Privacy Policy
Last updated: July 30, 2026. This revision is effective immediately.
Introduction
Welcome to Brilliant, a professional desktop design tool for macOS, Windows and Linux (“App”). The App is a desktop application that includes features such as auto-layout, components, vector editing, and built-in AI capabilities for creating and modifying designs. Brilliant also offers a cloud publishing service that lets you publish design projects under a public handle, share and discover work, and collaborate (the “Platform”), available through our website, the App, and a command-line tool (the “CLI”). The App, the Platform and the CLI were developed and are owned and operated by Brilliant Design Ltd. (“Company” or “we”, “us”, “our”).
We are committed to complying with applicable data protection laws. This Privacy Policy (“Policy”) explains how we collect and use your personal information when you use our App, the Platform, the CLI or our website, which is available at www.brilliant.design (“Website”).
The App and Website are intended for users aged 13 and older. If you are in the European Economic Area or the United Kingdom, you must have reached the age at which you can consent to the processing of your personal data in your country (up to 16, depending on the member state), or have the consent of a parent or legal guardian. We do not knowingly collect personal information from children below these ages; if we learn that we have, we will delete it.
This Policy may be amended from time to time. If a change is material, we will post the updated Policy on our Website with an effective date at least 30 days after the posting date, and we will also make efforts to proactively notify you of the change. Changes that are not material (for example, clarifications and corrections) become effective on the date they are posted. If you continue to use the App after the effective date of a change, you indicate that you accept the updated Policy. If you do not agree to a change, you may stop using the App prior to the effective date.
Contact us
If you have any questions, comments or concerns regarding this Policy or our processing of your personal information, please email us at privacy@brilliant.design.
What we collect and why
| Scenario | Purposes | Categories of personal information processed |
|---|---|---|
| Creating your account and signing in (App, Platform or CLI) | Providing you with the App and the Platform; securing your account; contacting you with administrative issues concerning the App, this Policy or our Terms of Use | Your email address, the short-lived sign-in code we email you, a device identifier (desktop App), your App version and operating system, and an approximate location (city and country) that we derive from your IP address using a lookup database on our own servers. If you sign in with Google, we receive your email address, name and profile picture from Google; we never receive your Google password. For web sign-ins we keep a session record containing a hashed session identifier, creation and expiry times, and the IP address and browser (user agent) of the device that signed in. |
| Purchasing a paid subscription to the App | Processing your payment; providing you with the App | Your email address, your name and the details of your chosen payment method. |
| Receiving App updates and upgrades | Providing you with the ability to update your App to the latest version or upgrade it | Device and App information. This information will not directly identify you. The App will search for updates and upgrades automatically, but they will not be downloaded and installed automatically without your approval. |
| Using Third-Party AI Agents on the App | Providing you with the functionalities of our App; operating subscription usage limits | The text and/or content you input into the Third-Party AI Agents (“Input”) and any output generated based on your input (“Output”) are transmitted directly from your device to the AI provider you selected, under the BYOK model described in our Terms of Use. We do not receive, store or use your Input or Output. What we do record is usage counts (such as the number of AI messages and token counts) tied to your account, to operate subscription limits. Your chat history is stored only on your device. |
| Creating your Platform profile | Providing your public namespace and profile page on the Platform | Your handle (generated automatically as a random word pair, not derived from your name or email; you can change it), display name, avatar image, bio, company, location text you choose to enter, links you choose to add, and your member number. Your profile page, including all of these plus your public projects, drops, stars and follows, is public. |
| Publishing or syncing a project or drop to the Platform | Hosting your project; serving it according to its visibility; retaining its version history | The design files, images, fonts and other assets in your project; and the project's full version history, including the date and author attribution of each checkpoint. If you push with a git client, the author name and email address recorded in your git commits become part of the project's history. Projects and drops are public by default; anyone can view and clone a public project, including its history. |
| Starring and following on the Platform | Providing the Platform's social features | The projects and drops you star and the users you follow, with timestamps. Stars and follows are public. |
| Collaborating live in a project session | Showing who is present in a live session | Your display name (or handle), avatar and an assigned cursor color are shared with the other signed-in participants of that session. Visitors who open a project page see only a participant count, not identities. Share-link spectators are not shown in the roster. The operations performed during a live session and the resulting materialized session state are stored on our servers as part of providing collaboration, and they become part of the project's saved history. Live sessions expire after a period of inactivity. |
