Privacy Policy
Last updated:
Summary. We collect what we need to run DesAIgner: your email address and password (stored only as a secure hash), or your Google account details if you sign in with Google, the ideas and files you give us, the designs we generate for you, and records of your credits and purchases. To generate designs, we send your project content to OpenAI; we don't send your email address or name, and according to OpenAI's API policy, API data is not used to train its models. Before we generate images from text you type, that text is checked against our content rules by Creem, our payment provider. Payments are handled by Creem, so we never see your card number. We send account emails through Resend, and we use Sentry to find and fix errors, without your prompts or your email address. We use analytics (PostHog) only if you agree in the cookie banner. We don't sell your data and we don't show ads. You can delete a project or your whole account yourself in the Service, and you can ask us for a copy of your data at any time: email faris@elevatesolutions.ba.
1. Who is responsible for your data
The controller of your personal data is:
Elevate Solutions, vl. Faris Rizvanović
Vilsonovo šetalište 9, 71000 Sarajevo
Bosnia and Herzegovina
Email: faris@elevatesolutions.ba
Data protection officer: [DPO CONTACT]
Representative in the European Union (GDPR Article 27): [EU REPRESENTATIVE]
This policy covers the DesAIgner website and the DesAIgner service (together, the "Service"). It doesn't cover the checkout of our reseller, Creem, which has its own privacy policy (section 5), or your Google account, which is covered by Google's privacy policy (section 5).
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Your email address, your name if you give one, your password stored only as a one-way hash (we can never read it), whether and when you confirmed your email address, your email preferences (for example whether we email you when your designs are ready), your account role and a counter used to sign you out of all devices | You, when you sign up or change your settings |
| Google sign-in | If you choose "Continue with Google": your Google account ID, your email address, whether Google has verified that address, and the name on your Google account. We keep the Google account ID (to recognise you next time), the email address and the name. We don't receive your Google password, and we don't keep your profile picture or any Google access token | Google, when you sign in with it (section 5) |
| Email links | When we email you a link to confirm your address or reset your password: a one-way hash of the link's secret code (never the code itself), the address it was sent to, when it expires and whether it was used | The Service |
| Free-credit record | A keyed one-way fingerprint (a hash) of your email address in a simplified form (lowercase, without a "+" suffix and, for Gmail addresses, without dots), so that the same person receives the free credits only once (section 3). It can't be turned back into your address without our secret key | The Service |
| Project content | Your app ideas, style hints, platform and screen choices, edit instructions and variant directions, and the plans, briefs, design systems, flow maps and code generated for you, including your edits | You, and the Service |
| Uploaded files | Images you upload for your own style or a saved brand kit, for example logos and reference screenshots. We re-encode them and remove embedded metadata (such as location data) | You |
| Generated images | Overview boards, screen images, screen versions and asset images. ZIP exports are built when you download them and are not stored | The Service |
| Share links and your comments | For each link you create to share a project: its label, what it shares, whether it allows downloads and comments, whether the badge is hidden, its expiry, its password stored only as a one-way hash, and when it was created or turned off. The comments and replies you write on your screens: the text, the screen, an optional position on it, the time and whether the thread is resolved | You |
| Comments from visitors to a shared project | If a project owner allows comments on a link and you comment as a visitor (no account needed): the name and email address you enter, your comment text, the screen and optional position on it, the link it was written on and the time | You, when you comment |
| Usage records | For each AI request: the time, project, step, AI model, amount of text and images processed, duration, whether it succeeded (and an error code if not) and what it cost us. For each content check (section 4): the time, project, step, how long it took and what it cost us, but not the text itself | The Service |
| Credit and billing records | Your plan, subscription status and billing periods, credit grants, holds, charges, refunds and expiry, purchases, and billing events such as a support credit or a reset by our staff (with the staff member and reason) | The Service, and Creem |
| Payment data | From Creem we receive your order and subscription identifiers, product, amount, currency, country, payment status and, where needed, your name and email. We never receive your full card or bank details | Creem |
| Emails we send you | The emails themselves (for example a confirmation link, a password-reset link, a notice that your designs are ready with the project's title, or a billing update) and their delivery status | The Service, and our email provider (section 5) |
| Technical data | Your IP address, browser and device information, request logs, and error reports (section 5) | Your browser, our hosting provider |
| Analytics data (only with your consent) | A random or pseudonymous ID, the pages you visit (the address without search terms or project IDs), the type of browser and device, and a short list of product events: signed up, confirmed email, created a project, approved a plan, screens finished, downloaded an export, started a checkout, started a subscription. Event details are limited to things like the platform, the number of screens or the plan chosen, never your prompts, project titles or email address | Your browser and our servers, only after you accept analytics (section 5) |
| Cookies and local storage | A sign-in session cookie, security cookies, a cookie that records your cookie choice, an email-confirmation link kept in your browser tab for a moment while you sign in, your display preferences and, only if you accept analytics, PostHog's analytics storage. No advertising cookies. See the Cookie Policy | Your browser |
| Messages | What you write when you contact us, and our replies | You |
We don't ask for special categories of personal data (such as health data). Please don't put personal data about other people, or sensitive information, into your app ideas or uploads unless it is needed.
