Privacy Policy
What personal data ai2 collects, why, the lawful basis for it, and the rights you have under UK GDPR.
1. Who we are
ai2 (ai2.design) is a design system product operated by BEY AGENCY LTD, a private limited company registered in England and Wales under company number 16435596, with a registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. BEY AGENCY LTD is the data controller for the personal data described in this policy.
For any privacy question or to exercise your rights, you can reach us at hi@bey.agency or hello@ai2.design. Both addresses reach the same team. Our supervisory authority is the UK Information Commissioner's Office (ICO), ico.org.uk.
2. Scope of this policy
This policy covers the ai2 website and its current features: the free open-core component registry, the documentation, the MCP server, and the two free tools (the Extractor and the Inspiration Gallery). It explains what personal data we handle when you use these, the lawful basis for it, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We aim to collect as little personal data as possible. When you subscribe to updates we use a double-opt-in step, and payment is processed by Polar Software, Inc., our merchant of record, so that we never handle your card details. This policy describes processing that is actually happening today rather than everything we might one day do.
3. Personal data we collect
We handle the following categories of personal data. We do not intentionally collect special category data (such as health, biometric, religious or political data) and the service is not directed to children.
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Contact data | The email address you submit to a newsletter or waitlist form, plus a confirmation status. | Provided by you | To send the updates you asked for, after you confirm through a double-opt-in email. |
| Purchase and licence data | Your email, the tier you bought, order and licence-key identifiers. Card details are handled by Polar and never reach us. | Provided by you at checkout via Polar | To provision and validate your licence and to keep a record of the purchase. |
| Correspondence data | Your email address and the content of any support message you send us. | Provided by you | To answer your enquiry and keep a record of the exchange. |
| Extractor inputs | The public URL you submit and the design tokens derived from it. | Provided by you | To fetch the target page server-side and return the extracted result at a private link. |
| Technical and log data | IP address, user-agent string, request timestamps. | Collected automatically by our hosting and CDN | To serve the site, keep it secure and prevent abuse. |
| Local preference | Your light or dark theme choice and your roadmap votes, held in your browser's local storage. | Set on your device | To remember your theme and your votes. These never leave your device and are not sent to us. |
| Licence session | If you sign in to the licence portal, your licence key, the tier you own and the email address on the licence, held in your browser's local storage. | Written on your device when you enter your key | To keep you signed in without an account. Unlike the items above this one does leave your device: the key is sent to us, and on to Polar, each time we validate your licence or you request a download. Signing out or clearing site data removes it. |
Newsletter and waitlist signups use a double-opt-in flow: when you submit a form we send a confirmation email, and your address is only added to our list after you click the link in it. Subscriber addresses are handled by Resend, our email provider (see section 7). You can unsubscribe from any email at any time.
4. How we use your data
- Operating, maintaining and securing the ai2 site, registry, documentation and MCP server.
- Running the Extractor: fetching the public URL you submit server-side and returning the derived tokens at a private link that expires automatically.
- Responding to support emails and keeping a record of the correspondence.
- Sending the newsletter or waitlist updates you have asked for, after you confirm through double-opt-in.
- Validating licence keys for paid tiers and keeping a record of the purchase. The key itself is generated and delivered to you by Polar, our merchant of record; we check it against Polar rather than issuing it.
- Emailing product download links to the address on your licence when you request a download, and counting those requests against your licence so the fair-use limit can be applied.
- Detecting, preventing and responding to abuse, fraud and security incidents.
- Meeting our legal, regulatory and accounting obligations.
We measure aggregate usage and page speed using Vercel Web Analytics and Vercel Speed Insights. These are cookieless: they set nothing on your device and read nothing from it. Vercel derives a hash from the incoming request so that one visit can be told apart from another, and discards it after 24 hours; we receive page views, page-speed measurements, referrers, filtered query parameters, an approximate location no more precise than city level, and device, operating system and browser type. We cannot identify you from this, we cannot follow you across other websites, and we do not attempt to link it to your licence, your email address or anything else we hold. We use no ad networks and no behavioural profiling, we do not carry out automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.
