625+ tools, reviewed by hand

Privacy Policy

What we collect, why, the legal basis for it, and the rights you have.

Last updated: 27 September 2026

This policy explains what personal data thedesigntools.site collects, why we collect it, what legal basis we rely on, who it is shared with, and what rights you have. It is written to meet the transparency requirements of the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA, along with comparable US state privacy laws.

The short version

  • You can read almost all of this site, and use every one of our free tools, without giving us anything at all. No account, no email.
  • We collect an email address if you subscribe to the newsletter, submit something for publication, create an account, or buy something from us.
  • If you make a design tool that launched on Product Hunt, we may email you once, at the company address published on your own website, to invite you to list it for free. No follow-ups, no tracking, and one click stops all contact — see Tool makers we contact first.
  • We sell advertising placements and directory listings. Payments are handled by Stripe — we never see or store your card details.
  • We do not sell your personal information. Nothing that tracks you loads at all unless you opt in, and we treat a Global Privacy Control signal as an opt-out.
  • Our hosting provider keeps standard server logs, as every website does.
  • Some outbound links are affiliate links. These are disclosed, and they never influence our editorial picks.
  • The Jobs board lists roles aggregated from public job-board feeds — applying always happens on that third party’s own site, never ours.
  • We use AI tools to help draft editorial copy. We never send them your email address, your account, or anything you typed into one of our browser tools.
  • You can ask us to show you, correct, or delete your data at any time by emailing hello@thedesigntools.site.

1. Who is responsible for your data

The Design Tools (thedesigntools.site) is the data controller for the personal data described in this policy — meaning we decide what is collected and why. The Design Tools is operated by an individual trader established in Sweden, not a registered company.

Contact for all privacy matters: hello@thedesigntools.site. We reply to every genuine privacy request sent to this address, and treat it as the primary and fastest way to reach us for anything in this policy — including exercising any of the rights in sections 9 and 10.

We have not published a postal address on this page. We’re in the process of setting one up (a registered mailbox, not a home address) to fully satisfy the geographic-address requirement of the EU e-Commerce Directive (2000/31/EC, implemented in Sweden as Lag (2002:562) om elektronisk handel) and the EU Consumer Rights Directive; this section will be updated with it. In the meantime, a postal address can be requested by emailing us for any legitimate legal purpose, including before or after a purchase.

We are a small independent publisher. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR — our processing is limited in scale, is not systematic monitoring on a large scale, and does not involve special-category data.

2. What we collect, why, and on what legal basis

Under GDPR we must tell you the specific lawful basis for each processing activity. Here it is in full.

Newsletter subscription

  • Data: your email address, and the date/time you subscribed.
  • Purpose: to send you the newsletter you asked for.
  • Legal basis: your consent (Article 6(1)(a) GDPR). You give it by submitting the form; you can withdraw it at any time by unsubscribing or emailing us, and withdrawing it does not affect the lawfulness of anything we sent beforehand.
  • Is it required? No. Subscribing is entirely optional and nothing on the site is gated behind it.

Tool submission form

  • Data: the tool’s name, website, category, description, pricing and your stated reasoning — plus your email address if you choose to provide it (that field is optional, though without it we cannot tell you the outcome).
  • Also asked: your connection to the tool (you make it, you work on it, or you use it), so that we only treat makers as makers; and, after you submit, two optional survey questions about what would help your tool. Answers are stored with your submission.
  • Purpose: to assess the tool for inclusion in the directory, to contact you if we have a question, and to tell you when a decision is made or the page goes live. If you make the tool, our automatic confirmation may mention the paid option for getting that same tool listed faster; it is about your submission, and we send nothing else unless you ask for it (see Offers for tool makers below). The email we send when your page goes live explains how to claim it.
  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in curating and maintaining the directory, and in replying to people who contact us. We consider this proportionate because you choose to initiate contact, the data is minimal, and you can ask us to delete it at any time.
  • Is it required? No — only if you want to submit a tool.

