Legal

Privacy policy

What happens to your data on this website, in the Editor, on a self-hosted Viewer, and on the public demo. In plain terms.

Last updated September 16, 2026.

Desde is two separate apps, plus one demo instance we run so people can try it. What happens to your data is different in each case, so this page covers all three, plus this website itself.

The short version#

Where Who holds the data
This website (desde.design) Almost nobody. Static pages, no accounts, and a page-view count that sets no cookies. If you sign up for release news, we keep your email address.
The Editor, on your own machine You do. It runs locally and only talks to services you set up yourself.
A Viewer someone self-hosts Whoever runs it. Their server, their database, their decision.
The demo at demo.desde.design We do. This and the email list above are the only places where "we" hold anything.

The rest of this page explains each row.

This website#

This site is a static export. Every page is a file, built ahead of time. There is no application server behind it deciding what to send you, and none of your reading is written to a database of ours.

One thing here does count visits. It is Vercel Web Analytics, and it tells us which pages people actually read. It is the only measurement on the site, and it is the plainest kind available.

It sets no cookies. It keeps no identifier for you, so nobody can follow one person from page to page, or know you from an earlier visit. What it records is the page you opened, the link that sent you there, and coarse facts like your country and whether you were on a phone. It is not Google Analytics. Nothing it collects is sold, shared, or used to target ads.

If you would rather not be counted, any content blocker stops it, and no part of the site breaks when it is blocked.

Fonts are bundled into the site at build time instead of loaded from a font provider, so your browser never makes a request to one just to render a page. The only thing the site saves in your own browser is whether you prefer light or dark mode.

The site is hosted on Vercel. Like any host, Vercel keeps basic server logs to run the infrastructure (the kind of thing every web host keeps). We have not added anything on top of that.

If you sign up for release news#

The footer has a form for release news by email. It is the only place on the site that asks for anything about you.

If you sign up, your email address goes to Loops, the service that keeps our mailing list and sends those emails. Nothing else from the form is sent. Your browser sends the form straight to Loops, so Loops also sees the IP address the request came from, as any website you contact does.

We use the list only to email you about Desde. We don't sell it or share it with anyone else. Every email has an unsubscribe link. To have your address deleted from the list entirely, email hello@desde.design.

The Editor, on your own machine#

The Editor is an app you run on your own computer, against your own copy of a code repository. It edits files on your disk. Nothing about that needs a network connection, and nothing about it is sent anywhere by default.

A few things do leave your machine, but only because you asked for them, and only to the service you pointed at:

  • An AI provider, when you use chat or AI-assisted editing. That is Anthropic or OpenAI, whichever you set up. It is your own API key, and the request carries the parts of your prototype relevant to the edit you asked for.
  • GitHub, if you connect a repository. The Editor does not hold or ask for your GitHub password or token. It uses the git and gh setup already on your machine, the same as if you typed the commands yourself.
  • Figma, only if you set up a Figma connection yourself. This is off by default. Nothing talks to Figma unless you add that configuration.

The desktop app downloads one thing automatically: the claude command line runtime, fetched from the public npm registry, and only when you might use an Anthropic model. If you have set up another provider and no Anthropic key, it is not downloaded at all. Either way that is a download, not an upload. It does not send anything about you or your project.

A few places in the code use the word "telemetry." All of it, as of this writing, means a message printed to your own browser console or held in a local variable for debugging. None of it is sent to us or to anyone else. There is no analytics package anywhere in the Editor's dependencies.

A Viewer someone self-hosts#

The Viewer is different: it's a web app meant to be run by a team, for that team, on a server they control. If you're using a Viewer someone invited you to, that person or their organization is the one holding your data, not us. We never see it. We don't have a copy of it. Questions about it go to whoever set that Viewer up, not to hello@desde.design.

For accuracy, here's what a Viewer's database actually holds, so an operator (or someone asking one) knows what to expect. Everything lives in one SQLite file on that operator's own server:

  • Accounts: email, display name, avatar image, and which sign-in provider (usually GitHub) created the account.
  • Sessions: a record tied to an account, used to keep you signed in.
  • Machine tokens: only a one-way hash of the token is stored. The actual token is shown once, at creation, and never saved anywhere in readable form.
  • Comments: the text, who wrote it, and which part of the page it's attached to.
  • The participant directory: the name and email of anyone who has commented on or been invited to a project, so they can be @-mentioned.
  • A notification record: which comment triggered an email and to whom, so a mention email isn't sent twice.

None of this reaches us. It's the operator's server, the operator's disk, the operator's responsibility.

The demo we run, at demo.desde.design#

This is the one place where "we" is the right word. The demo is a live Viewer we run so people can try the product before setting one up themselves. It has no GitHub connection configured, on purpose, so you cannot connect your own repository there. The only thing on it is one sample prototype we built. Anonymous comments are turned on, so you can leave feedback without creating an account.

What gets collected when you leave a comment#

  • A name. You type this in once; it's required to post a comment.
  • An email, if you choose to give one. It's optional.
  • The comment itself, and which element on the page it's attached to.

Before you post anything, that name and email sit in your own browser's local storage, not on our server. They're only sent to us the moment you submit a comment.

Because this is anonymous commenting, you're not signed in, and no account is created. No session cookie is set for you either. It's set only when someone actually signs in, which anonymous demo visitors never do.

Who can see it#

Anyone with the demo link can read the comments, including the name attached to each one. An email address, if you gave one, is hidden from other visitors. Only the small number of people who operate the demo can see it.

What an email gets sent for#

If email is turned on for the demo and you gave an address, someone @-mentioning you in a comment sends you one email about it, with an unsubscribe link. That's the only reason the demo would email a commenter. If email isn't turned on, no email goes out at all, and a mention just works as an in-app tag.

How your IP address is used#

Posting a comment, and a few other actions, are rate-limited by IP address, so no one can flood the demo with spam. The count is held in memory for up to one minute at a time, then automatically discarded. It is never written to the database or to a file, and it's never stored alongside your comment.

How long comments stay#

There's no automatic expiry today. A comment stays until someone deletes it. Because anonymous comments aren't tied to a verified account, anyone using the same review link can edit or delete one, the same way you could delete your own. You can also email hello@desde.design and we'll remove a comment for you.

We don't sell anything collected on the demo, we don't run ads against it, and we don't share it outside the people who operate it.

What none of this does#

Nothing here uses ad trackers, advertising networks, or scripts that follow you from one site to another. The website counts page views, in the plain way described above. The only other thing it collects is an email address, and only if you sign up for release news.

The Editor and the demo count nothing at all. No analytics package appears in either dependency list, which is something you can check yourself rather than take our word for.

The one thing outside our control is a self-hosted Viewer. An operator running their own copy could add their own analytics to it. That would be their choice, on their server, and this page can't speak for it.

Changes to this page#

If what the software actually does changes, this page will change with it, and the date at the top will move. This page describes what the code does. It hasn't been reviewed by a lawyer, and it isn't a substitute for legal advice if you need to know how a specific law applies to you.

Questions#

Email hello@desde.design.