3. Why we use it, and our legal bases
| Purpose | Data used | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Create and secure your account, sign you in (with a password or with Google), confirm your email address, let you reset a forgotten password | Account data, Google sign-in data, email links, cookies, technical data | Contract (b) |
| Send you the emails the Service needs: email confirmation, password reset, account deletion confirmation, billing updates, and notices that your designs are ready or that your credits are running low | Account data, emails we send you | Contract (b). You can turn off "designs are ready" emails in Settings |
| Send you security notices, for example when your password was changed or Google sign-in was connected to your account | Account data, emails we send you | Legitimate interests (f): protecting your account |
| Generate and store your designs, let you edit and download them | Project content, uploaded files, generated images | Contract (b) |
| Let you share a project through a link, and read, answer and manage the comments on it | Share links and your comments, visitor comments, project content, generated images | Contract (b) |
| Receive a visitor's comment on a shared project, show it to the project owner and to other visitors of the same link, and tell the owner about it | Visitor comments | Legitimate interests (f): the project owner's interest, and ours, in receiving and answering the feedback the visitor chose to send |
| Protect shared links against abuse: limits on password attempts, comments and downloads, spam checks | Technical data (IP address), visitor comments | Legitimate interests (f): protecting the Service, project owners and visitors |
| Run the credit system: show prices, hold, charge and refund credits, apply plans and packs | Credit and billing records, usage records | Contract (b) |
| Take payments, issue invoices, handle taxes (done by Creem as reseller) | Payment data | Contract (b); legal obligation (c) |
| Keep accounting and tax records | Credit and billing records, payment data | Legal obligation (c) |
| Check the text you type against our Acceptable Use Policy before we generate images from it (done by Creem, section 4) | Project content, usage records | Legitimate interests (f): keeping prohibited content out of the Service, and meeting our payment provider's requirement to screen it |
| Prevent abuse and fraud: rate limits, limits on free credits and on repeated failed generations, investigating misuse of the Service | Account data, usage records, technical data | Legitimate interests (f): protecting the Service, our users and our costs |
| Give the free credits only once per person, including after an account is deleted | Free-credit record | Legitimate interests (f): preventing abuse of the free credits |
| Delete accounts whose email address is never confirmed, so nobody can hold on to an address they don't own | Account data | Legitimate interests (f): protecting the owners of email addresses |
| Keep the Service working and secure: error logs and error reports (Sentry), troubleshooting, backups | Technical data, usage records | Legitimate interests (f): running a reliable, secure service |
| Understand how people use the Service, to improve it: product analytics (PostHog) | Analytics data | Consent (a), given in the cookie banner. You can withdraw it at any time under "Cookie settings" (section 8) |
| Understand costs and set prices, using totals across users (for example the average AI cost of a step) | Usage records, credit records | Legitimate interests (f): running the business sustainably |
| Answer your messages and support requests | Messages, and the account data needed to help you | Contract (b), or legitimate interests (f) |
| Tell you about important changes to the Service, these policies or your plan | Account data | Contract (b); legal obligation (c) |
| Establish, exercise or defend legal claims | Any relevant data | Legitimate interests (f) |
Where we rely on legitimate interests, you can object (section 8). Where we rely on consent, you can withdraw it at any time; that doesn't affect what we did before you withdrew it. We don't send marketing emails. If we ever do, we will ask for your consent first where the law requires it.
