Get Started
Legal

Privacy Policy

Last updated: September 29, 2026

At Designless Private Limited ("Designless", "Company", "we", "us", or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our platform (collectively, the "Service").

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when using the Service, including:

  • Account Information: Your email address, and a password if you sign up with email. If you sign in with Google, we receive your name, email address, and profile photo link from Google
  • Profile and Billing Details: Your name and country and, where an invoice needs them, your state, postal code, and tax registration number (such as a GSTIN). If you request an Enterprise plan, your company's name, website domain, and size
  • Content Data: Design expressions, prompts, preferences, and other content you input into the Service
  • Communication Data: Messages, feedback, and support requests you send to us
  • Payment Information: Billing details processed through our third-party payment provider (we do not store full payment card numbers)

1.2 Information Collected Automatically

When you use the Service, we collect the following automatically:

  • Page Views: When you open a page on designless.io, our server records the view from the page request itself; your browser runs no measurement script for it. LESS Studio at designless.app records page views through our own server as well, including for visitors who are not signed in. Each record holds the page, the website that sent you (its domain only), your country, a device type (mobile, tablet, or desktop), a browser family, and a visitor code. The visitor code is a one-way hash of your IP address and your browser's user agent, computed separately for each site with a key that changes every day, so it cannot connect your visits across days or between designless.io and designless.app. Your IP address and full user agent are not stored with the record. On designless.io, for visitors outside the European Economic Area, the campaign labels in a link (utm_source, utm_medium, and utm_campaign) are recorded too. Page views on designless.io are never linked to an account
  • Product Usage: When you are signed in to LESS Studio, we record the pages you open and the actions you take in the product (for example creating or publishing a brand, or exporting an artefact) with your account, and the website that referred you when you signed up. You can turn this off with the Usage statistics switch on your LESS Studio profile page; records we need for billing, usage limits, and security are kept either way
  • Performance Timings: LESS Studio uses Vercel Speed Insights, which reports how quickly each page loads and responds, with the page address and your connection speed, to Vercel, our hosting provider. designless.io does not use it
  • Log Data: Our servers and hosting providers may record IP address, access times, referring URLs, and error logs

We do not use advertising pixels, session recording, or cross-site tracking. Cookies and browser storage are described in Section 6.

1.3 The Demo Bar on the designless.io Home Page

The home page has a demo bar where you can type a short description of a brand. If you use it, the text you type is sent to an AI model provider listed on our sub-processors page to write the reply; we do not store the text. To limit how often the demo can be used from one connection, we store your IP address and the time of each request. Your browser also keeps a count of your demo requests (see Section 6).

1.4 Information from Third Parties

We may receive information about you from third-party services you connect to your account, such as design applications, code repositories, or authentication providers.

2. How We Use Your Information

We use the information we collect for the following purposes:

Purpose Legal Basis
Provide and operate the Service Contract performance
Process your content to generate design systems and outputs Contract performance
Send service updates and administrative messages Legitimate interest
Improve and optimize the Service Legitimate interest
Analyze usage patterns and trends Legitimate interest
Detect, prevent, and address security issues Legitimate interest
Send marketing communications (with consent) Consent
Comply with legal obligations Legal obligation

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following limited circumstances:

  • Service Providers: With trusted third-party vendors who assist us in operating the Service (hosting, analytics, payment processing, email delivery), bound by contractual obligations to protect your data. The current list is published at designless.io/subprocessors.
  • Legal Requirements: When required by law, legal process, or government request
  • Safety and Rights: To protect the rights, property, or safety of the Company, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, in which case your information may be transferred to the acquiring entity
  • With Your Consent: When you have given us explicit permission to share your information

4. Data Retention

We keep your information while your account is active. These are the automatic deletion schedules our systems run today:

  • Page Views: Page-view records, and the routine status checks the canvas and the desktop app send, are deleted 90 days after they are recorded. Daily totals made from them, which hold no visitor code, are kept
  • Security Alerts: Security alerts, which can include an IP address, are kept until we review them; once closed, they are deleted 90 days after they were raised
  • Agent and Canvas Activity Logs: Logs of the requests your agents make through LESS MCP, and of the edits applied in canvas sessions, are deleted after 12 months
  • Deleted Accounts: When you delete your account in LESS Studio, sign-in is blocked and your API keys are suspended at once, and your published themes are deleted 30 days later

Other information, including your account details, content, other product usage records, support correspondence, and the IP addresses the demo bar records, has no automatic deletion schedule today. You may delete your content at any time, and you can ask us to delete your personal data (see Section 7).

