Privacy Policy

Last updated: July 27, 2026

This Privacy Policy describes how Exemplo ("we", "us", or "our") collects, uses, and handles information when you use our website and services (the "Service"). Exemplo is operated from Oregon, United States, and the Service is intended for users in the United States.

In short: we do not sell your personal information, and we do not share it with third parties for their own marketing or advertising purposes. We collect only what we need to operate the Service.

1. Information We Collect

  • Account information. Your email address, and if you sign in with Google, GitHub, or Microsoft, the account identifier and profile image URL that provider returns to us. If you sign in with an emailed code, we store that code's hash until it expires. We never receive your password for those providers.
  • Project and submitted content. Brand names, descriptions, website URLs, style selections, prompts, and other inputs you provide, together with the outputs we generate from them (design systems, starter kits, logos) and their version history.
  • Website scan data. When you ask us to analyze a website, we load that site in an automated browser and store what we extract from it (a screenshot, colors, fonts, and logo images) so we can build your design system. Please only scan sites you own or are authorized to analyze.
  • Billing information. If you purchase credits, our payment processor (Stripe) handles your card details directly. We never receive or store full card numbers. We store your Stripe customer and subscription identifiers, your credit balance, and a ledger of credit purchases and usage.
  • Usage and device data. IP address, browser and device type, pages visited, and in-product events (such as which wizard steps you complete), used to operate, secure, and improve the Service.
  • Waitlist information. If you join our beta waitlist, we store your email address and when you joined and were notified.
  • Support communications. Messages you send us and our replies.

2. Cookies and Analytics

We use two kinds of cookies and similar technologies:

  • Essential cookies required for authentication, session management, and security. The Service will not work without these.
  • Analytics. We use Google Analytics to understand how the Service is used, for example which steps people complete or abandon. This involves cookies and similar identifiers, and sends usage events (including your IP address and a randomly generated client identifier) to Google. We use this only to measure and improve our own Service; we do not use it to build advertising profiles or to serve you ads.

You can block or delete cookies in your browser settings, install Google's Analytics opt-out add-on, or enable your browser's Global Privacy Control (GPC) signal, which we honor as an opt-out of sharing where applicable. Blocking essential cookies will prevent you from signing in.

3. How We Use Information

  • To provide, maintain, and improve the Service, including generating design systems, starter kits, and logos from your inputs.
  • To authenticate users and secure accounts.
  • To process payments and administer credit balances.
  • To respond to support requests and communicate with you about the Service.
  • To detect, prevent, and address abuse, fraud, or technical issues, including rate limiting.
  • To comply with legal obligations.

We do not use your project content or submitted inputs to train our own machine-learning models.

4. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:

  • With service providers who process data on our behalf to operate the Service (listed in Section 5).
  • When required by law, legal process, or to protect the rights, safety, or property of Exemplo or others.
  • In connection with a merger, acquisition, or sale of assets, in which case any successor will be bound by this Privacy Policy.
  • With your direction or consent.

5. Service Providers

These providers process data on our behalf. All are located in the United States or process data in the United States.

  • Vercel. Website hosting and delivery.
  • Google Cloud Platform. Application hosting, database, and secret storage.
  • Cloudflare R2. Storage for generated images, logos, and website screenshots.
  • Stripe. Payment processing.
  • Mailtrap. Transactional email delivery (sign-in codes, notifications).
  • Upstash. Rate limiting and abuse prevention.
  • Google Analytics. Product usage analytics.
  • AI providers. Anthropic, OpenAI, Google (Gemini), xAI, DeepSeek, Recraft, and Ideogram, which process the prompts and inputs needed to generate your outputs. We use their business or API offerings, under which they do not train their models on our API data.
  • Sign-in providers. Google, GitHub, and Microsoft, if you choose to sign in with them.

This list may change as we improve the Service; we will update it here when it does.

6. Data Retention

  • Account and project data. Kept while your account is active. You can delete your account yourself at any time from your account settings, which immediately removes your account, projects, generated outputs, and credit history (backups roll off within 90 days).
  • Billing records. Kept for at least 7 years where required by tax and accounting rules, even after account deletion.
  • Website scan data. Screenshots and extracted style data are kept while your project exists so you can regenerate outputs from them.
  • Generated images. Logo files we generate are stored in our image storage and removed by a periodic cleanup process that runs after the project or account they belong to is deleted, rather than at the instant of deletion.
  • Usage and analytics data. Retained in aggregated or pseudonymous form; Google Analytics data follows our configured retention window.
  • Waitlist emails. Kept until you ask us to remove them or the beta program ends.

7. Security

We use reasonable administrative, technical, and physical safeguards to protect information, including encryption in transit, encrypted secret storage, and access controls. No method of transmission or storage is, however, completely secure, and we cannot guarantee absolute security.

8. Your Rights and Choices

You can delete your account and its data at any time from your account settings. You may also request access to, correction of, or a copy of your personal information, and you may opt out of the analytics described in Section 2. We will not discriminate against you for exercising these rights.

California residents. Under the CCPA/CPRA you have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to opt out of the sale or sharing of personal information. As stated above, we do not sell or share personal information for cross-context behavioral advertising. We honor Global Privacy Control signals. You may also designate an authorized agent to make a request on your behalf.

Other state privacy laws. Residents of Oregon, Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws have similar rights, including the right to appeal a denied request. If we deny your request, you may appeal by replying to our response; if we deny your appeal, you may contact your state attorney general.

To exercise any of these rights, email support@exemplo.io from the address associated with your account. We will verify your request and respond within the time required by applicable law (generally 45 days).

9. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and where appropriate we will notify you in the Service or by email.

11. Contact

For questions about this Privacy Policy or our data practices, contact us at support@exemplo.io.