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Automatic limits in the Service (such as rate limits, pausing new generations after many failures, or not giving free credits twice to the same email address) are technical safeguards; you can always contact us about them.
4. How your content is processed by AI (OpenAI)
The Service generates designs with the OpenAI API, provided by OpenAI, L.L.C. (USA), which acts as our processor.
What we send to OpenAI, only when you start a step that needs it:
- Plan: your app idea, style hints, platform and screen count, together with our own instructions.
- Overview board and screens: a description built from your plan (brief, design system, screens and flow). For screens, we also send the overview board image and, for most screens, an earlier screen of the same project as style references.
- Find assets: the screen image, to list the elements on it.
- Assets: a cut-out of the screen image around the element you chose.
- Edits, variants and code export: the screen image and your edit instruction or variant direction; for code export, the screen image and the design system.
- Uploaded files: the logo and reference images of your own style or brand kit, when a step uses them.
What we don't send: your email address, name, password, account ID, payment data or IP address. OpenAI receives the requests from our servers, not from your browser.
Content screening (Creem)
Before we generate images from text you type, our servers send that text to Creem's content moderation service, provided by Armitage Labs OÜ (Estonia), the company that operates Creem. Creem checks it against its content policies and answers "allow" or "refuse"; for this purpose Creem acts as our processor. Creem requires this check from every AI image product that uses it for payments. If the text is refused, nothing is generated and nothing is charged.
What we send to Creem, only when you start a step that turns your text into images:
- New project: your app idea, style hints and any font names you enter.
- Plan approval: all the text in the plan you approve (for example the brief, design system names, screens, elements, flow labels and chart labels), including your edits.
- Your style: font names you enter.
- Edits and variants: your edit instruction or variant direction.
- With each request, a pseudonymous reference made of internal IDs (your account ID, the project ID and the step), so that Creem can audit its checks. It doesn't contain your name or email address.
What we don't send to Creem for screening: your email address, name, password, uploaded or generated images, or your IP address. Creem receives the requests from our servers, not from your browser.
What we keep. We don't store the text a second time for this. For text that passed, we keep a one-way fingerprint (a hash; the text itself is not stored with it) with the project for up to 30 days, so the same text isn't checked again; it is deleted with the project. We keep a usage record of each check (section 2), without the text. How Creem keeps the text it receives is governed by our agreement with Creem and Creem's Privacy Notice.
How OpenAI handles it. According to OpenAI's published API data-usage policy at the time of writing, data sent to the OpenAI API is not used to train OpenAI's models unless the customer opts in, and OpenAI may keep API inputs and outputs for up to 30 days to detect abuse, after which they are deleted unless the law requires longer retention. We have not opted in to share data for training. We ask OpenAI not to store our text requests beyond what it needs to answer them. This is OpenAI's policy, not a promise we can make for OpenAI; see OpenAI's API data controls and OpenAI's privacy policy.
5. Who we share it with
We share personal data only with the providers below, who process it for us under contracts that require them to protect it and use it only on our instructions, and with the reseller and the sign-in provider described below.
