analytics, we record an anonymised session replay via PostHog. All form inputs, text content and images are masked client-side before anything leaves your browser, so the replay shows your interactions (clicks, navigation, scroll) without revealing the content you see or type, and never includes your room photos. You can switch this off at any time via ; revoking consent stops further recording immediately and clears your local PostHog identifier.

8. Security

We apply appropriate technical and organisational measures (TLS encryption, access controls, row-level security in the database, short-lived signed URLs for file access). Absolute security cannot be guaranteed.

9. Automated decisions / AI

Cozzify uses AI models to generate suggestions about your room. These outputs are advisory and do not produce legal effects or similarly significant impacts within the meaning of Art. 22 GDPR. No automated decisions are made about creditworthiness, employment, insurance or similar matters.

10. Your rights

To exercise your rights, contact us at HelloBaixu@gmail.com. Signed-in users can also export their data or delete their account directly from My Account.

11. Changes

We may update this privacy policy as needed. We will communicate material changes through the service.

See also Terms, Right of Withdrawal and Withdrawal & Refunds.