| Importing designs from Figma | Operating the optional Figma import integration | If you connect Figma, we store the access and refresh tokens Figma issues on our servers so the connection keeps working, and we use them only to fetch the files you select from Figma's API. The tokens are limited to read-only scopes. You can revoke the connection at any time from your Figma account. |
| Viewing public content on the Platform | Serving public pages and files; preventing abuse; enforcing rate limits | The IP address from which you access the Platform, requested URLs, and standard request metadata, processed transiently for rate limiting and abuse prevention. When you download the desktop App we record the version, platform, and city and country (derived from your IP on our own servers); the IP address itself is not stored with the download record. |
| Contacting us with an inquiry | Providing you with support in your use of the App, maintaining our customer relations with you | Your email address, the subject and contents of your inquiry, and our communications with you in relation to your inquiry. |
| Use of cookies on the Website | Operating and improving the Website; our business development | Information concerning your use of the Website, e.g., the IP address from which you access the Website, time and date of access, type of device and browser used, language used, links clicked via a mouse or a touch screen, and actions taken while using the Website. |
| AI usage metering | Operating our App and enforcing our agreements | Your user account data, token counts, timestamps, and the AI model used. |
| Analytics | Operating and improving the App; our business development | By default, the App sends anonymous usage events (which features are used, App version, platform, country). These carry only a random per-install identifier, never your design content, your account, or your IP address, and cannot be used to identify you. If you turn on the “Share Detailed Usage Data” setting in the App (off by default), usage events are instead tied to your account (including your email address and city). Anonymous and identified events are stored separately and share no common identifier. On the web, usage events are always anonymous. On the website, a separate, strictly necessary error-monitoring lane reports uncaught errors and the path patterns of failed requests, tagged with a random install identifier, the app version, the platform, and a route class only (never a full URL, page content or design content); it runs regardless of your cookie choices, is rate-limited, and is anonymized on the same schedule as our other anonymous analytics. Analytics events never contain your designs, prompts or file contents. |
| Creating a share link for a private project | Letting you share a private project read-only through a secret link | A share token (a random secret embedded in a short brilliant.design/s/ link) and the private project it grants read access to. The token is a viewer-grade read credential: anyone with the link can view that private project read-only, with no account and no ability to edit. It stays valid until you revoke it, which is permanent, and we record how many times the link has been viewed. |
| Inviting and managing collaborators | Providing and auditing access to a private project or drop | The email addresses you invite as collaborators, the access level you grant, and a record of invitations, changes and removals with timestamps. Invitations that are not accepted expire. |
| Receiving a gifted plan or an invitation | Granting an entitlement or invitation addressed to you | A grant record keyed by your email address, such as a gifted plan or a team or collaborator invitation, with the date and any note. It resolves to your account when you sign in with that email. |
| Booking a demo or contacting sales | Following up on your request | Your name, email address, and anything you choose to tell us when you book a demo or reach out to sales. |
| Processing your subscription payments | Operating billing and keeping it reliable | Billing and subscription event records we receive from our payment processor. Events we could not fully process are kept in full for up to 90 days so we can replay them. Your payment card details are handled by the processor and never reach our servers. |
You do not have a legal obligation to provide the above information; however, if you choose not to share this information with us, you may not be able to create your user account on the App, subscribe to the App with a paid subscription, use the Third-Party AI Agents on the App, or receive updates and upgrades, and we may not be able to handle your inquiry.
When you use the App, the App stores all design files, content, settings, and state information locally on your device. The App accesses content found in your device's clipboard when you copy or paste within the App and captures screenshots of your screen to provide design features and color-picking functionality. The App also accesses your device's accessibility permission to enable window management and global hotkey functionality, and registers system-wide keyboard shortcuts for the purpose of implementing the hotkey functionality. This information is stored locally on your device, and the Company cannot access it. The only design content that ever reaches our servers is content you choose to publish or sync to the Platform, as described in “Publishing on the Platform” below.
The App includes a built-in AI model that runs locally on your device for instant command processing. This local AI model does not send any data to external servers.
