In short
- We collect what we need to run Gradiently and nothing else.
- We never sell your data, and we don’t run advertising trackers.
- Your designs and uploads are private, and no AI model is trained on them.
- You can download or delete your data at any time from Settings.
10 sections
Gradiently is the controller of the personal data described here. That means we decide why and how it is used, and we answer for it.
For anything about your data, write to hello@gradiently.design or use the privacy request form. We answer within 30 days.
What you give us
- Account: your email address, name, username and a hashed password. If you sign in with Google, we receive your name, email address and profile picture from Google instead of a password.
- Profile: the picture, bio and links you choose to add.
- Your work: brands, designs, the images, logos and fonts you upload, Marks you craft or claim, and templates you share.
- AI requests: what you type to the Designer, the images you attach, and its replies.
- Messages: support requests, reports you file and replies to our emails.
What is created as you use Gradiently
- Ownership records: the ledger of each claim, transfer and certificate.
- Purchases: what you bought, the amount, currency, billing country and a payment reference. Card details go to Stripe; we never see or store full card numbers.
- Usage and device data: IP address, browser and device type, language, the pages and features you use, errors, and the dates and times of your sessions.
- Cookies: only the ones the service needs. See the Cookie Policy.
We don’t buy data about you, and we don’t ask for sensitive data such as health, religion or political views. Please don’t put it in your designs or requests.
| Purpose | Legal basis |
|---|---|
| Running your account, saving and exporting your work, recording who owns each Mark | Performing our contract with you |
| Answering the Designer and other AI requests you make | Performing our contract with you |
| Taking payments, sending receipts, paying out and keeping accounts | Contract, and our legal obligations on tax and accounting |
| Security: preventing fraud, abuse and impersonation, and checking new Marks against existing ones | Our legitimate interest in a safe service, and the interests of Mark owners |
| Measuring how Gradiently is used so we can fix and improve it | Our legitimate interest in improving the service |
| Emails the service depends on: security, receipts and notices about your Marks | Performing our contract with you |
| Optional emails: news about your Marks, the Market and the weekly edition | Our legitimate interest. You can turn each one off in Settings or unsubscribe in any email |
| Answering legal requests and defending legal claims | Legal obligation, and our legitimate interest |
Usage is measured with our own records. We don’t use third-party advertising or analytics trackers. If we ever add an analytics provider, we will list it under Subprocessors first and ask for your consent where the law requires it.
The check that compares a new Mark with existing ones is automatic. If it turns your Mark away and you think it is wrong, ask us and a person will look at it. We make no other automated decisions that have a legal or similarly significant effect on you.
When you use the Designer or Match a picture, your request, the design or Mark you are working on and any image you attach are sent to our AI provider, Anthropic, which returns a reply. It is sent only when you ask for it.
- Neither we nor our AI provider use your content to train AI models.
- The provider may keep requests for a short time to detect abuse, then deletes them.
- Other people’s private designs and uploads are never shown to the AI on your behalf, and yours are never shown on theirs.
If you connect your own AI assistant to Gradiently over MCP or the API, the data you let it read is handled by that assistant’s provider under its terms, not ours. The AI Policy has more.
Our servers are in Canada, which the European Commission recognises as giving personal data adequate protection. Some of the companies we work with are in the United States.
When personal data leaves the European Economic Area, the United Kingdom or Switzerland for a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where needed), or on the provider’s certification under the EU-US Data Privacy Framework. Ask us for a copy of the safeguards that apply.
| Data | Kept for |
|---|---|
| Account, profile, brands, designs and uploads | Until you delete them or your account |
| Sign-in sessions | Up to 30 days after you last used them |
| Designer requests | About a day in our systems while the work is done. A record of the credits each one spent stays with your account |
| Support requests and reports | Up to 2 years after they are closed |
| Payment, tax and ledger records | As long as tax and accounting law requires, usually up to 10 years, without your profile details once your account is gone |
| Server and security logs | Up to 90 days |
| Backups | Up to 35 days, encrypted, then overwritten |
When you delete your account in Settings, we remove your account, brands, designs and uploads. Marks you hold return to the Market, and Marks you crafted stay listed without your name. A Mark’s ownership history is kept because it is what every later certificate rests on, but it no longer identifies you.
Wherever you live, you can:
- See and download the data we hold about you. Settings has a download of your data.
- Correct anything that is wrong. Most of it you can edit yourself in Settings.
- Delete your account and its data.
- Object to processing we base on legitimate interests, or ask us to restrict it.
- Move your data to another service in a common format.
- Withdraw consent wherever we rely on it, and turn off optional emails.
Use Settings, the privacy request form or hello@gradiently.design. We may ask you to confirm it is you. It is free, and we answer within 30 days. We never treat you worse for using these rights.
European Economic Area, United Kingdom and Switzerland
You also have the right to complain to the data protection authority where you live or work. We would like the chance to put things right first.
United States
If a state privacy law such as California’s CCPA applies to you, you have the rights to know, correct and delete described above, and the right to appeal our answer. We don’t sell personal information and we don’t share it for cross-context behavioural advertising, so there is nothing to opt out of.
Data is encrypted in transit and backups are encrypted at rest. Passwords are stored only as hashes. Access to production systems is limited to the people who need it, and two-step sign-in is available for your account.
No service can promise perfect security. If a breach puts your rights at risk, we tell you and the relevant authority without undue delay, as the law requires.
Gradiently is not for anyone under 16, and we don’t knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
When this policy changes in a way that matters, we email you before it takes effect, with a summary of what changed. The date at the top always shows the latest version.

