Skip to content

Policy

Privacy policy

Most of this product never sends your work anywhere. Here is the part that does.

Last updated
2 September 2026
Applies to
huegrade.com and every tool on it

This policy covers huegrade.com and the tools on it. It is written to be read, so where a legal phrase and a plain one mean the same thing, we use the plain one.

The short version. You can use every color tool here without an account and without us storing anything about you. Images you open in the photo picker or the editor are processed in your browser and are never uploaded. If you make an account we keep your email, your saved palettes and your subscription status — and delete them on request.

Who we are

HueGrade is run by Faysal Khan. For anything in this policy, including an access or deletion request, write to mdfaysalkhancse@gmail.com — the same address as the contact page.

What we collect

If you never sign in: nothing that identifies you

The generator, contrast checker, gradient maker, converter, photo picker, editor and the rest run entirely in your browser. Palettes you build are held in the page and in your browser’s own storage. We do not need, and do not have, an account for you.

Our hosting and the optional analytics described below still see the ordinary traffic data any web request carries — IP address, browser and referring page — which is used to serve the site and to count usage in aggregate.

If you create an account

  • Your email address, and a password stored only as a bcrypt hash. We cannot read your password, which is also why a reset is the only recovery route.
  • If you sign in with Google: the account identifier, email, name and avatar URL Google returns. We never receive your Google password, and we ask for nothing beyond basic profile and email.
  • Session records — a random id and an expiry — so you stay signed in between pages.
  • Palettes you save to your account, with their names.
  • Subscription status for Pro: your plan, the customer and subscription identifiers from our payment provider, and the date the current period ends.

What we never collect

  • Your images. Photos you upload to the picker or the editor are read by your browser and never sent to our servers. An image you fetch by URL, and stock photos, pass through a proxy so the browser is allowed to sample them — that proxy fetches the file and hands it back; it does not keep a copy.
  • Card details. Payment happens on our provider’s checkout page. We never see or store a card number.
  • Anything sold or brokered. We do not sell personal data, and we do not share it for advertising beyond what the AdSense tag itself does on your device — which you can switch off entirely on the cookies page.

Why we are allowed to hold it

  • To provide the service — an account, its sessions and its saved palettes exist because you asked for them.
  • To keep the service working and safe — rate limiting, abuse prevention, and aggregate usage counts.
  • To bill you — subscription records, where you have bought Pro, including the financial records we are required to keep.
  • Optional analytics and advertising, which you can turn off on the cookies page.

Who processes it for us

We use as few third parties as the product allows, and each one sees only what its job needs.

  • Vercel — hosts the site.
  • Neon — hosts the PostgreSQL database holding accounts, sessions and saved palettes.
  • Google — OAuth sign-in (only if you use it), Analytics and AdSense (both optional).
  • HandyPay — subscription checkout and billing. Card details go to it and its payment processor, never to us.
  • Resend or an SMTP provider — sends the password reset email, which is the only email we send.
  • Pixabay — supplies stock photo search and the sample image. Your search terms reach it; your identity does not.

These providers operate internationally, so data may be processed outside your country. Where that involves a transfer out of the EEA or the UK, we rely on the providers’ own standard contractual clauses.

The site inspector

The site inspector fetches a URL you give it from our server, reads its stylesheets, and returns the colors and type styles. We log that request the way any server logs a request; we do not build a profile of the sites you scan and we do not republish them. Only submit URLs you are allowed to look at.

How long we keep it

  • Sessions expire on their own, and are deleted when you sign out.
  • Password reset tokens are stored hashed, are single-use, and expire shortly after being issued.
  • Account data and saved palettes are kept while the account exists, and deleted when you ask us to close it.
  • Billing records may be retained after that where accounting rules require it.

Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop using it. Depending on where you are — GDPR in the EU and UK, the CCPA in California, and comparable laws elsewhere — some of those are legal entitlements rather than courtesies. We do not distinguish: email mdfaysalkhancse@gmail.com from your account address and we will act on it, normally within 30 days.

Deleting your account deletes your saved palettes with it. Export anything you want to keep first — every palette exports as CSS, Tailwind, SCSS, JSON or design tokens without an account at all.

Children

This is a professional design tool and is not directed at children under 13. We do not knowingly collect their data; if you believe we have, tell us and we will delete it.

Security

Traffic is encrypted in transit. Passwords are hashed with bcrypt and are never stored or logged in readable form. Session cookies are httpOnly, so page scripts cannot read them. No system is perfect, and if a breach ever affects your data we will tell you rather than wait to be asked.

Changes

When this policy changes materially we update the date at the top of this page. For a change to what we collect or who we share it with, we will say so on the changelog as well — a silently edited privacy policy is not a notice.