Your AI keys stay on your device. When you connect your own AI provider account (BYOK), your API keys and provider credentials are stored only on your device: in the macOS Keychain, in the Windows Credential Manager, or in your browser's local storage when you use the web editor. They are sent only to the provider you connected, directly from your device, and never pass through or reach our servers. This includes the moment we validate a key you enter: that check is a request from your device straight to the provider. Removing a credential deletes it from your device.
Publishing on the Platform
The Platform is a publishing service, and publishing means public. Please understand exactly what becomes public when you use it:
Your profile is public. Your handle, display name, avatar, bio, links, member number, and your public projects, drops, stars and follows are visible to anyone at brilliant.design/your-handle, without an account. Your handle is generated automatically as a random word pair (for example, cozy-cactus). It is deliberately not derived from your name or email address, and you can change it. Your email address itself is never displayed by the Platform. If you hold a paid plan, a blue badge is shown on your public profile and wherever your account appears, so holding a paid plan is publicly visible.
Projects and drops are public by default. Anyone can view a public project, browse its full version history, and download (clone) its complete contents. Certain paid plans include the option to make a project private; private projects are served only to you and the people you invite. Project files may contain whatever you put in them; do not publish personal information (yours or anyone else's) that you do not want public.
Version history is retained. Every checkpoint of a project is kept until the project is deleted. Removing content in a new checkpoint does not remove it from earlier checkpoints. If you publish something by mistake, delete the project and treat the content as having been exposed.
Cloud projects sync continuously. When you are signed in and working on a cloud project, the App and the web editor save your changes to the Platform continuously as you work, not only when you explicitly publish. Synced changes are stored and served under the project's visibility, just like any other content described here.
Git metadata is public. Checkpoints display an author attribution. If you push with a standard git client, the author name and email address configured in your git client are recorded in the commit and served to anyone who clones the project. The App and the CLI manage this for you; if you use raw git, check your git configuration before pushing.
Caching. Public project files at fixed versions and avatars are served with long-lived cache headers, so browsers and intermediary caches may retain copies for a time after deletion. Deletion removes content from our systems on the schedule described under Data retention, but cannot recall copies that others made, or cached copies outside our systems.
Where your content is stored. Published projects and their history are stored in a private Google Cloud Storage bucket and served through our backend on Google Cloud Run. Avatars are stored in a separate Google Cloud Storage media bucket and are public (your profile is public). We do not store separate preview images of your projects: the project cards and previews shown on profile and explore pages are rendered live, in the viewer's browser, from the project's canvas content, under the same visibility rules as the project itself. A project may, however, contain thumbnail files that it generates as part of its own published content (for example under Assets/.thumbs); these live inside the project like any other file and are governed by the project's visibility. Project, profile and session metadata is stored in our MongoDB database. See our Subprocessors page for details.
Methods and sources for collecting your personal information
We collect personal information from several sources:
- Directly from you, when you create a user account on the App, purchase a paid subscription, use Third-Party AI Agents on the App or contact us with an inquiry.
- Directly from you, when you sign in to the Platform, edit your public profile, or publish or sync projects and drops to the Platform (including through the CLI or a git client).
- From Google, if you choose to sign in with Google (your email address, name and profile picture).
- Through the device you use to access our Website, the Platform or the App.
Sharing your personal information
We will not share your information with third parties, except in the circumstances listed below or when you provide us with your explicit and informed consent.
