Skip to content
designoboLog in

Privacy policy

Last updated

Who is responsible

ByteBridge LLC operates Designobo and is responsible for the personal data described here. This policy covers designobo.com and preview.designobo.com. For privacy questions or requests, contact [email protected].

Our mailing address is 8 The Green, Suite B, Dover, DE 19901, United States.

What we collect

  • Account information: your email address, display name, Google account identifier, team membership, selected model and account timestamps. We store sign-in session records, not your Google password.
  • Project content: project names, instructions, conversation history, comments, drawings, image attachments, generated screens, AI tool results and canvas layout.
  • Billing and usage: credit balances and transactions, model usage and token counts, subscription status and billing periods, and Stripe customer, subscription, invoice and checkout identifiers. Stripe collects payment details; we do not store full card numbers.
  • Technical and support information: service logs, error reports, request context and information you send us by email. Our hosting and security providers process connection information such as IP addresses, browser details and request times.

Why we use it

We use data to sign you in, save and generate prototypes, provide previews and exports, manage credits and payments, respond to requests, prevent abuse and diagnose errors. Account and project information is needed to provide the service; without it, some features cannot work.

Where data-protection law requires a legal basis, we rely on performance of our contract for providing the service; legitimate interests for security, reliability and support, balanced against your rights; and legal obligations for required financial records and lawful requests. Where consent is required for an optional use, we will request it separately. We do not sell your personal information or use project content for targeted advertising.

AI processing and training

Generating a prototype or project title sends relevant instructions, conversation history, screen content and, where supported, attachments to third-party AI services through OpenRouter and downstream providers serving the models. This can include earlier content in the project, not just your latest message. Models and providers may change over time.

We do not train AI models on your project content. We use OpenRouter's data-collection restriction to exclude provider routes that permit collection for training. OpenRouter still records request metadata, such as model, token counts, timing and cost, and describes limited anonymous prompt categorisation in its data collection documentation.

No training does not mean no retention: providers may process or retain data for security, legal compliance and other purposes under their applicable terms. We do not promise zero data retention. Only submit personal or confidential information if you are authorised to share it with these services. We will update this policy and notify you before a material change to how project content is used, obtaining consent where required.

Who receives data

  • Authentication providers: sign-in and account verification.
  • OpenRouter and downstream AI inference providers: AI processing of project content and usage metadata.
  • Hosting, database and storage providers: storing and processing account information, project content, image attachments and billing records.
  • Traffic delivery and security providers: delivering the service and protecting it from abuse, using connection and request information.
  • Payment providers: checkout, subscription management, payments and related billing information.
  • Error monitoring providers: technical diagnostics, which may include errors and request context.

Providers receive data relevant to their role. Services you interact with directly, such as Google sign-in and Stripe checkout, also explain their processing in their own privacy notices. We may disclose information when legally required or necessary to protect people, enforce our terms or investigate abuse.

Connected tools

When you connect an external tool through MCP, it can read and modify project content within the permissions you authorize. The tool and any providers it uses handle content they receive under their own terms and privacy policies.

Hosted previews

Anyone with a hosted preview link can view its screens without signing in. Treat these links as shareable access, not as private storage. Do not put information in a preview that its recipients should not see. Generated screens may load third-party resources, such as images or fonts, whose hosts receive the visitor's connection information.

Cookies and browser storage

We use cookies to maintain your sign-in session and secure the login process. We use local storage to remember interface preferences, such as panel sizes. Blocking these may prevent sign-in or reset preferences. Third-party services may use their own cookies when you visit them; their notices explain those uses.

Retention and deletion

We keep account and project data to provide your saved work and session history. Deleting a project in the app currently marks it as deleted; it does not immediately erase all associated database records. For account closure or a data-deletion request, email [email protected].

Retention depends on the purpose: providing your account and saved projects, investigating security incidents, resolving disputes, and meeting financial or other legal obligations. Some information may need to be retained after closure for those purposes. Copies may also remain in backups and service-provider logs for their applicable retention periods. We do not promise immediate deletion from every system.

International processing and security

Our providers may process information outside your country, including in the United States, where data-protection laws may differ. Contact us for information about processing locations and the transfer safeguards applicable to your data.

We use HTTPS and account access controls to help protect data, but no online service can guarantee complete security. Keep your sign-in account secure and report suspected unauthorised access to us.

Your rights

Depending on where you live, you may have rights to access, correct, delete or receive a portable copy of your personal data, restrict processing, or object to processing based on legitimate interests. If we rely on consent, you can withdraw it without affecting processing that was lawful before withdrawal. You may also complain to your local data-protection authority.

Send requests to [email protected]. We may need to verify your identity and will respond within the time required by applicable law. Designobo is intended for adults aged 18 and over. Contact us if you believe a child has provided personal information so we can investigate and address it.

Changes to this policy

We will update the date above when this policy changes and provide notice of material changes through the service or by email. Our terms of service explain the conditions for using Designobo.