5. Legal bases under UK GDPR
We rely on the following lawful bases under Article 6 of the UK GDPR for each purpose:
| Purpose | Lawful basis |
|---|---|
| Delivering the free tools and site you request, including Extractor results. | Performance of a contract, or steps taken at your request before entering one (Article 6(1)(b)). |
| Provisioning and validating a paid licence you purchased, and keeping the order record. | Performance of a contract (Article 6(1)(b)), and compliance with a legal obligation for tax and accounting records (Article 6(1)(c)). |
| Sending newsletter or waitlist updates after you confirm through double-opt-in. | Consent, which you may withdraw at any time (Article 6(1)(a)). |
| Answering and recording support correspondence. | Legitimate interests in helping users and keeping business records (Article 6(1)(f)). |
| Security, abuse prevention and keeping the service operational. | Legitimate interests in protecting the service and its users (Article 6(1)(f)). |
| Measuring aggregate usage and page speed through cookieless analytics. | Legitimate interests in understanding which pages are used and where the site is slow, so we can improve it (Article 6(1)(f)). We rely on this rather than consent because the measurement stores nothing on your device and cannot identify you; you may object at any time under section 10. |
| Meeting statutory accounting and legal-retention duties. | Compliance with a legal obligation (Article 6(1)(c)). |
8. International transfers
Some of our providers may store or process personal data outside the United Kingdom. Where that happens, we rely on an appropriate safeguard under the UK GDPR: a UK adequacy decision for the destination country, the UK International Data Transfer Addendum (UK IDTA) to the EU Standard Contractual Clauses, or the Standard Contractual Clauses where applicable, with any supplementary measures needed to keep your data protected to a UK standard.
9. Retention
We keep personal data only for as long as needed for the purpose it was collected for, or as required by law. The principal periods are:
| Data | Retention |
|---|---|
| Extractor inputs and derived tokens | Held transiently for about two hours at a private link, then deleted automatically. |
| Server and CDN logs | Retained for a short period by our hosting provider for security and operations, then rotated. |
| Newsletter and waitlist email addresses | Unconfirmed signups expire within 24 hours. Confirmed addresses are kept until you unsubscribe or ask us to remove your address. |
| Purchase and licence records | Kept for the life of the licence and afterwards as needed to meet statutory accounting and tax-retention duties. |
| Support correspondence | Kept while needed to handle your enquiry and for a reasonable period afterwards as a business record. |
| Theme preference and roadmap votes | Stay in your browser's local storage until you clear them; never held by us. |
| Licence session | Stays in your browser's local storage until you sign out or clear site data. We do not keep a copy of it; the key is only used at the moment we validate it or send you a download. |
| Rate-limit counters | Extractor counters expire on a rolling 24-hour window and download counters on a rolling 12-hour window. Download counters are keyed to a one-way hash of the licence key, so the key itself is never stored. |
| Subscribe tokens and order records | Confirmation tokens expire within 24 hours. Order and idempotency records are kept for the period needed to prevent duplicate processing and to support the purchase and licence records above. |
10. Your rights under UK GDPR
Subject to the conditions in the UK GDPR, you have the following rights over your personal data:
- Access: ask for a copy of the personal data we hold about you.
- Rectification: ask us to correct data that is inaccurate or incomplete.
- Erasure: ask us to delete your data (the right to be forgotten), where no overriding legal reason to keep it applies.
- Restriction: ask us to limit how we use your data in certain circumstances.
- Portability: receive the data you gave us in a structured, commonly used, machine-readable format.
- Objection: object to processing based on our legitimate interests.
- Withdraw consent: where we rely on consent, withdraw it at any time without affecting prior processing.
- Complain: lodge a complaint with the ICO at ico.org.uk.
To exercise any of these rights, email hi@bey.agency. To help us protect your data, please send the request from the email address it concerns where possible, or give us enough context to confirm your identity. We respond to valid requests within one calendar month and do not charge a fee for routine requests.
11. Security
We apply reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss and misuse, including transport encryption and keeping the amount of data we hold to a minimum. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take our responsibilities seriously and keep our measures under review.
12. Children's privacy
The service is not directed to children under the age of 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact hi@bey.agency and we will delete it.
13. Changes to this policy
We may update this policy as the service develops and new processing begins. Each version carries a last-updated date and a version number shown at the top of this page. Material changes will be reflected here before the related processing starts.
14. Contact and complaints
If you have a concern about how we handle your personal data, please contact us first at hi@bey.agency or hello@ai2.design so we can try to put it right.
You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk at any time, without affecting any other legal remedy available to you.
Operator and legal contact
ai2 (ai2.design) is operated by BEY AGENCY LTD, a private limited company registered in England and Wales (company number 16435596), registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
Questions about this document can be sent to hi@bey.agency or hello@ai2.design. Both addresses reach the same team.
Go to contact