| Scenario | Purposes | Examples of third parties involved |
|---|---|---|
| We will share your information with our service providers who assist us with the internal operations of the App and Website. These companies are authorized to use your personal information in this context only as necessary to provide these services to us and not for their own promotional purposes | Operating the App and Website, and managing our business | Google Cloud Platform (hosting and storage), MongoDB Atlas (database), Resend (email delivery), Paddle (payments), Amazon Web Services (installer downloads), Netlify (status page hosting), Google (Google Analytics). See our Subprocessors page for the full list. |
| When you use Third-Party AI Agents on the App, your Input goes directly from your device to the provider you connected (BYOK) | Providing you with the functionalities of the App | The AI providers you choose to connect (for example Anthropic, OpenAI, Google, OpenRouter). Under the BYOK model (as described in the Terms of Use), your Input is not shared by us: it is transmitted by your device, using your credentials, to the provider you selected. |
| When you publish content to the Platform, or star or follow | Operating the Platform: public content is public by design | Anyone on the internet can see your public profile, public projects and drops (including their full version history), stars and follows. This is disclosure at your initiative, not sharing by us with a specific third party. |
| If you abuse your rights to use the App or the Website or violate any applicable law while engaging with us | Responding to, handling, and mitigating suspected violations of law in connection with our business | Competent authorities, legal counsel and advisors |
| If a judicial, governmental, or regulatory authority requires us to disclose your information | Complying with a binding request from a competent authority | Competent authorities |
| If you are added to a Team plan, the Team Admin can see your seat metadata and aggregate usage counts | Managing seats, billing, and capacity for the Team | The Team Admin and their designated billing contact |
| If the operation of the App or the Website, or our business, is organized within a different framework, or through another legal structure or entity | Enabling a structural change in the operation of the App or Website, and our business. | The target entity of the merger or acquisition, legal counsel and advisors. |
BYOK users have a direct relationship with AI providers. When you use BYOK mode, your data flows directly between your device and the provider. We do not access, store, or process the content of your BYOK interactions.
Team plans
Brilliant offers Team plans where a designated administrator (the “Team Admin”) purchases seats and assigns them to email addresses of their choosing.
If your email is added to a Team, the Team Admin can see: your email address, the date your seat was created, your role (Admin or Member), administrative events related to your seat (invited, role changed, removed, notification resent), and aggregate usage counts tied to your seat (number of AI messages and designs created per billing period).
The Team Admin cannot see: the content of your designs, the text of your prompts, the text of your conversations with AI agents, individual message timestamps, or session-level activity logs.
When you are on a Team plan, the Team Admin's organization acts as the controller of the personal data described above, and we process it on their instruction. Our Data Processing Addendum is incorporated into the Terms for every Team plan and is accepted by the Team Admin at checkout. The current list of subprocessors is referenced by, and incorporated into, the DPA.
If you wish to exercise rights over this data, you may contact your Team Admin or us at privacy@brilliant.design. Requests that concern data controlled by your organization may be subject to the organization's review and approval.
Cookies
When you visit our Website, we use a small number of cookies and similar browser storage technologies. A “cookie” is a text file that websites send to a visitor's device to remember preferences or to measure how the site is being used.
We group the cookies we use on our Website into two categories:
- Strictly necessary cookies. Required for the Website and the Platform to function. One is a single entry in your browser's localStorage that records your cookie preferences so this banner doesn't reappear on every visit; it stores no personally identifiable information. If you sign in to the Platform, we also set a session cookie named brilliant_session, which keeps you signed in. It contains only a random identifier, is scoped to brilliant.design, is not readable by scripts (HttpOnly), is sent only over HTTPS, and expires after 30 days or when you sign out. Team admins who sign in to the team dashboard get a similar cookie named brilliant_team_session. Neither is used for advertising or cross-site tracking.
- Analytics cookies. Help us understand how visitors use the Website in aggregate. We use Google Analytics 4 (property ID G-BB78EDH424), which sets the cookies
_gaand_ga_BB78EDH424, both with a 2-year retention. These are loaded only after you opt in via our cookie banner or the Cookie Preferences page. If you reject or don't answer, Google Analytics is not loaded at all.
You can review, change, or withdraw your cookie consent at any time on our Cookie Preferences page. You can also control and delete cookies through your browser's settings; the exact steps vary by browser, so please consult your browser's help documentation.
We do not use cookies for advertising, re-targeting, or cross-site tracking, and we do not sell information collected through cookies.
Two pages load third-party services that may set their own cookies: the pricing page loads Paddle's checkout script (Paddle is our merchant of record and processes payments), and the demo-booking page embeds Cal.com's scheduler. Those services operate under their own privacy policies; see our Cookie Preferences page for details.
Pages that render a design, such as a project or drop page, load two components from Google's servers: the renderer engine (WebAssembly) from www.gstatic.com, and the renderer's default typeface from fonts.gstatic.com. Your browser requests both directly, on every such page load, before any design is drawn. Your IP address and browser user agent are therefore disclosed to Google, which processes them under its own privacy policy. Further typefaces may be requested from fonts.gstatic.com when a design uses font families or characters the renderer does not already have. These requests set no cookies, and we do not use them for advertising or tracking. The fonts used on our other web pages are served from our own servers and do not contact Google.
