Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how Hexly ("Hexly", "we", "us"), operated by Kevin Kwok, an individual based in Indonesia, handles information in connection with the Hexly browser extension and the Hexly website. By using Hexly you agree to this Policy.
1. Who we are and who processes payments
Hexly is a Chrome extension that extracts design information from web pages you visit — colors, typography, CSS, and downloadable assets — for designers and developers. Payments for Hexly Pro are handled by Paddle.com Market Ltd ("Paddle") as our Merchant of Record. Paddle collects and processes your payment information under its own privacy policy; we never receive or store your full payment card details.
2. Information we collect
Account information. If you create a Hexly account, you sign in with Google, either in the Hexly extension or on the Hexly website. Through Google Sign-In we receive a basic set of profile information: your email address, your Google account identifier, and where provided your name and profile image. We use this to create and identify your account. The same account is used across the extension and the website. We do not receive your Google password.
Subscription information. When you purchase Hexly Pro, Paddle provides us with confirmation of your subscription status and an associated account identifier so we can enable Pro on your account. We receive transaction metadata (such as whether a subscription is active, its plan, and its renewal state), not your card number.
Usage and account-state data. For signed-in users we store, on our backend (Supabase), a per-day count of how many times you have run Hexly, so that free-tier daily limits and Pro's unlimited access can be enforced. This is tied to your account identifier.
History data. If you use the History feature, we store the artifacts you have copied — specifically color values, font specifications, and CSS snippets — along with the page URL where each was captured and a timestamp. History is stored on our backend and tied to your account. We store only these text artifacts. We do not store copied or downloaded image or SVG asset files in History; binary assets are never uploaded to or retained on our servers.
Guest data. If you use Hexly without an account (guest mode), we do not create a server-side record for you. A lifetime run counter is stored locally in your browser using the extension's local storage and never leaves your device.
Technical and log data. Our website is hosted on Cloudflare Pages and our backend is provided by Supabase. Like most hosting and backend providers, these services automatically log basic technical request data — such as IP address, browser and device type, and timestamps — for security, reliability, and abuse-prevention purposes. We use Supabase's built-in analytics to understand aggregate service usage and performance. We do not use this data to build advertising profiles, and we do not combine it with the design content you extract.
Data we do not collect. We do not collect the full content of the web pages you inspect. Extraction of colors, fonts, CSS, and assets happens locally in your browser, and the results are shown to you in the extension. Except for the History artifacts described above, extracted design data is not transmitted to or stored on our servers. We do not track your general browsing history across sites, we do not sell your data, and we do not use third-party advertising trackers.
3. Browser permissions and why we need them
The Hexly extension requests the following permissions:
- storage — to save your local settings, your guest run counter, your signed-in session, and panel state on your device.
- identity — to perform Google Sign-In so you can create and access a Hexly account.
- downloads — to let you download an extracted asset (an image or SVG) directly to your device when you choose to.
- Host access to the sites you use Hexly on — required so the extension can read the page you are actively inspecting in order to extract its colors, fonts, CSS, and assets, and, for asset copying, to fetch asset bytes so they can be placed on your clipboard. This access is used only on pages where you invoke Hexly and only to power the features you trigger. Hexly does not monitor, log, or transmit the pages you visit.
4. How we use information and our legal basis
We use the information above to: create and secure your account; enable and enforce tier limits (guest, free, Pro); enable Pro after a successful Paddle transaction; provide the History feature; maintain the security and reliability of the Service; and respond to support requests. Where data-protection law applies to you, we process this data on the basis of performing our contract with you (providing the Service you request), our legitimate interests (securing and improving the Service, preventing abuse), and your consent where required. We do not use your data for advertising, and we do not serve ads.
5. Third parties
We rely on a small number of processors: Google (authentication), Supabase (account, run-count, History storage, and analytics), Cloudflare (website hosting), and Paddle (payment processing and subscription management). Each processes data under its own terms and privacy policy. We share with them only what is necessary for these functions. We do not sell or rent your personal data to anyone.
6. Data retention and deletion
We retain account, run-count, and History data while your account exists. Guest run-counter data lives only in your browser and is under your control; it is not stored on our servers. Technical logs held by our hosting and backend providers are retained under their respective policies. Subscription and transaction records held by Paddle are retained by Paddle under its own policies. To request deletion of your account and associated data, email support@gethexly.com from the address tied to your account. We will delete your account record, stored run counts, and History data within 30 days of verifying the request. Subscription and transaction records held by Paddle are retained by Paddle under its own policies and legal obligations; deleting your Hexly account does not delete Paddle's billing records, which you can address directly with Paddle.
7. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct inaccurate data, request deletion of your account and associated data, object to or restrict certain processing, withdraw consent where processing is based on consent, and request a copy of your data in a portable format. To exercise any of these rights, contact us at support@gethexly.com. We will respond within a reasonable time and in line with applicable law. You may also have the right to lodge a complaint with your local data-protection authority.
8. Security
We use industry-standard measures to protect data held on our backend, including authenticated access to your account records. Your Pro status is determined on our server from verified subscription confirmations and is never trusted from the client alone. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
Hexly is not intended for and not directed to anyone under 13 (or the minimum age of digital consent in your jurisdiction, if higher). We do not knowingly collect personal data from children.
10. International users
Hexly is operated from Indonesia and used globally. Our processors may store and process data in other countries. By using Hexly you consent to your information being transferred to and processed in countries that may have different data-protection laws than your own.
11. Changes
We may update this Policy. Material changes will be reflected by the "Last updated" date above. Continued use of Hexly after an update constitutes acceptance.
12. Contact
For any privacy question or request, contact us at support@gethexly.com.
