Skip to content

Now in the official shadcn registry directory.

Start free

Privacy Policy

What personal data ai2 collects, why, the lawful basis for it, and the rights you have under UK GDPR.

Last updated: 2026-07-27Version 1.6

1. Who we are

ai2 (ai2.design) is a design system product operated by BEY AGENCY LTD, a private limited company registered in England and Wales under company number 16435596, with a registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. BEY AGENCY LTD is the data controller for the personal data described in this policy.

For any privacy question or to exercise your rights, you can reach us at hi@bey.agency or hello@ai2.design. Both addresses reach the same team. Our supervisory authority is the UK Information Commissioner's Office (ICO), ico.org.uk.

2. Scope of this policy

This policy covers the ai2 website and its current features: the free open-core component registry, the documentation, the MCP server, and the two free tools (the Extractor and the Inspiration Gallery). It explains what personal data we handle when you use these, the lawful basis for it, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We aim to collect as little personal data as possible. When you subscribe to updates we use a double-opt-in step, and payment is processed by Polar Software, Inc., our merchant of record, so that we never handle your card details. This policy describes processing that is actually happening today rather than everything we might one day do.

3. Personal data we collect

We handle the following categories of personal data. We do not intentionally collect special category data (such as health, biometric, religious or political data) and the service is not directed to children.

CategoryExamplesSourcePurpose
Contact dataThe email address you submit to a newsletter or waitlist form, plus a confirmation status.Provided by youTo send the updates you asked for, after you confirm through a double-opt-in email.
Purchase and licence dataYour email, the tier you bought, order and licence-key identifiers. Card details are handled by Polar and never reach us.Provided by you at checkout via PolarTo provision and validate your licence and to keep a record of the purchase.
Correspondence dataYour email address and the content of any support message you send us.Provided by youTo answer your enquiry and keep a record of the exchange.
Extractor inputsThe public URL you submit and the design tokens derived from it.Provided by youTo fetch the target page server-side and return the extracted result at a private link.
Technical and log dataIP address, user-agent string, request timestamps.Collected automatically by our hosting and CDNTo serve the site, keep it secure and prevent abuse.
Local preferenceYour light or dark theme choice and your roadmap votes, held in your browser's local storage.Set on your deviceTo remember your theme and your votes. These never leave your device and are not sent to us.
Licence sessionIf you sign in to the licence portal, your licence key, the tier you own and the email address on the licence, held in your browser's local storage.Written on your device when you enter your keyTo keep you signed in without an account. Unlike the items above this one does leave your device: the key is sent to us, and on to Polar, each time we validate your licence or you request a download. Signing out or clearing site data removes it.

Newsletter and waitlist signups use a double-opt-in flow: when you submit a form we send a confirmation email, and your address is only added to our list after you click the link in it. Subscriber addresses are handled by Resend, our email provider (see section 7). You can unsubscribe from any email at any time.

4. How we use your data

  • Operating, maintaining and securing the ai2 site, registry, documentation and MCP server.
  • Running the Extractor: fetching the public URL you submit server-side and returning the derived tokens at a private link that expires automatically.
  • Responding to support emails and keeping a record of the correspondence.
  • Sending the newsletter or waitlist updates you have asked for, after you confirm through double-opt-in.
  • Validating licence keys for paid tiers and keeping a record of the purchase. The key itself is generated and delivered to you by Polar, our merchant of record; we check it against Polar rather than issuing it.
  • Emailing product download links to the address on your licence when you request a download, and counting those requests against your licence so the fair-use limit can be applied.
  • Detecting, preventing and responding to abuse, fraud and security incidents.
  • Meeting our legal, regulatory and accounting obligations.

We measure aggregate usage and page speed using Vercel Web Analytics and Vercel Speed Insights. These are cookieless: they set nothing on your device and read nothing from it. Vercel derives a hash from the incoming request so that one visit can be told apart from another, and discards it after 24 hours; we receive page views, page-speed measurements, referrers, filtered query parameters, an approximate location no more precise than city level, and device, operating system and browser type. We cannot identify you from this, we cannot follow you across other websites, and we do not attempt to link it to your licence, your email address or anything else we hold. We use no ad networks and no behavioural profiling, we do not carry out automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.

6. Cookies and local storage

This site sets no cookies beyond what is strictly necessary and uses no tracking cookies. Our analytics are cookieless and store nothing on your device, which is why you are not asked to accept a cookie banner here. Your theme preference and your roadmap votes are kept in your browser's local storage and are not transmitted to us. The licence session, if you sign in to the licence portal, is also kept in local storage, but it holds your licence key and that key is transmitted when we validate it or send you a download. Full details of each item are in the Cookie Policy at /legal/cookies.

7. Sharing and sub-processors

We share personal data only with service providers who process it on our behalf under contract, and only as needed to run the service. We do not sell personal data. A provider only receives data for the feature it powers.

