Privacy Policy
Last updated: 15 August 2026
This policy explains what personal data Design Corpus collects, why, and how it is handled. We collect the minimum needed to run the Service.
1. What we collect
Account data
- Email address and, optionally, a display name.
- If you sign in with Google: your Google account email, name, and profile image, as provided by Google.
- If you use a password: a salted hash of it (never the password itself).
Purchase data
- Payment is processed by Stripe. We receive your email, the amount, and Stripe's transaction identifiers. We never see or store card numbers.
Usage data
- When your AI agent connects to our MCP endpoint, we log requests (which tool was called, when, and by which account) to operate the Service, enforce license tiers and fair use, and detect abuse.
- OAuth authorizations you grant to agents (client name, timestamps), so you can see and revoke them.
- Standard server logs (IP address, user agent, timestamps) for security and reliability.
We do not collect the content of the projects you build with your agent, and we do not track you across other websites.
2. How we use it
- To provide the Service: authenticate you, link purchases to your account, serve references at your tier.
- To send transactional email: password reset codes, purchase confirmations, important account or policy notices. (Sent via Resend.)
- To enforce our Terms, prevent fraud and abuse, and process refunds.
- To improve the Service using aggregate, de-identified usage patterns.
We do not sell personal data, and we do not send marketing email unless you opt in.
3. Where it lives — our processors
- Convex — database, authentication, and file storage (US-hosted).
- Vercel — website hosting.
- Stripe — payments.
- Resend — transactional email.
- Google — only if you choose "Continue with Google".
Each processor handles data under its own privacy terms and appropriate safeguards. Data may be processed outside your country.
4. Cookies
We use only strictly necessary cookies: your session, and security tokens for sign-in. No advertising or cross-site tracking cookies. Because these are essential, no consent banner is required; you can clear them any time by signing out or clearing your browser.
5. Retention
- Account data: for as long as your account exists.
- Purchase records: as long as required for tax and accounting obligations (typically 7 years).
- MCP usage logs: rolling window of up to 12 months, then deleted or aggregated.
6. Your rights
Depending on where you live (including under GDPR and similar laws), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any of these, email us — we respond within 30 days. Deleting your account removes your personal data, except purchase records we are legally required to keep.
7. Reference sites in the library
The library contains screenshots and design metadata of publicly accessible websites. This is information about websites, not about individuals; we do not intentionally collect personal data through it. If a screenshot contains personal information and you would like it removed, contact us.
8. Security
Data is encrypted in transit (TLS) and at rest by our processors. Access tokens are random, expiring, and revocable. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.
9. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
10. Changes and contact
We may update this policy; material changes will be announced on the site or by email. Privacy questions or requests: hello@designcorpus.com.