| Recipient | What they do for us | Data | Location |
|---|---|---|---|
| Vercel Inc. | Hosts the website and application; keeps request and error logs | All data processed by the Service, technical data | EU (Frankfurt, Germany) |
| Neon, Inc. (Postgres, through the Vercel Marketplace) | Stores our database | Account data, project content, usage, credit and billing records | EU (Frankfurt, Germany) |
| Vercel Inc. (Vercel Blob) | Stores images | Generated images, uploaded files | EU (Frankfurt, Germany) |
| OpenAI, L.L.C. | Generates plans, images and code (section 4) | Project content, uploaded files, generated images used as references | USA |
| Armitage Labs OÜ (Creem) | Checks the text you type against content policies before images are generated from it (section 4) | Project text (ideas, style hints, font names, plan text, edit instructions, variant directions), pseudonymous account and project IDs | Estonia (EU) [CREEM MODERATION PROCESSING LOCATION] |
| Plus Five Five, Inc. (Resend) | Sends the emails about your account (see "Emails" below) | Email address, your name if you gave one, the content of each email, delivery data (time, status, bounces) | USA |
| Functional Software, Inc. (Sentry) | Collects error reports so we can find and fix bugs (see "Error reports" below) | Technical data | EU (Frankfurt, Germany) |
| PostHog, Inc. | Product analytics, only if you accept analytics (see "Analytics" below) | Analytics data | EU (Frankfurt, Germany) |
Our reseller. Purchases are made from Creem, operated by Armitage Labs OÜ (Estonia), which acts as the merchant of record: it sells you the plan or credit pack, takes payment, handles tax and invoices, and handles payment disputes. For that, it is an independent controller of the data you give it at checkout, under its own privacy policy: Creem's Privacy Notice. It shares with us the payment data listed in section 2. When you delete your account, we cancel your Creem subscription, and Creem keeps its own records of your purchases under its own policy.
Emails (Resend)
We send emails only about your account and your use of the Service: confirming your email address, resetting your password, telling you your password was changed or that Google sign-in was connected to your account, confirming that your account was deleted, billing updates (for example that a plan started, a plan will end or a payment failed) and, unless you turn them off in Settings, that your designs are ready. When your credits are running low we tell you once per top-up. We send no marketing emails and no newsletters. Our emails contain no tracking pixels and no tracked links. A link that confirms your address works for 24 hours; a password-reset link works for 30 minutes; each works only once. Open a confirmation link in the browser where you're signed in to the account it was sent to: if you aren't signed in, we ask you to sign in first and then finish confirming (your browser holds the link in that tab meanwhile, see the Cookie Policy), and a link opened while you're signed in to a different account doesn't work.
Error reports (Sentry)
When something goes wrong in the Service, in your browser or on our servers, an error report is sent to Sentry: what failed and where in our code, the page or address it happened on (without search terms or secret codes), your browser and operating system, and the version of the Service. Before a report leaves your browser or our servers, we remove email addresses, passwords, keys, cookies, the contents of requests and the text of your prompts, and we don't attach your name or email address; at most a pseudonymous ID is attached. We have set Sentry not to store IP addresses. Sentry sets no cookies, stores nothing in your browser, and doesn't record your screen.
Analytics (PostHog), only with your consent
If, and only if, you choose "Accept analytics" in the cookie banner, your browser loads PostHog's analytics code and we record the analytics data listed in section 2. If you reject analytics, or your browser sends a Global Privacy Control or Do Not Track signal, PostHog is never loaded and our servers send no events about you. When you are signed in, analytics use a pseudonymous ID derived from your account, never your email address or name. We don't record your screen or capture what you type, and we have set PostHog not to store IP addresses. You can withdraw your consent at any time under "Cookie settings" (section 8): PostHog then stops and its data is removed from your browser.
Sign-in with Google
If you choose "Continue with Google", Google handles the sign-in under its own terms and privacy policy, as an independent controller, and tells us the details listed in section 2. We ask only for your basic profile and your email address. If an account with the same email address already exists, we link your Google account to it only when that address has been confirmed, and never to an account you're signed in to under a different email address. When we link Google to an existing account, we sign that account out on every other device and email you, so you can reset your password if it wasn't you. We never receive your Google password, and we don't access anything else in your Google account.
We may also disclose data:
- to the people a project owner shares a project with, and to the project owner, as described under "Shared projects and comments" below;
- to professional advisers (lawyers, accountants, auditors) under a duty of confidentiality;
- to authorities or courts when the law requires it, or to protect the rights, safety or property of our users, the public or us;
- to a buyer or successor if our business is sold or reorganised, who must keep protecting it under this policy.
We don't sell personal data, and we don't share it with advertisers or data brokers.
Shared projects and comments
A project owner can create a link that lets anyone who has it view a project, optionally protected by a password and with an expiry date. The owner can turn a link off at any time.