ProviderPurposeLocation
Vercel (hosting and CDN)Serving the site, edge delivery, and standard server and CDN logs (IP address, user-agent, timestamps).May be outside the UK; see section 8.
Vercel Web Analytics and Speed InsightsCookieless measurement of page views and page speed, described in section 4. No cookie is set and nothing is stored on or read from your device; visits are told apart by a hash Vercel derives from the request and discards after 24 hours.May be outside the UK; see section 8.
Resend (email)Delivering transactional and newsletter emails (subscribe confirmation, welcome, support acknowledgements and product download links) and storing confirmed subscriber addresses. Resend does not deliver your licence key; Polar does.United States; safeguarded under section 8.
Polar Software, Inc. (payments, merchant of record)Our merchant of record for paid licences: taking payment, handling card data, calculating and remitting sales tax and VAT, issuing your receipt and invoice, processing refunds, and generating and delivering your licence key. Polar is the seller of record for the transaction and operates its own customer portal where your key and orders are shown; BEY AGENCY LTD is the licensor. Card details are handled by Polar and never reach us.United States and Ireland; safeguarded under section 8.
Google (Workspace email)Hosting the hello@ai2.design mailbox. When you use the contact form, or email us directly, your name, address and the content of your message are delivered into and stored in that mailbox. Google processes it as our email host; we do not use Google Analytics, Google Ads or any Google tracking on this site.May be outside the UK; see section 8.
Framer (embedded product previews)Live previews of the Framer products we sell are embedded on their product pages (under /pro/framer). When such a page loads, your browser requests the preview directly from Framer, so Framer receives your IP address, user-agent and the fact that you viewed that page, and Framer loads its own assets and fonts. This happens only on those product pages, not on the rest of the site, and no cookie is set on our side. What Framer does with that request is governed by Framer's own privacy terms.May be outside the UK; see section 8.
Upstash / Vercel KV (key-value store)Short-lived operational records: rate-limit counters (including download counters keyed to a one-way hash of your licence key, never the key itself), subscribe confirmation tokens, and order and idempotency records so a purchase is not processed twice.May be outside the UK; see section 8.

We may also disclose personal data where required by law, by a valid court order, or where necessary to protect our rights, property or safety or those of others.

8. International transfers

Some of our providers may store or process personal data outside the United Kingdom. Where that happens, we rely on an appropriate safeguard under the UK GDPR: a UK adequacy decision for the destination country, the UK International Data Transfer Addendum (UK IDTA) to the EU Standard Contractual Clauses, or the Standard Contractual Clauses where applicable, with any supplementary measures needed to keep your data protected to a UK standard.

9. Retention

We keep personal data only for as long as needed for the purpose it was collected for, or as required by law. The principal periods are:

DataRetention
Extractor inputs and derived tokensHeld transiently for about two hours at a private link, then deleted automatically.
Server and CDN logsRetained for a short period by our hosting provider for security and operations, then rotated.
Newsletter and waitlist email addressesUnconfirmed signups expire within 24 hours. Confirmed addresses are kept until you unsubscribe or ask us to remove your address.
Purchase and licence recordsKept for the life of the licence and afterwards as needed to meet statutory accounting and tax-retention duties.
Support correspondenceKept while needed to handle your enquiry and for a reasonable period afterwards as a business record.
Theme preference and roadmap votesStay in your browser's local storage until you clear them; never held by us.
Licence sessionStays in your browser's local storage until you sign out or clear site data. We do not keep a copy of it; the key is only used at the moment we validate it or send you a download.
Rate-limit countersExtractor counters expire on a rolling 24-hour window and download counters on a rolling 12-hour window. Download counters are keyed to a one-way hash of the licence key, so the key itself is never stored.
Subscribe tokens and order recordsConfirmation tokens expire within 24 hours. Order and idempotency records are kept for the period needed to prevent duplicate processing and to support the purchase and licence records above.

10. Your rights under UK GDPR

Subject to the conditions in the UK GDPR, you have the following rights over your personal data:

  • Access: ask for a copy of the personal data we hold about you.
  • Rectification: ask us to correct data that is inaccurate or incomplete.
  • Erasure: ask us to delete your data (the right to be forgotten), where no overriding legal reason to keep it applies.
  • Restriction: ask us to limit how we use your data in certain circumstances.
  • Portability: receive the data you gave us in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on our legitimate interests.
  • Withdraw consent: where we rely on consent, withdraw it at any time without affecting prior processing.
  • Complain: lodge a complaint with the ICO at ico.org.uk.

To exercise any of these rights, email hi@bey.agency. To help us protect your data, please send the request from the email address it concerns where possible, or give us enough context to confirm your identity. We respond to valid requests within one calendar month and do not charge a fee for routine requests.

11. Security

We apply reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss and misuse, including transport encryption and keeping the amount of data we hold to a minimum. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take our responsibilities seriously and keep our measures under review.

12. Children's privacy

The service is not directed to children under the age of 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact hi@bey.agency and we will delete it.

13. Changes to this policy

We may update this policy as the service develops and new processing begins. Each version carries a last-updated date and a version number shown at the top of this page. Material changes will be reflected here before the related processing starts.

14. Contact and complaints

If you have a concern about how we handle your personal data, please contact us first at hi@bey.agency or hello@ai2.design so we can try to put it right.

You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk at any time, without affecting any other legal remedy available to you.

Operator and legal contact

ai2 (ai2.design) is operated by BEY AGENCY LTD, a private limited company registered in England and Wales (company number 16435596), registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

Questions about this document can be sent to hi@bey.agency or hello@ai2.design. Both addresses reach the same team.

Go to contact
Other policies