Skip to main content
wadevo
Legal

Privacy Policy

Last updated: 4 June 2026

What we touch, and what we don't — written to match how Wadevo works today, not how we'd like it to work later. Where a right or feature isn't live yet, we say so and label it “coming.”

Wadevo builds portable design systems from a short prompt or a reference image. Wadevo is operated by Tamarack Hills LLC.

The short version

What we collect

Data Wadevo collects, when, and where it goes
DataWhenWhere it goes
Text prompt (up to 4,000 chars)Generating in StudioSent to the run’s AI provider (Google Gemini on our key; OpenAI/Anthropic on yours). Not stored by Wadevo.
Reference image (≤ 8 MB)Uploading in StudioSent inline to the run’s AI provider. Never written to our disk.
Account email + IDCreating an account / signing inHandled by Clerk (our auth provider); we store the Clerk user ID and email with your account row.
Generated design systemsGenerating while signed inSaved to your dashboard (tokens, DESIGN.md, style guide) so you can reopen them. Email us to delete.
Your provider API keys (optional)Settings → Bring your own keyStored encrypted at rest (AES-256-GCM), decrypted in memory per call, shown only masked, removable anytime.
Brand Check screenshotRunning a Brand CheckSent to Google Gemini for the visual check; processed in memory; not stored by Wadevo.
Email addressJoining the waitlistStored by Wadevo (see below).
“Which AI tool?” (optional)Waitlist form / onboardingStored alongside your email / account metadata.

What we do not collect

How your generation data is used

Your prompt or image is sent to the run’s AI provider to produce the tokens and DESIGN.md prose, which we return to you. Wadevo does not train any model on your inputs — we have no training pipeline. The deterministic parts of the output (CSS, the Tailwind config, the style-guide HTML, the React components) are produced by Wadevo’s own templates; only the token extraction and DESIGN.md prose come from the model.

AI providers as processors

On the platform path (the default and the free tier), your prompt or image is processed by Google LLC on our behalf through the Gemini API; Brand Check screenshots also go to Gemini. The content you submit leaves Wadevo and is processed on Google’s infrastructure, which may be located anywhere Google operates. EU/EEA data residency is not guaranteed.

If you bring your own key (Settings → Bring your own key), generations on that provider go to OpenAI (policies) or Anthropic (privacy policy) under your own agreement with that provider — Wadevo passes your input through on your key and stores none of it. Clerk Inc. processes your sign-in (email, session) as our authentication provider.

Wadevo uses a paid Gemini API key. Under Google’s paid API terms, Google does not use your prompts or images to train its models; inputs may be logged transiently by Google for safety and abuse monitoring.

Google’s processing is governed by Google’s Data Processing Terms and Privacy Policy. Model-generated HTML previewed in Studio renders inside a sandboxed iframe with a null origin that can’t reach the rest of the page or your data — a security boundary on our side that doesn’t change how Google processes your input.

How waitlist data is stored

If you join the waitlist, your email (lowercased) and optional “which tool” answer are saved to our Postgres database. We use them for one purpose: to email you about early access and launch. We don’t send marketing email without your explicit consent, and we don’t share this list.

Cookies

Wadevo sets no tracking or analytics cookies — and no third-party pixels. Signing in sets Clerk’s strictly-necessary session cookies (e.g. __session/__client) so you stay signed in — that’s their only job. Your accessibility and appearance preferences live in your browser’s localStorage, not cookies. Because we set no non-essential cookies, no consent banner is required; if we ever add analytics, we’ll gate it behind an explicit consent choice for EU/EEA/UK visitors before any such script loads.

Data retention

Your rights

Available now

Coming (not live yet — exercised by email until then)

One-click data export and self-service account deletion are built next; we don’t claim them as live. The contact below is how to exercise your rights today.

For EU / EEA / UK users (GDPR)

For California users (CCPA/CPRA)

Wadevo does not currently meet the CCPA’s applicability thresholds. Regardless, we do not sell or share your personal information. California residents may request removal of their waitlist entry through the contact below.

Changes & contact

If we make a material change, we’ll post the updated policy here and update the “Last updated” date. Privacy questions and data requests: privacy@wadevo.com.