Legal document

Published

Privacy Policy

Effective date: August 8, 2026 This Privacy Policy explains how Design Labs Inc., a Delaware corporation (“Design Labs,” “Chic,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you visit chic.dev or use the Chic design service (the “Service”). It also explains choices and rights that may apply to you. 1. Scope and roles This Policy applies to Chic’s website, accounts, Studio, Projects, support, and payment journeys. It does not govern a third-party website or service you access from Chic or use after export. For account, product, security, and billing data, Design Labs generally acts as the business or controller. When you submit information about another person, you are responsible for having the rights, notices, and lawful basis needed to provide it. Standard Chic plans do not include a data-processing addendum or regulated-data commitment. 2. Information we collect Account and identity information. We receive identifiers and profile information used to create and secure your account, such as name, email address, authentication identifiers, session status, and organization membership. Authentication is provided through a specialist identity provider. Project and Customer Content. We process prompts, product descriptions, URLs, screenshots, images, videos, logos, brand materials, reference files, chat messages, selected sections, design directions, generated output, source exports, and related Project history. Payment and entitlement information. We receive plan, price, checkout status, subscription status, Project entitlement, transaction identifiers, invoices, billing country, and limited payment metadata from our billing and payment providers. Hosted payment providers process payment-card details; Chic is not intended to receive or store complete card numbers or card security codes. Usage and technical information. We collect device and browser type, IP address, timestamps, requested pages, referring information, cookie or session identifiers, feature interactions, error and security logs, generation status, usage quantity, and performance telemetry. Model-usage and cost records are kept for operations and billing but are not shown as provider internals to other customers. Communications. We collect information you send in support, legal, privacy, billing, survey, or feedback communications. We receive information directly from you, automatically from your browser and use of the Service, and from providers involved in authentication, payments, infrastructure, AI processing, and connected services. 3. How we use information We use personal information to provide, personalize, maintain, and support the Service; authenticate users and keep accounts secure; create and restore Projects; generate, refine, preview, and export designs; process payments and entitlements; communicate about transactions, security, support, and product changes; detect, investigate, and prevent fraud, abuse, and technical incidents; monitor reliability and enforce limits; comply with legal, accounting, tax, sanctions, and recordkeeping obligations; protect the rights and safety of users, Design Labs, and third parties; and analyze and improve the Service. Where applicable law requires a legal basis, we rely on performance of our contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where we specifically request it. You may withdraw consent for future processing, but withdrawal does not affect earlier lawful processing or processing based on another legal ground. We may create aggregated or de-identified information that cannot reasonably identify you and use it for lawful product, security, research, and business purposes. We do not attempt to re-identify data treated as de-identified unless permitted by law to test our de-identification controls. 4. AI and automated processing Chic transmits the inputs needed for a generation or refinement—including prompts and uploaded media—to AI model and infrastructure providers. The provider and model may vary based on service configuration, availability, quality, and the requested operation. Current provider categories include model gateways and model developers such as OpenRouter, OpenAI, Google, Anthropic, and their routed inference providers. We use paid or business API offerings where configured and select provider and account settings intended for business processing when available. Each provider's retention, abuse monitoring, training or product-improvement use, subprocessors, regions, and independent uses remain governed by its applicable terms, policies, and account configuration. We do not promise zero-data retention or no training across every route. Do not submit regulated, highly sensitive, or confidential information that you cannot permit these providers to process under those conditions. AI-assisted output does not make decisions that produce legal or similarly significant effects about you. It may be inaccurate or contain unexpected material and requires human review. 