Privacy
This page describes what the software actually does. It was written by reading the code that does it, not by adapting somebody else's policy.
No accounts, and one third-party tag: Pinterest
There is no sign-up and no password.
This site carries the Pinterest advertising tag on every public page. It is there so we can see which pins and which ads actually bring people here, and how many of those visits end in a purchase. It is the only third-party script on this site.
It sets cookies — _epik and _pinterest_ct_ua, from ct.pinterest.com — and it tells Pinterest that a browser reached a page on this domain, and, if you buy, that a purchase was completed. Pinterest uses that under its own privacy policy, which is not ours and which we do not control. Your browser's own settings, and any tracker blocker you already run, will stop the tag; nothing on this site needs it to work.
A completed sale is also reported to Pinterest by our server, and a blocker cannot stop that half. This is the honest limit of the sentence above: blocking the tag stops what your browser sends, not what our server sends. When a payment is confirmed we send Pinterest the sale on its own, from the server, carrying a one-way scrambled form of your email address — a SHA-256 hash, which is what lets Pinterest tell that the person who bought is the person who saw the ad — together with the amount and currency of the sale. Both halves carry the same reference number so Pinterest counts the sale once rather than twice.
What is not sent to Pinterest: your wall's style, its width, its height, or anything else about the plan you bought. Those stay on our own server. Nor is your email address sent in readable form. If you want no server-side report at all, the only way is not to buy — and we would rather say that plainly than leave the sentence above sounding like a complete answer.
What has not changed: there are still no accounts, there is no Google Analytics, there is no social widget and no comment system, and the fonts are served from this domain rather than from a font network. Our own usage tracking stays first-party — it goes to this site's own server and to nobody else's, and it is described in full below.
What stays in your browser
Your work is kept in your own browser's local storage, on your device:
- your saved walls — the "My walls" library, under
geowall-library-v1 - the wall you are working on, and the shared room settings it is drawn with
- a random visitor id, under
trimbid-analytics-visitor-v1, and a small buffer of unsent usage events
None of this is readable by us. Clearing your browser data deletes it — which is why a purchase is recoverable from your link and your email instead.
Usage events
The app records anonymous events so we can see where the tool is confusing. Eleven event names exist and no others are accepted: opening the app, picking a style, measuring a wall, generating a plan, seeing the pay prompt, tapping unlock, saving a wall, setting the baseboard, setting the wall height, opening one of the calculator pages, and completing a purchase.
Two of those are recorded outside the design tool. Opening a calculator page notes which page was opened, and — if you arrived from a link somewhere else — the site's name only, such as www.google.com. Never the full address you came from: a search link carries what you typed, and what you typed is not ours to keep.
Completing a purchase is not recorded by your browser at all — our server writes it when the payment processor confirms the payment, so that a sale is still counted if you close the tab. It notes the same three things a plan does: the style and the wall's width and height. It does not record the amount, and your browser cannot send this event — the collector refuses it, so a sale can only be recorded by the payment confirmation itself.
An event carries a timestamp and a small set of properties — wall dimensions, the style, and counts such as how many pieces or obstructions a drawing came to. A rollup per visit records how long the visit lasted and how many plans, saves and unlocks it contained.
Alongside the parsed events, the raw batch your browser sent is stored verbatim as a second copy. It contains the same events and ids and nothing further; it is kept as insurance against a parsing mistake on our side.
What is not recorded, as a rule the collector enforces rather than a promise: no name, no email address, no postal address, no location, no free text you typed, and no contents of a saved wall. The visitor id is a random value — it is not derived from you or your device, and there is no fingerprinting of any kind.
If you buy a plan, that id stops being anonymous. The purchase record is linked to it, so we can see which visits led to sales — which means the usage events from that browser can be connected to the email address on your purchase, including the ones recorded before you bought. Nothing extra is collected at that moment; what changes is that what was already collected becomes attributable to you. If you never buy, no such link is ever made.
The application does not record your IP address or your browser's user-agent string. Our web host keeps its own server access logs, as every web host does; those are the host's ordinary operational records and are not part of this system.
When you buy a plan
Payment is handled by Stripe on Stripe's own page. Card numbers never reach this site's server and are never stored by us. Stripe processes your payment under its own privacy policy.
Two things are stored on our server around a purchase.
When checkout starts, before payment completes, a copy of the wall design you are buying is uploaded and stored against the Stripe session — the wall's id and the design itself. This is what lets your link reopen the plan afterwards on any device.
When payment completes, Stripe tells our server, and a purchase record is written:
- your email address, as given to Stripe — the recovery path if you lose your link
- Stripe's session and payment references, the amount and currency, and the time of purchase
- the wall the purchase is for: its id, the width it was bought at, and — for support, never for access — the height, pattern and preset you were looking at
Your name is not stored. Stripe returns the cardholder name with every payment and this site used to keep it. It was never read by anything — a plan is delivered by email and by your link, and a name is part of neither — so as of 11 August 2026 it is not written at all.
Your unlock link is never stored. Only a one-way SHA-256 hash of it is kept, which is enough to recognise your link and not enough to reconstruct it.
Your email address is used to identify your purchase and to answer you. It is not added to a mailing list, and no marketing email is sent from this site — there is no mailing list to add it to.
How long it is kept
Purchase records are kept as the receipt for your purchase and as the means of restoring your plan if you lose it. Usage events are kept while they are useful. There is no automatic deletion schedule today, which is stated because it is true rather than left unsaid.
Asking for your data, or its deletion
Email plans@instantwallapp.com from the address you bought with, and you can have a copy of what is held about you, or have it deleted. Deleting a purchase record ends the link that reopens that plan — the plan you already downloaded is unaffected.
Changes to this policy
If what the software records changes, this page changes with it and the date below moves.
Last updated 3 September 2026