Wadevo builds portable design systems from a short prompt or a reference image. Wadevo is operated by Tamarack Hills LLC.
The short version
- Browsing, /try, and the gallery need no account. Generating requires a signed-in account (authentication by Clerk).
- When you generate, your prompt or image is sent to the AI provider for that run — Google Gemini on our platform key by default, or OpenAI/Anthropic when you use your own stored key — then the result is returned to you. We do not store your prompt or image.
- The design systems you generate while signed in are saved to your dashboard so you can reopen and re-export them. Brand Check screenshots are judged in memory and never stored.
- If you add your own provider API keys, we store them encrypted (AES-256-GCM), show only a masked form, and you can remove them in Settings anytime.
- We set no tracking or analytics cookies (only Clerk’s strictly-necessary session cookies), run no analytics, and don’t sell your data.
- To remove your waitlist email or account data, email us and we’ll handle it by hand (self-serve tools are coming).
What we collect
| Data | When | Where it goes |
|---|---|---|
| Text prompt (up to 4,000 chars) | Generating in Studio | Sent to the run’s AI provider (Google Gemini on our key; OpenAI/Anthropic on yours). Not stored by Wadevo. |
| Reference image (≤ 8 MB) | Uploading in Studio | Sent inline to the run’s AI provider. Never written to our disk. |
| Account email + ID | Creating an account / signing in | Handled by Clerk (our auth provider); we store the Clerk user ID and email with your account row. |
| Generated design systems | Generating while signed in | Saved to your dashboard (tokens, DESIGN.md, style guide) so you can reopen them. Email us to delete. |
| Your provider API keys (optional) | Settings → Bring your own key | Stored encrypted at rest (AES-256-GCM), decrypted in memory per call, shown only masked, removable anytime. |
| Brand Check screenshot | Running a Brand Check | Sent to Google Gemini for the visual check; processed in memory; not stored by Wadevo. |
| Email address | Joining the waitlist | Stored by Wadevo (see below). |
| “Which AI tool?” (optional) | Waitlist form / onboarding | Stored alongside your email / account metadata. |
What we do not collect
- No tracking cookies and no analytics. We’ve installed no analytics or advertising provider, and set no tracking pixels.
- No stored prompts, reference images, or Brand Check screenshots. Inputs exist in server memory for the one run, then are gone.
- No stored IP address. Your IP is used only momentarily, in server memory, to apply rate limits. It is not written to a log or database.
- No plaintext API keys. Your provider keys are stored only as encrypted blobs; our agent-access keys are stored only as hashes.
- No payment data. Founding-member checkout, if you use it, happens entirely on Stripe’s pages; card details never touch our servers.
How your generation data is used
Your prompt or image is sent to the run’s AI provider to produce the tokens and DESIGN.md prose, which we return to you. Wadevo does not train any model on your inputs — we have no training pipeline. The deterministic parts of the output (CSS, the Tailwind config, the style-guide HTML, the React components) are produced by Wadevo’s own templates; only the token extraction and DESIGN.md prose come from the model.
AI providers as processors
On the platform path (the default and the free tier), your prompt or image is processed by Google LLC on our behalf through the Gemini API; Brand Check screenshots also go to Gemini. The content you submit leaves Wadevo and is processed on Google’s infrastructure, which may be located anywhere Google operates. EU/EEA data residency is not guaranteed.
If you bring your own key (Settings → Bring your own key), generations on that provider go to OpenAI (policies) or Anthropic (privacy policy) under your own agreement with that provider — Wadevo passes your input through on your key and stores none of it. Clerk Inc. processes your sign-in (email, session) as our authentication provider.
Google’s processing is governed by Google’s Data Processing Terms and Privacy Policy. Model-generated HTML previewed in Studio renders inside a sandboxed iframe with a null origin that can’t reach the rest of the page or your data — a security boundary on our side that doesn’t change how Google processes your input.
How waitlist data is stored
If you join the waitlist, your email (lowercased) and optional “which tool” answer are saved to our Postgres database. We use them for one purpose: to email you about early access and launch. We don’t send marketing email without your explicit consent, and we don’t share this list.
Cookies
Wadevo sets no tracking or analytics cookies — and no third-party pixels. Signing in sets Clerk’s strictly-necessary session cookies (e.g. __session/__client) so you stay signed in — that’s their only job. Your accessibility and appearance preferences live in your browser’s localStorage, not cookies. Because we set no non-essential cookies, no consent banner is required; if we ever add analytics, we’ll gate it behind an explicit consent choice for EU/EEA/UK visitors before any such script loads.
Data retention
- Prompts, images, Brand Check screenshots: not retained by Wadevo; they exist only in server memory for one run. The AI provider may retain them transiently per its API terms.
- Generated systems: retained in your dashboard while your account exists; email us to delete any or all of them.
- Your provider API keys: retained encrypted until you remove them in Settings (removal deletes the row).
- Waitlist email: retained until you ask us to remove it.
- Rate-limit data: in-memory only, cleared on server restart. Never persisted.
Your rights
Available now
- Remove your own provider keys — Settings → Bring your own key → Remove (self-serve, immediate).
- Removal from the waitlist, deletion of saved systems, or full account deletion. Email us and we’ll do it by hand, promptly.
- Access to what we hold. Email us and we’ll send you what’s attached to your account (account email/ID, saved systems, key metadata — never key plaintext, which we can’t read).
Coming (not live yet — exercised by email until then)
One-click data export and self-service account deletion are built next; we don’t claim them as live. The contact below is how to exercise your rights today.
For EU / EEA / UK users (GDPR)
- Lawful basis for generation: legitimate interest — providing the service you explicitly requested when you click generate.
- Lawful basis for the waitlist: consent — you chose to submit the form, and can withdraw it anytime by asking us to delete your entry.
- International transfers: your input may be processed outside the EU/EEA/UK on the infrastructure of the run’s AI provider (Google by default; OpenAI or Anthropic on your own key) and of Clerk; each acts as an Article 28 processor for that processing.
- Your statutory rights (access, rectification, erasure, restriction, objection, portability) apply; for now, exercise them through the contact below.
For California users (CCPA/CPRA)
Wadevo does not currently meet the CCPA’s applicability thresholds. Regardless, we do not sell or share your personal information. California residents may request removal of their waitlist entry through the contact below.
Changes & contact
If we make a material change, we’ll post the updated policy here and update the “Last updated” date. Privacy questions and data requests: privacy@wadevo.com.