Last updated: 20 August 2026
CATWLK is a local-first browser extension and stylist workspace. It analyzes
retailer product information, organizes client edits, and can share selected
review or intake data through the CATWLK service. CATWLK has no advertising
network and does not sell personal information.
On supported Zara, H&M, Mango, Uniqlo, COS, Massimo Dutti, ARKET,
& Other Stories, Sézane, ASOS, Weekday, GANNI, Abercrombie & Fitch,
Reformation, and Zalando domains, CATWLK checks the current URL to determine
whether it is a recognized product page. Only on a recognized product URL may
it read the retailer, product title, displayed price, image URL, declared fiber
composition, care instructions, and structured product data. On category,
cart, account, checkout, and other non-product routes, it does not inspect page
content or form fields.
On another retailer, generic capture runs only when the user invokes CATWLK on
the active tab and may inspect visible page text and structured product data to
attempt a product capture. CATWLK does not read values entered in form fields,
passwords, payment-card or bank-account credentials, contacts, precise
location, or browser history outside the supported or user-invoked active page.
Depending on the features chosen, CATWLK may handle stylist and client identity
and contact information; authentication information; client comments, feedback,
and other communications; optional general location, climate, or timezone;
optional measurements, comfort, mobility or sensory needs, allergies, and
material sensitivities; budgets, purchase dates, purchase prices, and wear
records; captured product URLs and product-page content; and operational
activity required for edits, reviews, intake, synchronization, and abuse
protection.
Optional health-related information is used only to adapt fit, comfort, and
material recommendations. Financial information is limited to user-entered
budgets and purchase records plus retailer-displayed product prices. CATWLK
does not collect payment-card numbers, bank-account credentials, credit
ratings, or financial statements.
Products, comparisons, notes, tags, purchase and wear records, preferences,
local client profiles, edits, recommendations, report data, and branding may be
stored in the browser's local extension storage. Wardrobe summaries are calculated on the
device. Authentication refresh tokens and raw review/intake tokens use a
separate local secrets record excluded from backups, diagnostics, reports, and
browser sync.
Material preferences, limits, and display settings may use
the browser's extension sync storage when available; the browser vendor controls that synchronization. Where sync storage is unavailable, CATWLK falls back to local storage. Removing CATWLK
deletes its local extension storage, subject to the browser's own sync behavior.
CATWLK does not transmit local product, browsing, preference, or client records
automatically. Makepad Keycloak uses Authorization Code Flow with PKCE where
the browser exposes an identity API and Device Authorization Grant on supported
mobile/Safari targets. Signing in does not migrate existing extension records.
Before connection, CATWLK asks the user to acknowledge the cloud data
categories and records the policy version and acceptance time locally.
A stylist may use a CATWLK password account or continue with Google or Apple.
For a social login, Keycloak receives the provider identifier, a
provider-verified email address, and an optional name. CATWLK does not store the
Google or Apple access token. A matching existing account is not linked from
email alone: the stylist must confirm ownership with the existing CATWLK
password. Google and Apple process authentication under their own privacy
terms.
When a stylist explicitly migrates a client, CATWLK previews record counts and
the API verifies a SHA-256 checksum before PostgreSQL becomes authoritative for
that client. Cloud-managed captures and offline mutations are written locally
first and then synchronized with idempotency protection. Unselected local
clients remain local.
When a stylist publishes a review, CATWLK stores the selected client-facing
snapshot together with workspace-local client, edit, and item reference IDs
needed to connect responses to the edit. An intake stores the context selected
by the stylist and answers submitted by the client. Clients can respond without
an account. Intake submissions include the privacy-policy version and
acceptance time confirmed by the client. Raw bearer tokens remain after the URL #; PostgreSQL stores only
their cryptographic hashes. Internal profile notes and unrelated clients are
not added to a shared snapshot. Private file objects will use MinIO when file
features are enabled.
The server records operational events required to run edits, reviews, intake,
synchronization, and abuse protection. It does not receive general browser
history or include advertising trackers.
Paid checkout is disabled until CATWLK's commercial release gate is complete.
If enabled, checkout opens a user-requested Lemon Squeezy page and the extension
requests optional access to https://api.lemonsqueezy.com/*. Activation sends
the entered license key and a generated device label. Validation and
deactivation send the license key and instance ID. Lemon Squeezy returns license
status, plan information, expiration, and purchase email. No product, retailer,
client, report, preference, or usage records are included in those requests.
A Copy action writes only the requested analysis, comparison, diagnostic, or
client link to the clipboard. Diagnostics omit saved products, notes, client
records, and preferences. A product URL is included only when the user opts in.
Optional local reminders request browser alarms and notifications only when the
stylist enables them and do not put client names in notification text.
Retailer images remain referenced by their source URL, so opening a shared
review may make an ordinary request to that retailer. CATWLK does not claim
ownership of retailer content.
Users can delete supported local records and extension data. A stylist can
revoke an active review or intake link, and can separately make a delivered
review view-only. Review links expire after 30 days and intake links after 14
days unless they are revoked earlier. A signed-in stylist can delete their
cloud account from CATWLK Settings. CATWLK removes the user's active workspace
records, sessions, private links, and stored objects. For a genuinely shared
workspace, CATWLK removes that membership and transfers ownership instead of
deleting other members' work. CATWLK then opens the secure identity page for
confirmation of the Keycloak identity deletion. CATWLK does not keep a separate
application-level backup copy of deleted account data.
CATWLK uses only the permissions and retailer hosts declared by each generated
browser manifest. Analysis appears in a side panel on supported Chromium
desktop browsers, a native sidebar on Firefox desktop, and a full-page
extension tab on Safari and supported mobile browsers. User-invoked generic
capture uses activeTab and scripting. Makepad Keycloak sign-in uses the
browser identity redirect where available and device authorization elsewhere.
Required first-party hosts are limited tocatwlk.com for the CATWLK API and auth.catwlk.com for Makepad Keycloak.
The only optional host is api.lemonsqueezy.com, for license actions if paid
activation is enabled.
Information received from Google APIs is handled under applicable browser-store
and Google API user-data policies, including Limited Use requirements.
Material changes will be reflected here and in the extension's release notes
before distribution. For privacy or support requests, visit
CATWLK Help or the public
CATWLK support tracker.