Data retention
We will retain your information for as long as you are an active user of the App.
We do not retain your Input or Output on our servers, and your AI chat history is stored only on your device. We do not retain design content on our servers unless you publish or sync it to the Platform. When you publish or sync a project or drop, we store its design files, assets and full version history on our servers for as long as it exists, as described in “Publishing on the Platform” above.
For the Platform specifically: deleted projects and drops are made immediately inaccessible and are permanently deleted from our systems within 30 days (this window also allows support to recover an accidental deletion). When you change your handle, your old handle keeps redirecting to your new one until someone else claims it, and for 30 days only you can reclaim it. If you delete your account, your account data and your published projects and drops are permanently deleted on the same 30-day schedule. Web sign-in sessions expire after 30 days, or when you sign out. Sign-in codes are short-lived and single-purpose. Temporary Figma import relay files are deleted within 24 hours.
Anonymous analytics events are anonymized after 90 days: the random install identifier, session identifier and client timestamp are removed, and the remaining timestamp is coarsened to the day. Identified analytics events (collected only if you opt in to sharing detailed usage data) are automatically deleted 365 days after they are recorded.
Thereafter, we will continue to retain your personal information as necessary to comply with our legal obligations, resolve disputes, establish and defend legal claims and enforce our agreements.
Data security
We maintain administrative, technical, and organizational safeguards designed to protect your personal information. These measures include encryption of data in transit (HTTPS/TLS), storing web session identifiers only as cryptographic hashes, the configurable permission model for actions by Third-Party AI Agents (allowing you to require per-action approval for system-level operations), and the ability to limit, deny or interrupt any action at any point. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure your personal information, there is no guarantee that it will be immune from information security risks.
Third-Party AI Agents
The App allows you to access and use Third-Party AI Agents, as further described in our Terms of Use. The Inputs you submit to Third-Party AI Agents and any related metadata (including any personal information that may be included therein) will be transmitted to and processed by the third-party providers in accordance with their own privacy policies. Those third-party providers' policies apply in addition to, and are separate from, this Policy, and we do not control, and are not responsible for, the privacy practices of such third-party providers.
Your rights
As a user of our App and Website, you have the following rights in relation to your personal information:
- Right to review your information. You have the right to review, either by yourself or through an authorized representative or a guardian, any information we have stored about you in our databases.
- Right to request to rectify your information. If, upon reviewing your information, you find your information to be incorrect, incomplete or outdated, you have the right to ask us to rectify your information or delete it. We will inform you within 30 days whether we can comply with your request.
- Right to have your personal information deleted, under certain circumstances, such as when the information is no longer necessary for the purposes the information was collected for.
Deleting your account. You can delete your Brilliant account yourself, at any time, from your account settings. Deletion asks you to confirm before anything is removed. When you confirm, you are signed out of all devices and sessions, and your account data and the projects and drops you published are permanently deleted from our systems within 30 days, on the same deletion schedule described under Data retention above. Deletion cannot recall copies of public content that other people made while it was public. You can also email privacy@brilliant.design and we will delete your account for you.
Additional Information for Individuals in the EEA and UK
Data Controller. Brilliant Design Ltd. is the controller of your personal information processed on the App and the Website. Our address is 41 Hasimcha st., Kfar Yona, Israel 4034463.
International data transfers. To facilitate processing your information through the App and Website, and by our service providers, we will transfer your information to and within countries outside the EU or the UK, such as Israel. We do so under an adequacy decision or under the terms of a data transfer agreement that contains standard data protection contractual clauses with adequate safeguards determined by the EU Commission and the UK Information Commissioner's Office.
