Legal
Privacy Policy
We collect only what running the site, the Theme Studio and Mlola Pro needs. No analytics, no advertising trackers, and we never sell your data.
Last updated 25 September 2026
Who we are
Mlola runs https://ui.mlola.com and is the controller of the personal data described here. Contact us at hello@mlola.com.
What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Account: name, email address, a hashed password | To sign you in to the Theme Studio and your account | Contract |
| Sessions: IP address, browser user agent, sign-in time | To keep you signed in and protect your account | Contract; legitimate interest in security |
| Themes you save, their versions, and the prompts you write in the Studio | To store, version and host your themes | Contract |
| Theme generation log: prompt, result, timing | Rate limits, cost control and fixing failures | Legitimate interest |
| Mlola Pro: licence plan and status, CLI token names (tokens are stored only as hashes), and which Pro items were installed when | To deliver Pro, enforce install limits and trace leaked copies | Contract; legitimate interest |
| Order details from Paddle: order and customer ids, plan | To grant or revoke your licence | Contract |
| Emails you send us | To answer you | Legitimate interest |
We do not receive or store your card or bank details: Paddle.com collects payment as Merchant of Record.
Cookies and local storage
We set one cookie: the sign-in session, which is strictly necessary and lasts up to 30 days. Your browser’s local storage keeps your chosen theme and light or dark mode; it never leaves your device. We use no analytics or advertising cookies. Paddle’s checkout, loaded only on the pricing page when you buy, may set its own cookies under Paddle’s privacy policy.
Who processes data for us
- Paddle.com (payments, invoices, taxes, refunds), as an independent controller under its own privacy policy.
- TypeSafe AI and OpenAI receive the text of a Studio prompt to turn it into a theme. Do not put personal information in prompts.
- Our hosting provider runs the server and database that store the data above.
- npm and GitHub host the open-source packages and code; installing them is governed by their own policies.
Some of these providers are outside your country. Where the law requires it, transfers rely on appropriate safeguards such as standard contractual clauses.
How long we keep it
- Account, themes and licence data: while your account exists.
- Sessions: until they expire or you sign out.
- Generation and install logs: up to 12 months.
- Records we must keep for tax or accounting are kept by Paddle as the law requires.
Deleting your account deletes its themes, sessions, tokens and logs.
Your rights
You can ask to see, correct, export or delete your data, object to or restrict how we use it, and withdraw consent where we rely on it. Email hello@mlola.com from your account’s address; we answer within 30 days. You may also complain to your local data protection authority.
Security
Passwords and CLI tokens are stored only as hashes, traffic is encrypted with HTTPS, and access to the server and code is protected by two-factor authentication.
Children
Mlola UI is for developers and is not directed at children under 16; we do not knowingly collect their data.
Changes
We will update this page when our practices change, and tell account holders by email about significant changes.