Design Buddy

Privacy policy

What Design Buddy stores, when configured providers receive content, how public links work, and how to exercise privacy rights.

Effective August 3, 2026 · version 2026-08-03

01Who this policy covers

This policy explains how Workflow Corporation, an Iowa corporation handles personal data when you visit Design Buddy, create an account, join a workspace, contact support, or open a public design link. A customer controls the content placed in its workspace; for personal data in that content, the customer is the controller and we act as its processor under the data processing terms.

02Data we collect

  • Account and workspace data: name, email address, password hash, session data, invitation and membership records, workspace name, role, and account timestamps.
  • Customer Content: designs, versions, text, uploads, fonts, images, brand assets, signatures, comments, comment author names, share-link records, and exports or backups you ask the service to prepare.
  • Provider inputs and output: prompts, selected design context, source images, and generated output when you use a configured text or image provider.
  • Technical and security data: IP address, request and error logs, device and browser information supplied with requests, security events, and share-link view counts.
  • Support data: messages, attachments, contact details, and troubleshooting information you send us.

03How we use data

  • Provide, authenticate, render, save, share, export, and support the service.
  • Operate workspace membership, invitations, password recovery, and transactional email.
  • Run a provider-backed feature when you deliberately invoke it and the provider is configured.
  • Protect accounts, investigate abuse, diagnose faults, and maintain service reliability.
  • Comply with law, enforce our terms, and establish or defend legal claims.
  • Understand aggregate service use and improve the product without selling personal data or using Customer Content to train a model of our own.

05Who receives data

We disclose data only as needed for the following recipients and purposes:

  • Other workspace members according to their role. Workspace members share one content library; a member may see content belonging to the workspace rather than to one individual.
  • Public-link recipients. Anyone holding an active share link can view and download the design named by it without an account. Comments are not included on the public page.
  • Infrastructure providers that host the application, managed database, stored workspace files, logs, and transactional email.
  • Configured AI providers. Depending on the feature selected, this may include OpenAI, Anthropic, Replicate, or Stability AI. A provider receives only the inputs needed for that request. Provider availability is controlled by deployment configuration.
  • Professional advisers, authorities, and a successor where reasonably necessary for legal advice, a valid legal demand, protection of rights and safety, or a merger, financing, or sale.

We do not sell personal data or share it for cross-context behavioural advertising.

06Text and image providers

Local editing, rendering, export, and plain-background removal run in your browser or in Design Buddy without sending the image to a model. Text assistance, image generation, and supported image edits can call a configured third-party provider.

Before invoking such a feature, do not include confidential or personal data that the provider does not need. Providers process requests under their own terms and retention settings. Design Buddy does not promise that a third-party provider will use data in the same way we do; the operator is responsible for configuring vendors on acceptable terms.

07Cookies and browser storage

Design Buddy uses essential browser storage, not advertising cookies. The service uses an Auth.js session cookie to keep you signed in, a workspace cookie to remember the active workspace, and a theme cookie. The browser may also retain interface hints, cross-tab clipboard content, a comment author name, and cached brand information in local storage.

Blocking essential cookies prevents sign-in and workspace selection. Clearing local storage removes the local conveniences but not workspace content stored by the service.

08Retention and deletion

We retain account and workspace data while the account or workspace is active and as needed afterward for security, dispute resolution, legal compliance, and ordinary backup rotation. Password-reset tokens expire after their stated window; used reset records and operational logs may remain for security and troubleshooting.

A verified workspace owner may request deletion through support@workflowcorp.com. Export required content first. We delete active workspace content and identity records subject to legal holds, fraud-prevention needs, and the time required for protected backups to age out. Revoking a public share link stops new access on the next request.

09Security

We use access controls, tenant-scoped storage paths, password hashing, signed sessions, unguessable share tokens, encryption in transit, provider access controls, and operational logging appropriate to the service. No system is perfectly secure. Report suspected compromise to support@workflowcorp.com and revoke exposed share links promptly.

10Where data is processed

The production service is hosted in the United States, and service providers may process data in the United States or other countries where they operate. Where transfer rules require a safeguard, we use the contractual mechanism described in the data processing terms or another lawful mechanism.

11Your choices and rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or an appeal, and may complain to a data-protection authority. Send requests to support@workflowcorp.com. We verify requests and may ask you to work through the workspace that controls the content.

We do not make decisions producing legal or similarly significant effects through automated processing. Browser or device privacy signals are not used because the service does not sell data or conduct cross-context behavioural advertising.

12Children

Design Buddy is a business service and is not directed to children under 13. We do not knowingly create accounts for children under 13. If you believe a child has provided data, contact support@workflowcorp.com so we can investigate and remove it where required.

13Changes and contact

We will post changes here and update the effective date. We will give reasonable advance notice of material changes when required.

Privacy requests and questions may be sent to support@workflowcorp.com.

Workflow Corporation, an Iowa corporation

210 Emerson Pl, Suite 300, Davenport, IA 52801, United States

support@workflowcorp.com · +1 (563) 275-6409