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Regular security assessments and penetration testing
  • Access controls and role-based permissions for our team
  • Secure development practices and code review processes
  • Incident response procedures and breach notification protocols

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Cookies and Browser Storage

designless.io sets no cookies. Its pages load no scripts, fonts, or images from other companies; our typefaces are served from our own domain, cdn.designless.app.

LESS Studio can cause two cookies to be set, both tied to signing in:

  • ls-canvas-token: Set by LESS Studio while you are signed in, for designless.app and its subdomains. It carries your sign-in to the canvas at canvas.designless.app. It lasts up to one hour, is renewed while you stay signed in, and is removed when you sign out
  • __cf_bm: When your browser opens a page on our sign-in server at api.designless.app, for example while you sign in with Google, Cloudflare, the network provider in front of that server, sets this security cookie for that domain to tell people from automated traffic. It expires after 30 minutes

We do not use advertising, analytics, or other tracking cookies. You can manage cookies through your browser settings; if you block ls-canvas-token, the canvas may not recognise your LESS Studio sign-in.

Your browser's local storage and session storage can be read only by the site that wrote them. We use them as follows:

  • designless.io: Nothing, unless you use the demo bar on the home page, which keeps a count of your demo requests (less-demo-usage) that starts over after 24 hours
  • LESS Studio: Your sign-in session; your color mode and the notices you have dismissed or snoozed; and, between signing up and your first sign-in, the answers you gave at sign-up with your email address, removed when they are applied. Session storage, which your browser clears when you close the tab, holds a team invitation while you sign in, the update notices you dismissed, and a flag that stops the page reloading in a loop after an update
  • The canvas at canvas.designless.app: Interface state such as your view preferences, open tabs, and dismissed notices

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to the processing of your data for certain purposes
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis

To exercise any of these rights, please contact our privacy team. We will respond to your request within 30 days.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses approved by the European Commission where applicable.

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.

10. Third-Party Links

The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services before providing your information.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information is collected, used, shared, or sold
  • The right to delete personal information held by us
  • The right to opt out of the sale of personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your CCPA rights

To exercise your CCPA rights, please contact our privacy team.

12. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the rights described in Section 7 above. Our legal bases for processing are described in Section 2.

You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

13. Indian Privacy Rights (DPDP Act)

Designless Private Limited is incorporated in India. If you are in India, the Digital Personal Data Protection Act, 2023 (the "DPDP Act") applies to our processing of your digital personal data. We process personal data for the purposes described in Section 2, on the basis of your consent or for legitimate uses recognized under the DPDP Act.

As a Data Principal under the DPDP Act, you have the right to:

  • Access a summary of the personal data we process about you and the processing activities undertaken
  • Request correction, completion, or updating of your personal data
  • Request erasure of your personal data, subject to legal retention requirements
  • Withdraw consent at any time, with the same ease with which it was given
  • Nominate another individual to exercise your rights in the event of death or incapacity
  • Have your grievances addressed through an accessible grievance-redressal mechanism

To exercise any of these rights or to raise a grievance, please contact our privacy team, which serves as our grievance-redressal contact. We will acknowledge and address grievances within the timelines prescribed under the DPDP Act and its rules. If you are not satisfied with our response after exhausting this mechanism, you may complain to the Data Protection Board of India.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Designless
Contact our privacy team

For data protection inquiries in the EU, you may also reach our Data Protection Officer at dpo at designless.io.

Expression Infrastructure for AI Agents
Home About Terms Privacy DPA Contact
© 2026 Designless™ · Designless Private Limited · CIN: U62011KA2026PTC219644 · Headquartered in Bengaluru, Karnataka, India