Claiming a tool page, and maker replies

  • Data: the email address you claim with, the tool page it is linked to, when you claimed it, a note if you add one, and the replies and fact corrections you send. We email you a one-time link and code to confirm the address.
  • Purpose: to confirm that you speak for the tool, to let you correct facts and publish a reply on its page, and to email you when something you sent goes live. A reply you publish is shown on the page as the maker’s reply; your email address never is.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR) — you asked us to provide the free maker dashboard — and our legitimate interests (Article 6(1)(f)) in checking that only the real maker can speak for a tool.

Offers for tool makers (only if you ask)

  • Data: your email address, and proof of your consent: when you gave it, the exact wording you agreed to, and which form you used.
  • Purpose: occasional emails for tool makers — launch help and sponsorship — at most two a month.
  • Legal basis: your consent (Article 6(1)(a) GDPR), given by ticking a separate, unticked box on a form or in your maker dashboard and then confirming it from the email we send you. Nothing is sent until you confirm. Every email has an unsubscribe link, and you can withdraw at any time.
  • Is it required? No. Submitting a tool, claiming a page and everything else work without it.

Tool makers we contact first

If you make a design tool that launched on Product Hunt, we may write to you once to invite you to list it here. It is the only case where we contact someone who has not contacted us first, so here is exactly how it works.

  • Data: the product’s name, tagline and website as shown on Product Hunt; the company contact address its makers published on that website (a shared inbox such as hello@ or contact@ — never an individual’s personal address, and never a personal mailbox such as Gmail); the page where we found it; and when we emailed it and whether you replied or opted out.
  • Where it comes from: Product Hunt’s public daily and weekly leaderboards, and your own website. We never buy lists or guess addresses.
  • Purpose: to send one email inviting you to list the product in the directory for free. One email per company: we do not follow up, and we do not add you to the newsletter or any other list.
  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in keeping the directory complete and useful to designers. We consider this balanced with your interests because the message is about your own product and professional field, it goes to an address you published for business contact, it is a single message, nothing about it is tracked, and stopping it takes one click. We do not send these emails to companies in countries whose law requires consent even for business email.
  • Your choice: every email has a link that stops all contact from us for good and can also delete what we hold; replying “no” works too. You can ask to see or delete the data at any time (Articles 15 and 17 GDPR), free of charge. This is your absolute right to object to direct marketing (Article 21(2)).
  • Who handles it: Hostinger hosts our mailbox and sends the email. To write one personal sentence, our AI provider sees only public facts about the product (its name, tagline and a short excerpt of its homepage) — never your email address.
  • Tracking: none. The email has no tracking pixel and no redirecting links, so we do not know whether you opened it or clicked anything.
  • How long: we delete the address 90 days after emailing it, unless you reply (a reply is then handled like any other email — see If you contact us by email). To keep our promise never to write again, we keep only your company’s domain and a one-way fingerprint of the address.

Prompt submissions

  • Data: the prompt text you submit and what it is for, plus your email address if you give one.
  • Purpose: to review the prompt for the library and to tell you the outcome.
  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR), on the same reasoning as above. Published prompts are shown without your email address.

Inspiration gallery submissions

The Submit to Inspiration form is the one place on this site where you can upload a file, and where something you send us is published under your name.

  • Data: your name (used as the public credit), your email address (required, and never shown publicly), an optional portfolio or social link that your credit points to, a discipline and description, and either an image you upload or the address of a website you are nominating.
  • Where the image goes: an uploaded image is stored in this site’s own media library on our hosting, and is published on the site if accepted. If you nominate a website instead, no file is uploaded — we ask a third-party screenshot service (thum.io) to capture that public page, and the address of the page is all we send it.
  • Purpose: to review the submission, publish and credit it, and email you the outcome.
  • Legal basis: consent (Article 6(1)(a) GDPR) for publishing your name, credit link and image, which you give through the confirmation box on the form; and our legitimate interests (Article 6(1)(f)) in reviewing submissions and replying to you.
  • Taking it down: email us from the address you submitted with and we will remove it. A website owner who does not want their site in the gallery can ask us the same way, and we remove it without argument.

Designer and agency listings

If you list yourself in the designers & agencies directory, the listing is a public profile that you write and control.