5. How we disclose information We disclose information only as reasonably necessary for the purposes in this Policy: Service providers. Providers support authentication, cloud hosting, networking, databases, object storage, email, billing, hosted checkout, fraud prevention, AI generation, web search, build execution, monitoring, and support. Current core providers include Clerk for authentication; Autumn and Stripe for billing and payment; AWS, Vercel, and Neon for infrastructure and data services; OpenRouter, OpenAI, Google, Anthropic, and routed model hosts for AI; and E2B and retrieval providers for isolated build or search functions. Providers may change as the Service evolves. Your directions. We disclose content when you publish, share, export, connect, or otherwise direct us to do so. Legal and safety. We may disclose information if we reasonably believe it is required by law, legal process, or a valid government request; necessary to protect rights, safety, security, or property; or appropriate to investigate fraud, abuse, or violations. Business transfers. Information may be disclosed in a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality and legal requirements. Professional advisers. We may disclose limited information to lawyers, accountants, auditors, insurers, and other advisers under duties of confidentiality. We do not sell personal information for money. We do not currently share personal information for cross-context behavioral advertising or use sensitive personal information to infer characteristics. If those practices change, we will provide the notices and choices required by law. 6. Projects, exports, and sharing Projects are owner-bound. Free Preview Projects are currently unlisted and do not include an anonymous public share link. Paid Projects are private by default. A Project or export may become accessible to others when you intentionally export, publish, deploy, send, or connect it to another service. Copies made by recipients or external services are outside our control. Removing content from Chic may not remove copies already exported, cached, indexed, or retained by others. 7. Cookies and similar technology Chic and its providers use cookies, local storage, and similar technology needed for authentication, security, preferences, checkout continuity, fraud prevention, and core product operation. We may also use limited measurement technology to understand reliability and feature use. We do not currently use Chic data for third-party targeted advertising. Browser controls may block some technology, but essential functions may then stop working. 8. Retention We retain account and Project information while your account is active and as reasonably needed to provide history, refinement, export, support, security, and the entitlements you purchased. We retain transaction, acceptance, tax, accounting, fraud, audit, and legal records for the periods required or reasonably necessary for those purposes. Raw provider records and operational evidence may be retained to establish exact output, cost, safety, and incident history. When information is deleted from active systems, limited copies may remain temporarily in backups, immutable security or transaction records, provider systems, and legally required archives. Retention depends on data type, sensitivity, contractual commitments, legal requirements, dispute risk, and technical necessity. We may retain aggregated or de-identified information without a time limit where lawful. 9. Security We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, owner-bound records, transport encryption, access controls, and restricted artifact publication. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur. You are responsible for account security and for safely handling exported files. 10. International transfers Design Labs and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we and our providers use recognized transfer mechanisms or other lawful safeguards. By using the Service, you understand that information may be processed outside your country. 11. Your choices and privacy rights You may update certain account information through the Service, cancel a subscription through the billing portal, and control what Project content you submit or export. You may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent by emailing privacy@chic.dev. Depending on your location, some rights may not apply or may be subject to exceptions. Residents of jurisdictions with applicable U.S. state privacy laws may also request the categories or specific pieces of personal information we hold, correction or deletion, and information about disclosures; opt out of sale, targeted advertising, or qualifying sharing; limit certain uses of sensitive information; and appeal a denied request. Chic does not currently engage in sale or targeted-advertising sharing, so no opt-out link is presently required. We will not discriminate against you for exercising a privacy right. We may verify your identity before completing a request and may ask an authorized agent for proof of authority. We will respond within the period required by applicable law. If we deny a request, you may appeal by replying to the decision with “Privacy Appeal” in the subject line. You may also complain to your local data-protection authority. 12. Children The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child provided information, contact privacy@chic.dev so we can investigate and delete it where required. 13. Third-party links and exports The Service may contain links to or exports for third-party products. Their privacy practices are governed by their own notices, not this Policy. Review those notices before providing information or deploying an exported design. 14. Changes to this Policy We may update this Policy as the Service, providers, or law changes. We will post the new effective date here and provide additional notice when required by law. Your continued use after the effective date means the updated Policy applies to future processing, subject to non-waivable rights. 15. Contact Design Labs Inc. is the operator of Chic. Privacy questions and requests may be sent to privacy@chic.dev. Legal notices may be sent to legal@chic.dev, and product or billing questions to support@chic.dev.