Legal
Privacy Policy
Effective date: January 1, 2024
Last updated: September 6, 2026
This Privacy Policy describes how Brutux Studio collects, uses, and protects your personal data when you use Desy Guard.
Who We Are
- Desy Guard is a B2B SaaS product developed and operated by Brutux Studio (SIREN: 980 255 814), a design and engineering studio based in Thonon-les-Bains, France.
- Contact: contact@brutux.studio
- Desy Guard helps agencies and enterprises audit codebases and design systems, extract design tokens and components, generate documented design systems, and monitor for drift continuously.
Data We Collect
Account Data
When you create an account, we collect your name, email address, and organization name. Authentication is handled by Clerk. We do not store raw passwords.
Usage Data
We collect data about how you use Desy Guard: pages visited, features used, analysis runs triggered. This data is used exclusively to improve the product.
Integration Tokens
If you connect GitHub, Figma, or Jira, we store OAuth access tokens for those services. These tokens are encrypted at rest and used solely to fetch your codebase, design files, or project tracking data for analysis.
Source Code and Design Files
When you connect a GitHub repository or Figma file, content is fetched via API and processed in memory. Only extracted design tokens, component names, and structural metadata are written to our database. Raw source code and raw design files are not permanently stored. Files temporarily staged during upload are removed after analysis completion. The extracted structured data is retained in EU Central (Frankfurt) storage for the duration of your subscription.
LLM Interaction Logs
When our AI analysis features process your codebase or design system, we log metadata (model used, token counts, cost) for billing and quality purposes. Prompts sent to LLM providers include design token names, component names, and property values derived from your project. They do not include your source code, file paths, or any personal data. LLM responses are not retained beyond the completion of the analysis job.
Payment Data
Billing is handled by Stripe. We do not store full credit card numbers. Stripe provides us with a payment method token and subscription status only.
How We Use Your Data
- To deliver the Desy Guard service: run analyses, generate reports, monitor drift, and provide recommendations.
- To manage your account and subscription.
- To communicate with you about your account, service updates, and critical security notices.
- To improve and debug the product using aggregated, anonymized usage data.
- We do not sell your data to any third party. We do not use your data for advertising.
Data Sharing and Sub-processors
- We share your data only with the sub-processors necessary to run the service.
- Supabase (EU Central, Frankfurt, Germany): database and file storage hosting.
- Vercel (global edge, primary US): application hosting and serverless functions.
- Clerk (US): authentication and user management.
- Stripe (US and EU): payment processing.
- Sentry (US, error data scrubbed before ingestion): error monitoring and performance tracking.
- Inngest (US): background job orchestration and processing.
- GitHub (US): source code integration (when connected by the user).
- Figma (US): design file integration (when connected by the user).
- Atlassian / Jira (US or EU depending on your tenant): project tracking integration (when connected by the user).
- LLM providers routed via our infrastructure: Anthropic (US), OpenAI (US), Google Gemini (US), Mistral AI (EU), Groq (US). Used exclusively for AI analysis features. Prompts do not include personal data, source code, or file contents.
- Resend (US): transactional email delivery.
- Desy Guard is in the process of executing Data Processing Agreements with all sub-processors. DPAs with Critical-tier vendors (Supabase, Vercel, Clerk, GitHub, Figma) are targeted for completion by Q4 2026, and with all remaining sub-processors by Q1 2027.
- For transfers of personal data to US-based processors, we rely on Standard Contractual Clauses (SCCs) incorporated into each vendor's DPA where required under GDPR Chapter V.
- EU data residency mode: organizations can activate EU data residency mode via Settings, which routes all AI analysis through Mistral AI (France). If EU-only routing fails, the system falls back to US-based providers and this event is logged in the organization's audit log. This option is available on all paid plans.
Data Retention
- We retain different categories of data for different periods, based on operational need and legal obligation.
- Project data (design tokens, component metadata, design system snapshots, analysis results): retained for the lifetime of your account and subscription. You may delete individual projects at any time. On account cancellation, project data is retained for 30 additional days to allow export, then permanently deleted.
- Audit logs and monitoring records: retained for 12 months from the date of generation, then automatically purged.
- Webhook payloads and analytics event data: retained for 90 days, then automatically purged.
- Billing records and invoices: retained for a minimum of 7 years as required by French financial regulations (Code de commerce, art. L123-22) and EU VAT obligations. This retention is mandatory regardless of account deletion.
- Raw source code and design files: not permanently stored. Content fetched from GitHub, Figma, or Jira is processed in memory and discarded after analysis. Only the extracted structured metadata is persisted.
- On account deletion, all personal data and project data outside mandatory retention categories is permanently erased within 24 hours via automated deletion.
Legal Basis for Processing
- In accordance with GDPR Article 13, Brutux Studio processes your personal data on the following legal bases:
- Contract performance (Article 6(1)(b)): processing necessary to provide the Desy Guard service, including account management, running analyses, generating design system reports, and delivering all features described in your subscription agreement.
- Legitimate interests (Article 6(1)(f)): processing necessary for security monitoring, fraud prevention, abuse detection, and maintaining the integrity and availability of the service. Our legitimate interests are balanced against your rights and do not override them.
- Legal obligation (Article 6(1)(c)): processing necessary to comply with applicable law, including retention of billing and invoice records for a minimum of 7 years as required by French and EU financial regulations.
Automated Decision-Making
- In accordance with GDPR Article 13(2)(f), Desy Guard does not make automated decisions that produce legal effects concerning you or that similarly significantly affect you, as defined by GDPR Article 22.
- AI analysis features (design system generation, drift detection, recommendations) produce outputs that require human review and action. No automated decision replaces or substitutes for human judgment on matters that could have legal or similarly significant consequences for you.
Your Rights Under GDPR
- As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: you may request a copy of the personal data we hold about you.
- Right of rectification: you may request correction of inaccurate data.
- Right of erasure: you may request deletion of your personal data.
- Right to data portability: you may request your data in a machine-readable format.
- Right to object: you may object to certain processing activities.
- Right to restriction: you may request that we limit how we use your data.
- To exercise any of these rights, contact us at contact@brutux.studio. We will respond within 30 days.
Security
- We apply industry-standard security measures: data encrypted in transit (TLS 1.3) and at rest (AES-256), access controls, and regular security reviews.
- OAuth tokens and secrets are stored encrypted.
- Row-level security is enforced at the database level to prevent cross-organization data access.
Contact and Data Requests
- Data Controller: Brutux Studio, Thonon-les-Bains, France
- DPO Contact: contact@brutux.studio
- For any question, data access request, or deletion request, contact us at contact@brutux.studio.
- You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertes): www.cnil.fr.