Security & privacy overview

Mockuuups Studio is built local-first for design work: on the web, desktop app, and plugins, your imported designs are processed on your device. Account data (email, auth, billing metadata) is stored with standard protections—encryption in transit (TLS) and at rest. This Help article is a short security and privacy overview for customers and vendor questionnaires; formal terms live on our legal pages.

Do you upload my designs?

For normal use of Mockuuups Studio (web, desktop, and plugins), no—imported designs stay on your device. We serve the mockup gallery from our servers; file contents are not uploaded for ordinary mockup creation. Analytics may include which mockup you used and the file extension—not the filename or image contents.

Details: Do you upload images I import somewhere? Is my intellectual property safe? · Security

Optional features that use our servers

  • Share links — only when you choose to create a share; that shared asset is uploaded for that purpose.
  • Server-side rendering (planned) — if local rendering fails (for example WebGL issues), we may offer a server fallback. This is not the default path and is not live yet. It will require an informed opt-in.

See Security for the full wording.

Encryption and infrastructure

  • Data in transit is protected with TLS 1.2+
  • Stored account data is encrypted at rest
  • Public traffic is served through Cloudflare, including DDoS mitigation and web application firewall (WAF) protections
  • Production is isolated from development and staging
  • We monitor service health and application errors and alert our operations team

Providers and regions: List of Subprocessors

Full overview: Security

Authentication, passwords, and SSO

You can sign in with magic link emails, Google, Apple, or GitHub. Optional passwords follow our password policy. Team plans support SAML SSO.

Delete account and data retention

You can delete your account in account settings. Per our Data Processing Agreement (DPA), we delete account data within 30 days of termination or request. Billing records may be retained by our payment provider as required by law. We do not currently auto-delete inactive accounts.

AI

We do not use your imported designs to train AI models. If we offer on-device assist features in the future, that processing would stay on your device and would be opt-in.

Use these pages for formal commitments (GDPR, DPA, privacy, security questionnaires):

Report a security issue

Email hello@mockuuups.com. We also publish a contact pointer at /.well-known/security.txt. Personal data breaches are handled under our DPA (notify without undue delay, within 72 hours of becoming aware).

What we don’t claim

We do not publish SOC 2, ISO, or formal pen-test reports. For what we do practice, start with Security and the documents linked above.

Still need help? Contact Us