Privacy policy
What we collect when your coding agent uses TheDesignAgent, and what we do with it.
TheDesignAgent is run by BornTall, LLC, a Pennsylvania company ("we", "us"). This policy explains what we collect when you use the website at thedesignagent.ai, the hosted MCP server, the @thedesignagent/mcp npm package, the thedesignagent CLI and the TheDesignAgent plugins (together, "the service"), and what we do with it. Questions go to thedesignagent@borntall.com.
The short version
- We collect what we need to brief and review the UI your coding agent builds, to bill for it, and to keep the service working.
- Code and screenshots your agent sends are processed by AI models (Anthropic, and OpenAI for search embeddings) under their API terms. We don't sell your data, and we don't train models on it.
- We store a model of each project so later reviews improve. We don't keep the raw body of each MCP request.
- You can ask us to export or delete your data at any time.
What we collect
Account information
- Email address. You sign in with a one-time email link, so we keep the address you sign in with.
- How you found us. On your first visit we note the referring site, any campaign tags (UTM), the landing page and the time, and attach them to your account when you sign up.
- API keys. We store only a one-way hash of each key and its first few characters, never the key itself. We also keep the names you give keys and projects.
What your coding agent sends
When your agent calls Discover, Ux or Visual, it sends a description of the task, the code or UI being reviewed, optional surrounding code, a project model (a summary of your app's structure, data types and design tokens that the agent extracts from your repository), and for Visual a page URL or screenshot.
We store:
- the project model, plus the jobs, personas and design decisions we infer from it, so later briefs and reviews start from your context;
- review results: scores, findings, recommendations and summaries;
- usage records for each call: the tool, time, cost in credits, model used, scores, and the client and channel that made the call.
We don't keep the full request or response of MCP calls. Our call logs hold sizes and one-way hashes of the task and code, not the text.
Screenshots
- Hosted Visual opens the public or preview URL you give it in a headless browser, takes a screenshot in memory and sends it for review. We don't save the image.
- The local MCP server takes screenshots on your own machine and keeps them in
~/.thedesignagent/screenshotsfor 24 hours. If you save a login session for a page behind sign-in, it stays on your machine in~/.thedesignagent/auth. Your API key can be stored locally in~/.thedesignagent/credentials. None of these local files are sent to us apart from the screenshot being reviewed.
Usage and device information
- The name and version of the MCP client or tool making a call, and how it was installed (hosted, npm, plugin, CLI or CI).
- Your IP address and browser or agent user agent, which we store only as one-way hashes, and your country as reported by our hosting provider.
- Product events such as signing up, creating or revoking a key, buying credits and turning auto-recharge on or off.
- Website analytics: page views measured by Vercel Web Analytics, and a note when a visit came from an AI assistant such as ChatGPT or Perplexity.
- A log of automated crawlers and agents fetching our pages (the page, the crawler's name and user agent, and country; no IP address).
Payment information
Payments are processed by Stripe. We never see or store your full card number. We keep your Stripe customer ID, the card brand and last four digits (so auto-recharge can tell you which card it will charge), and records of what you bought and paid. When an agent buys credits over the Machine Payments Protocol, the payment is handled by Stripe or, if used, a stablecoin deposit address, and we keep the same purchase records.
Cookies and browser storage
- Sign-in cookies: set by our authentication provider to keep you signed in to the dashboard.
tda_ft: remembers how you first found us, for up to 180 days.tda-theme(local storage): remembers your light or dark preference.tda-ai-referral(session storage): notes that this visit came from an AI assistant.
We don't use advertising cookies or sell data to advertisers.
How we use it
- To run the service: write briefs, review UI, remember your project, and show your usage in the dashboard.
- To bill you: track credits, process purchases and auto-recharge, and handle refunds and disputes.
- To keep it safe: authenticate keys, enforce rate limits and prevent abuse.
- To improve it: understand which features, clients and channels people use, and how they found us.
- To talk to you: sign-in emails, receipts and replies to support requests.
AI processing
Reviews are produced by Anthropic's Claude models. To find relevant guidance we also send the task description and the first 2,000 characters of the code under review to OpenAI to create search embeddings. Both process this data under their commercial API terms. We don't use your content to train AI models, and we don't share your project context with other customers.
If you run the local server with your own Anthropic API key, its fallback reviews go directly from your machine to Anthropic under your account.
Who we share it with
We share data only with the service providers that run TheDesignAgent for us:
- Supabase: database, authentication and backend functions
- Vercel: website and API hosting, and web analytics
- Anthropic: AI reviews
- OpenAI: search embeddings
- Stripe: payments
We may also disclose information if the law requires it, to protect the service or its users, or as part of a merger or sale of the business, in which case this policy continues to apply. We don't sell personal information.
How long we keep it
We keep account, project and usage data while your account is active, so your project context keeps improving. Payment records are kept as long as tax and accounting rules require. When you ask us to delete your account, we delete or anonymize your data within 30 days, apart from records we must keep by law.
Your choices and rights
- Export or delete: email thedesignagent@borntall.com from your account's address and we'll send a copy of your data or delete it.
- Keys: revoke API keys at any time in the dashboard.
- Local data: delete
~/.thedesignagenton your machine to remove local screenshots, saved sessions and stored keys. - Cookies: clear them in your browser; the service still works without the attribution cookie.
Depending on where you live, you may have rights to access, correct, delete or port your personal information, or to object to some processing. We honor those requests by email, and we won't treat you differently for making one.
Security
Keys are stored as hashes, IP addresses and user agents as hashes, traffic is encrypted in transit, and access to production data is limited. No system is perfectly secure; if we learn of a breach that affects you, we'll tell you.
Children
The service is for developers and businesses and isn't directed at anyone under 16. We don't knowingly collect data from children.
Where data is processed
We and our providers process data in the United States and other countries where they operate.
Changes
We'll update this page when our practices change and change the effective date above. If a change is significant, we'll tell signed-in users by email or in the dashboard.
Contact
BornTall, LLC · Pennsylvania, USA · thedesignagent@borntall.com