Legal basis for processing your personal data. We process your personal data based on the following legal bases:
| Purpose or Scenario | Legal Basis |
|---|---|
| Creating a user account on the App | The performance of our terms of use contract with you. |
| Purchasing a paid subscription to the App | The performance of our terms of use contract with you. |
| Receiving App updates and upgrades | The performance of our terms of use contract with you; our legitimate interest in providing you with the updates and upgrades to the App. |
| Using Third-Party AI Agents on the App | The performance of our terms of use contract with you; our legitimate interest in providing you with the functionalities of our App and in the operation and improvement of the App. |
| Contacting us with an inquiry | Our legitimate interest in providing you with support in your use of the App and maintaining our customer relations with you. |
| Use of strictly necessary cookies on the Website | Our legitimate interest in the proper operation of the Website. |
| Use of optional cookies on the Website | Your consent. |
| AI usage metering | The performance of our terms of use contract with you and our legitimate interest in the operation of the App. |
| Signing in to the Platform and maintaining your session | The performance of our terms of use contract with you; our legitimate interest in securing user accounts. |
| Hosting and publicly serving projects, drops, profile information, stars and follows you choose to publish | The performance of our terms of use contract with you. Publishing is at your initiative: you choose what to publish, and published content is public by design. |
| Processing IP addresses and request metadata of Platform visitors for rate limiting and abuse prevention | Our legitimate interest in protecting the Platform from abuse and keeping it available. |
| Analytics | Your consent; our legitimate interest in developing and enhancing our business and the App. |
| Sharing your data with our service providers | Our legitimate interest in the proper operation of the App and Website, and our business. |
| Routing your Input to AI providers | Our legitimate interest in providing you with the functionalities of our App. |
| Responding to, handling, and mitigating suspected violations of law in connection with our business | Our legitimate interest in defending and enforcing against violations and breaches that are harmful to our business. |
| Complying with a binding request from a competent authority | Our legitimate interest in complying with mandatory legal requirements imposed on us. |
| Enabling a structural change in the operation of the App or the Website, and our business | Our legitimate interest in our business continuity. |
Data subject rights. If you are in the EEA or the UK, you have the following rights:
- Right to Access and receive a copy of your personal information that we process.
- Right to Rectify inaccurate personal information we have concerning you and to have incomplete personal information completed.
- Right to Data Portability, that is, to receive the personal information that you provided to us, in a structured, commonly used, and machine-readable format. You have the right to transmit this data to another person or entity. Where technically feasible, you have the right to have your personal information transmitted directly from us to the person or entity you designate.
- Right to withdraw your consent to processing your personal information, easily and at any time, if the basis for our processing is your consent. We may continue to process personal information with respect to which your consent is not necessary. Withdrawing your consent will not affect the lawfulness of the processing we carried out based on your consent before such withdrawal.
- Right to Object to our processing of your personal information based on our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or if we need to process such personal information for the establishment, exercise, or defense of legal claims.
- Right to Restrict us from processing your personal information (except for storing it): (a) if you contest the accuracy of the personal information (restriction applies only for a period enabling us to determine the accuracy); (b) if the processing is unlawful and you prefer to restrict rather than delete; (c) if we no longer need the personal information but you require it for legal claims; or (d) if you object to our processing based on our legitimate interest (restriction applies only for the period enabling us to determine whether our legitimate grounds override yours).
- Right to be Forgotten, under certain circumstances, such as when you object to our processing based on our legitimate interest and there are no overriding legitimate grounds. However, we may still process your personal information if necessary to comply with legal obligations, or for the establishment, exercise, or defense of legal claims. If you wish to exercise any of these rights, please contact us through the channels listed in this Policy.
When you contact us with a request, we reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. If we are unable to provide you with the information that you have requested, we will explain the reason.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then pursuant to Article 77 of the GDPR, you may lodge a complaint with the supervisory authority in the Member State of your residence, place of work, or place of an alleged infringement of the GDPR.
If you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO).
Additional Information for Individuals in the United States
Brilliant Design Ltd. is providing the following additional information to its clients residing in the United States, pursuant to applicable state privacy laws in the U.S.
We do not sell your information to any third party, or share it for cross-context behavioral advertising. Furthermore, we do not share or sell sensitive information.
We keep the personal information specified below for the periods described above under the “Data Retention” section. Following these periods, we shall ensure that the information is not accessed, except in extraordinary events such as legal disputes.