What a shared page shows. The project's title and platform and, depending on what the owner chose to share, its finished screens (image, name and purpose), the flow between them, a presentation and a clickable prototype, plus image downloads and comments if the owner allows them. It doesn't show the owner's name, email address or account details, or the project's prompts, plan, settings or other projects. If the owner replies to a comment, visitors of that link see the reply under the name on the owner's account (or "Project owner" if there is none). On the Free plan, the page shows a small "Made with DesAIgner" badge.
If you comment as a visitor:
- the project owner sees your name, your email address and your comment;
- other visitors of the same link see your name and your comment, but never your email address;
- people with a different link to the same project don't see it;
- we tell the project owner about new comments, for example by email. The notice may include your name and the start of your comment, never your email address;
- your comment is not sent to OpenAI, to Creem's content check or to any other AI service;
- your name and email address are remembered in your own browser, so you don't have to type them again (see the Cookie Policy).
Who decides. The project owner decides to share the project, whether to allow comments and what to do with them. We store and show comments so the owner can use this feature, and we use them, together with your IP address, to keep shared links secure and to prevent spam and abuse. Please ask the project owner first if you have a question about a comment you left; you can always contact us as well (section 8).
6. International transfers
We are based in Bosnia and Herzegovina, and some of our providers are in the United States (including Resend, which stores the emails it sends for us in the USA). So your data may be processed outside the country where you live, including outside the European Economic Area.
Where the law requires safeguards for such a transfer, we rely on:
- the European Commission's Standard Contractual Clauses, included in our providers' data processing agreements; and/or
- the EU-US Data Privacy Framework, for US providers that are certified under it;
- equivalent safeguards under the law of Bosnia and Herzegovina.
You can ask us for more information about these safeguards at faris@elevatesolutions.ba.
7. How long we keep it
| Data | How long |
|---|---|
| Account data, project content, uploaded files, brand kits, generated images | Until you delete them or your account. When you delete a project or your account in the Service, we delete this data immediately, and in any case within 30 days: deletion starts as soon as you confirm, a large account's files can take a few moments to disappear, an hourly check finishes any deletion that was interrupted, and a second clean-up pass removes anything a running generation wrote at the last moment |
| Accounts whose email address is never confirmed | Deleted with all their content 30 days after sign-up, unless the account has a purchase or credit history |
| Email confirmation and password-reset links | A confirmation link works for 24 hours, a reset link for 30 minutes. The stored hash of a link is deleted 7 days after it was used or expired, and at once when you delete your account |
| Usage records | 24 months, then deleted |
| Credit and billing records, purchase and invoice records | For as long as your account exists. After you delete your account, we keep them only in anonymised form: your email address, name and password are erased, and the records stay linked only to a random internal ID. We keep them for 10 years after the end of the financial year in which the account was deleted, as accounting and tax law requires, then delete them. Creem keeps its own records under its own policy |
| Free-credit record (fingerprint of your email address) | For as long as your account exists, and 12 months after it is deleted |
| Hosting request and error logs, and error reports (Sentry) | Up to 90 days |
| Analytics data (PostHog, only with your consent) | 12 months |
| Emails held by our email provider (Resend) | For the limited time set by Resend's retention for our plan (currently up to 30 days) |
| Backups | Deleted data may remain in encrypted backups for up to 30 days, until they are overwritten |
| Data held by OpenAI | Up to 30 days, according to OpenAI's API policy (section 4) |
| Fingerprints of text that passed the content check | Up to 30 days, and deleted with the project (section 4) |
| IP addresses used for rate limiting (sign-in, sign-up, password reset and email confirmation) | Kept in our database only while the limit is running, at most about one hour after your last attempt, then deleted automatically |
| Share links | Until the owner deletes the link, the project or their account. A link that is turned off or has expired stops working at once, and stays in the owner's list until they delete it |
| Comments, including a visitor's name, email address and comment text | Until the project owner deletes the comment, the screen, the project or their account. Turning a link or its comments off, or deleting a link, doesn't delete the comments: the owner still sees them |
| Proof that a visitor entered a share link's password (a cookie in the visitor's browser) | 12 hours. It stops working sooner if the owner changes or removes the password or turns the link off |
| IP addresses used for rate limiting on shared projects (viewing images, entering a password, commenting, downloading) | Kept in our database only while the limit is running, at most about one hour after your last request, then deleted automatically |
| Your cookie choice | In your browser, for 6 months; then we ask again (see the Cookie Policy) |
| Messages with us | Up to 2 years after the conversation ends |
If we close an inactive account (see the Terms of Service), we delete its data on the same schedule.
