Legal

Privacy policy

What we collect when your coding agent uses TheDesignAgent, and what we do with it.

TheDesignAgent is run by BornTall, LLC, a Pennsylvania company ("we", "us"). This policy explains what we collect when you use the website at thedesignagent.ai, the hosted MCP server, the @thedesignagent/mcp npm package, the thedesignagent CLI and the TheDesignAgent plugins (together, "the service"), and what we do with it. Questions go to thedesignagent@borntall.com.

The short version

What we collect

Account information

What your coding agent sends

When your agent calls Discover, Ux or Visual, it sends a description of the task, the code or UI being reviewed, optional surrounding code, a project model (a summary of your app's structure, data types and design tokens that the agent extracts from your repository), and for Visual a page URL or screenshot.

We store:

We don't keep the full request or response of MCP calls. Our call logs hold sizes and one-way hashes of the task and code, not the text.

Screenshots

Usage and device information

Payment information

Payments are processed by Stripe. We never see or store your full card number. We keep your Stripe customer ID, the card brand and last four digits (so auto-recharge can tell you which card it will charge), and records of what you bought and paid. When an agent buys credits over the Machine Payments Protocol, the payment is handled by Stripe or, if used, a stablecoin deposit address, and we keep the same purchase records.

Cookies and browser storage

We don't use advertising cookies or sell data to advertisers.

How we use it

AI processing

Reviews are produced by Anthropic's Claude models. To find relevant guidance we also send the task description and the first 2,000 characters of the code under review to OpenAI to create search embeddings. Both process this data under their commercial API terms. We don't use your content to train AI models, and we don't share your project context with other customers.

If you run the local server with your own Anthropic API key, its fallback reviews go directly from your machine to Anthropic under your account.

Who we share it with

We share data only with the service providers that run TheDesignAgent for us:

We may also disclose information if the law requires it, to protect the service or its users, or as part of a merger or sale of the business, in which case this policy continues to apply. We don't sell personal information.

How long we keep it

We keep account, project and usage data while your account is active, so your project context keeps improving. Payment records are kept as long as tax and accounting rules require. When you ask us to delete your account, we delete or anonymize your data within 30 days, apart from records we must keep by law.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete or port your personal information, or to object to some processing. We honor those requests by email, and we won't treat you differently for making one.

Security

Keys are stored as hashes, IP addresses and user agents as hashes, traffic is encrypted in transit, and access to production data is limited. No system is perfectly secure; if we learn of a breach that affects you, we'll tell you.

Children

The service is for developers and businesses and isn't directed at anyone under 16. We don't knowingly collect data from children.

Where data is processed

We and our providers process data in the United States and other countries where they operate.

Changes

We'll update this page when our practices change and change the effective date above. If a change is significant, we'll tell signed-in users by email or in the dashboard.

Contact

BornTall, LLC · Pennsylvania, USA · thedesignagent@borntall.com