Back to home

Privacy Policy

Last updated May 25, 2026

This Privacy Policy explains what we collect, why, and what you can do about it. We try to keep things minimal: we only collect data we actually need to run the Service.

1. Who we are

Uisdom ("we", "us") operates Uisdom.design from Mühlenstrasse 20, 13187 Berlin, Germany. We are the data controller for the personal data described here. Contact: uisdomcontact@gmail.com.

2. What we collect

Account: email address and authentication credentials (handled by Supabase). If you sign in with Google, we receive the email associated with that Google account.

Usage: sessions you create, the source URLs you submit, chat messages with the AI, generated workspace files, leads captured from your published sites, and basic logs (timestamps, IP, user agent) for security and abuse prevention.

Billing: if you subscribe to a paid plan, our payment processor stores the data needed to process payments. We never see or store your full card details.

3. Why we use it

To run the Service: authenticate you, create and edit your projects, host your published sites, send transactional emails (e.g. clone-ready, password reset).

To improve the Service: aggregate analytics and debugging.

To comply with the law: respond to lawful requests, prevent fraud and abuse.

4. Third parties we share data with

We use a small number of trusted providers to operate the Service: Anthropic (AI models that generate your sites), Supabase (authentication, database, and file storage), E2B (sandbox runtime that executes the generated code), Vercel (web hosting), Stripe (payment processing for paid plans), Microsoft Clarity and Meta Pixel (analytics and audience measurement — only loaded after you accept analytics in our cookie banner), and SMTP providers (transactional emails). They only process data on our instructions.

We don't sell your personal data.

5. Where we store it

Application code and traffic are served by Vercel from Frankfurt, Germany (eu-central-1 / fra1) and Washington D.C., USA (us-east-1 / iad1). Authentication, the database, and file storage run on Supabase. Processing therefore happens in the European Union and the United States. Where transfers to the U.S. are involved we rely on standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework.

6. How long we keep it

Account and project data: as long as your account is active, plus a short retention period after deletion for backups and legal obligations.

Logs: typically up to 90 days.

Leads captured by your published sites are stored on your behalf and you control retention.

7. Your rights (GDPR / similar laws)

You can request access to, correction or deletion of your personal data, object to processing, request portability, or withdraw consent. Email hello@uisdom.design and we'll respond within a reasonable time.

You can also lodge a complaint with your local data protection authority.

8. Cookies

We use essential cookies for authentication, language preference, and remembering your cookie-banner choice. Analytics and marketing tools (Microsoft Clarity for product analytics and session insights, Meta Pixel for audience measurement) are only loaded after you click "Accept" in our cookie banner. You can withdraw consent at any time by clearing your choice in the banner; the loaders react immediately and stop firing.

9. Children

The Service is not intended for children under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.

10. Changes to this Policy

We may update this Policy. If we make material changes we'll notify you by email or in the Service. The "Last updated" date at the top tells you when this version took effect.