8. Your rights
Under the GDPR and the law of Bosnia and Herzegovina, you have the right to:
- access your personal data and get a copy of it;
- correct data that is wrong or incomplete;
- delete your data ("right to be forgotten");
- restrict how we use it in certain cases;
- data portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another service;
- object to processing based on our legitimate interests;
- withdraw consent at any time, where we rely on consent;
- complain to a data protection authority: the Personal Data Protection Agency of Bosnia and Herzegovina, or the authority in the EU country where you live or work, or where you think the problem happened. We would appreciate the chance to help first.
What you can do yourself in the Service:
- Delete a project, from the dashboard or inside the project. Its screens, images, versions and code exports are deleted, and any generation still running for it stops (the credits for a step our AI provider was already working on are charged, see the Terms of Service).
- Delete your account, in Settings. For your protection we ask you to type your email address and to confirm your password; if your account has no password (you sign in with Google), we may ask you to sign in with Google again first. You are signed out everywhere at once, and your projects, images, uploads and brand kits are deleted straight away (on a large account the last files can take a few moments to disappear). An active subscription is cancelled straight away and the credits left on the account are lost (see the Terms of Service and the Refund Policy). We send a confirmation to your email address. What we keep afterwards, in anonymised form, and for how long, is in section 7.
- Change your password, or set one if you signed up with Google, and reset a forgotten password from the sign-in page.
- Turn off emails that tell you your designs are ready, in Settings.
- Change your cookie choice, including withdrawing your consent to analytics, under "Cookie settings" at the bottom of our website or in your account menu.
- Download each project as a ZIP (its brief, design system, flows, images and exported code), and sign out of all devices.
For everything else, including getting a copy of all your data, email faris@elevatesolutions.ba from the email address on your account. We may ask you to confirm your identity. We reply within one month; if a request is complex, we may extend that by up to two more months and will tell you why. Using your rights is free, unless a request is clearly unfounded or excessive.
If you commented on a shared project. A comment isn't tied to an account, so the quickest way to have one removed is to ask the person who shared the link with you: the project owner can delete it. You can also email faris@elevatesolutions.ba from the email address you entered with the comment, and tell us the link or project and roughly when you commented. We will help you use your rights, and, where the request concerns how the owner uses your comment, we may pass it on to the project owner.
9. How we protect your data
We use technical and organisational measures appropriate to the risk, including:
- passwords stored only as salted, memory-hard hashes (scrypt), never in readable form;
- email confirmation and password-reset links that work only once, expire quickly and are stored only as one-way hashes; resetting your password signs you out on every device;
- encrypted connections (HTTPS) for everything you send and receive;
- sign-in cookies that scripts on the page can't read, and protection against cross-site request forgery;
- access checks on every request, so your projects and images are available only to your account, and to the people you share a link with;
- rate limits on sign-in, sign-up, password reset, email confirmation and generation;
- error reports cleaned of personal data before they leave your browser or our servers;
- secret keys kept on the server only, and access to production data limited to the staff who need it.
No system is perfectly secure. If a personal data breach puts your rights at risk, we will tell the authority and you, as the law requires.
10. Children
The Service is for adults. You must be at least 18 to create an account (see the Terms of Service). We don't knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy when the Service, our providers or the law change. The date at the top shows when it last changed. If a change is significant, we will tell you by email or with a notice in the Service before it takes effect.
12. Contact
For anything about your personal data, email faris@elevatesolutions.ba, or write to Elevate Solutions, vl. Faris Rizvanović, Vilsonovo šetalište 9, 71000 Sarajevo, Bosnia and Herzegovina. You can also contact our data protection officer at [DPO CONTACT].