Legal
Privacy
Platform is a design token workspace. This page explains what we store, why, and who else ever sees it. Last updated 21 August 2026.
What we store
- Your account. Your name and email address. If you sign up with a password, we store only a bcrypt hash of it; we cannot read your password. If you sign in with Google, we store the account identifier Google gives us, plus the name and email address on that Google account.
- Your design systems. Project names, descriptions and token documents, whatever you put in them.
- Sharing. The email addresses you invite to a project.
- Operational logs. Ordinary server logs used to keep the service running and diagnose faults.
What other people can see
Your projects are private by default. Two things change that, and both are your choice:
- Sharing a project with a teammate's email lets that person open and edit it.
- Publishing a project lists it on Explore, where its name, description and tokens can be read and copied by anyone, no account needed. Your display name is shown as the author. Your email address is never published. You can unpublish at any time, which removes it from Explore immediately.
Who else your data reaches
- Google, only if you choose Google sign-in, and only to verify who you are.
- OpenAI, for two things. If you use the AI agent, your message and the current project's token document are sent to OpenAI to generate a reply; if you never open the agent, nothing is sent. Separately, a new image, an avatar, a project cover, or an image a token points at, is sent to OpenAI to be checked automatically for explicit content before it is stored (see the image rules). Only the image itself goes: not your name, not your email address, not which project it belongs to. An image already saved is never re-sent.
- Plausible, page-view counts only. We use it to see which pages are visited. It does not use cookies and does not collect personal data. See Plausible's data policy.
- Our hosting and database providers, which store the data on our behalf.
We do not sell your data, and we do not share it with anyone else.
Cookies and tracking
There are no advertising cookies and no third-party advertising trackers on this site.
We use Plausible for privacy-friendly analytics. It runs without cookies and without collecting personal data. It records that a page was viewed (the URL, the referring site, the browser, and a coarse location) so we can tell what is useful. It does not identify you and it does not follow you across other sites.
We set exactly one cookie, and only if you use Google sign-in: a short-lived token that protects the sign-in from being forged by another site. It lasts ten minutes and is deleted as soon as sign-in finishes.
When you are signed in, your browser stores an access token in
localStorage so you stay signed in between pages. It expires after
72 hours. Signing out removes it.
Keeping and deleting your data
We keep your account and projects for as long as your account exists. You can delete any project yourself at any time, which removes it and its tokens for everyone it was shared with.
You can delete your whole account from Settings → Delete account. It is not a deactivation and there is no waiting period: the account row itself is deleted, and everything attached to it goes with it in the same transaction: your projects and their tokens, your uploaded images, your project settings, the invitations you sent, the invitations other people sent to your address, your pins, likes and comments, your Google sign-in link, and any outstanding confirmation or password-reset links. We keep no shadow copy and no "deleted" flag, so we cannot restore an account after you delete it, not for you, and not for anyone who asks us to.
Three honest exceptions, none of which contains your design work:
- Server logs. Ordinary operational logs record that requests happened, and some lines name the email address that made them. They age out on their own and are never used to rebuild an account.
- Feedback you send us. A note from Send feedback is correspondence we received, kept so we can act on it. It is not used to rebuild an account, and it is not your design work. If you delete your account, the note stays with the name and address that were on it when you sent it.
- Our database provider's backups. Our host may hold routine encrypted snapshots for a short period for disaster recovery. Your data is gone from the live database immediately; a snapshot taken before you deleted expires on its own schedule, and we do not restore from one to retrieve deleted accounts.
Some things are never stored in the first place, so there is nothing to delete: we do not keep what you type to the AI agent or what it replies, and an image sent for the automated check described above is not kept by us beyond the copy you uploaded.
Security
Passwords are hashed with bcrypt and never stored in readable form. Traffic is served over HTTPS, and access tokens expire. No system is perfectly secure, so please use a strong, unique password.
Children
Platform is not intended for children under 13, and we do not knowingly collect their information.
Changes
If this policy changes in a way that materially affects you, we will update the date at the top of this page and, where the change is significant, tell you directly.
Contact
Questions about privacy, or a request to delete your data: platformds@pm.me.