Categories of personal information we collect and process and their sources
| Categories of personal information | Details of the personal information that was collected | Sources of information |
|---|---|---|
| Identifiers | Name, email address, IP address, Platform handle, display name, avatar | Directly from you. Through the device you use to access our App and Website. |
| Commercial information | Payment details | Directly from you. Through the device you use to access our App and Website. |
| Other information that identifies, relates to, describes, or is capable of being associated with, a particular individual | Your inquiries, and content you publish to the Platform (design files, assets, version history and profile information, which are public by design). Your Inputs to Third-Party AI Agents go directly from your device to the provider you connected and are not collected by us. | Directly from you. Through the device you use to access our App and Website. |
| Internet or other electronic network activity information | Data collected by cookies, device data, AI usage metering | Directly from you. Through the device you use to access our App and Website. |
| Sensitive information | Account credentials | Directly from you. Through the device you use to access our App and Website. |
Business purposes for the collection of personal information
| Categories of personal information (per the table above) | Business purposes |
|---|---|
| Identifiers Commercial information Other information that identifies, relates to, describes, or is capable of being associated with, a particular individual Internet or other electronic network activity information Sensitive information |
|
Disclosures to third parties
| Categories of personal information (per the table above) | Categories of entities we give the information to, and why |
|---|---|
| Identifiers Commercial information Other information that identifies, relates to, describes, or is capable of being associated with, a particular individual Internet or other electronic network activity information Sensitive information |
|
Your rights
- The Right to Know. You have the right to know whether we are processing your personal information. If we are, you have the right to know: The categories of personal information we collected about you; The categories of sources from which the personal information was collected; The purposes for which we collect personal information; The categories of third parties with whom we share personal information; The specific pieces of personal information we collected about you.
- The Right to Obtain a Copy of Your Personal Information. If your data is available in a digital format, you have the right to obtain a copy of the personal information we hold about you in a portable and readable format (to the extent this is technically feasible).
- The Right to Delete Your Personal Information. In some cases, state privacy laws provide for the right to request the deletion of your personal information.
- The Right to Correct Inaccurate Personal Information. Once we receive a request from you to correct your data and verify your identity, we will examine the veracity of the corrected information you provided, consider your request to correct, and inform you of our decision. To establish the veracity of the personal information as per your request, we will consider all circumstances pertaining to the personal information for which correction is requested. We may also require you to provide documentation in support of your request to correct the personal information.
- The Right to Opt Out of Processing for Solely Automated Profiling. You have the right to opt out of solely automated processing of your personal information to evaluate, analyze, or predict your personal aspects related to your economic situation, health, personal preferences, interests, reliability, behavior, location, or movements, where that processing is done in furtherance of a decision that produces a legal or similarly significant effect on you.
- The Right to Non-Discrimination as a Result of Exercising Your Rights. You have the right not to be discriminated against by us for exercising the rights granted to you under applicable law. If you exercise your rights, we cannot: deny you services; charge different prices or fees for services, including through discounts, benefits, or fines; provide you with a different level or quality of services; propose that you receive different prices or tariffs for services. Please note that we may charge a different fee or provide a different level or quality of services if the difference is reasonably related to the value we gain from your personal information.
Filing Requests
Should you wish to exercise your rights under applicable laws as specified above, please contact us by email at privacy@brilliant.design.
To verify your identity, we will ask you to provide additional information through a verification process in which you will be asked to provide us with two items of information known to you and to us.
Note: you may appoint an authorized agent to file requests to exercise your rights on your behalf. To this end, you must provide your authorized agent with written approval to do so. The authorized agent will have to present us with proof attesting that you authorized them to act on your behalf. Furthermore, we will require verification of your identity, as explained above.
Our Response to Your Requests
We will respond to your requests within 45 days (or within 90 days, where the law permits and we determine it necessary considering the complexity and number of the requests you have filed). If we take longer than 45 days, we will inform you of the extension within the initial 45-day response period, together with the reason for the extension.
Please note that any changes to your personal data that is controlled by your organization (including its deletion) will be subject to your organization's review and approval.
We may deny your request in the following cases:
- If we believe in good faith, based on reasons that are documented in writing, that your request is fraudulent or an abuse of your rights under applicable law.
- If we conclude that the request is irrelevant, based on all the circumstances at issue (e.g., if you requested to correct your personal information, and we find that it is likely to be accurate).
- If it is contrary to federal or state law.
- Due to a discrepancy in the required documentation.
- If the fulfillment of your request turns out to be impossible or involves disproportionate effort.
We will provide you with a detailed explanation including sufficient facts to enable you to meaningfully understand why we cannot fulfill your request.
You may appeal our decision to deny your request by submitting a written appeal to us at privacy@brilliant.design.