  • Data you publish: your name or studio name, what you do, your region and remote availability, services and disciplines, a description of your work, rates and team size if you choose to state them, showcase images, and links to your website and social profiles. All of this is published deliberately — that is the point of the listing.
  • Data we hold but do not publish: your account email address and your subscription and payment records (see Payments below).
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR) — you asked us to publish and host your listing and we charge you for it.
  • Control: you can edit or unpublish your profile at any time from your account page, and cancelling takes it down at the end of the month you have paid for.

Advertisers and paid listings

  • Data: the contact name and email of the person booking, the business being advertised, the copy, logo and links supplied for the placement, and the purchase record.
  • Purpose: to run the placement, check it before it goes live, let you edit it from your account, and support and invoice you.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR), and our legitimate interests (Article 6(1)(f)) in checking that an advertiser is a fit for our readers before publishing anything.

Accounts and signing in

You only need an account if you buy something from us or list yourself in the designers & agencies directory. Everything else on the site works signed out.

  • Data: your email address, the sign-in method you used, and the times you signed in. If you sign in with Google or GitHub, we receive your email address and basic profile information from them — never your password, and we never ask you for a password to those accounts.
  • Sign-in by email code: if you sign in with a one-time code we email you, the code is short-lived and single-use.
  • Purpose: to let you back into your own campaigns, listings and billing, and to keep other people out of them.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR), and our legitimate interests (Article 6(1)(f)) in keeping accounts secure.
  • Closing it: email us and we will close the account and delete what we are not legally required to keep — see section 8 on retention.

Payments

Everything we sell is paid for through Stripe. The payment page may show the charge as sold through Link, Stripe’s checkout service.

  • What we never have: your card number, CVC or expiry. Card details are entered on Stripe’s own payment form and go straight to Stripe. They never reach our website, our database or our server logs.
  • What we do hold: a record of what you bought, when, for how much, your email address, and Stripe’s identifiers for the customer, payment and subscription. Stripe also tells us the country, card brand and last four digits it recorded, so that support and refunds are possible.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR) to take the payment and provide what you bought; and a legal obligation (Article 6(1)(c)) to keep accounting records, which is why purchase records outlive everything else — see section 8.
  • Stripe’s own role: Stripe processes payments on our instructions, and separately acts as a controller in its own right for fraud prevention, regulatory compliance and its own financial-services obligations. Its handling is governed by the Stripe privacy policy.
  • Transfer: Stripe is a US company with an Irish entity for European customers; transfers outside the EEA and UK rely on the Standard Contractual Clauses and Stripe’s Data Privacy Framework certification. See section 7.

If you contact us by email

  • Data: your email address, your message, and anything else you choose to include.
  • Purpose: to read and answer your enquiry.
  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in responding to people who contact us, or performance of a contract (Article 6(1)(b)) where your message concerns an agreement between us.
  • Retention: correspondence is kept while your enquiry is open and for a reasonable period afterwards for reference, then deleted.

Server logs

  • Data: IP address, browser and device type, pages requested, referring page, timestamps. This is generated automatically by our hosting infrastructure.
  • Purpose: security, abuse prevention, and diagnosing technical faults.
  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in keeping the site secure and functioning. We do not use these logs to profile or identify individual visitors.

Analytics — Google Analytics 4

We use Google Analytics 4 to understand aggregate traffic — which pages get read, roughly how visitors arrive, broad device and country-level trends. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which handles this processing for EEA/UK/Swiss users on Google’s behalf.

  • Data: pages viewed, approximate location (city/country level, derived momentarily from IP — Google Analytics 4 does not log or store your full IP address in reports by design), device and browser type, how you arrived at the site, and how long you spend. This is tied to a randomly generated identifier stored in your browser, not to your name or email.
  • What we have deliberately left off: we have not enabled Google Signals or any ads-personalisation feature in Analytics. Your Analytics activity is not linked to any Google advertising identifier, and it is not used to personalise the ads you see. (Separately, the site shows clearly-labelled Google AdSense ads — see “Advertising — Google AdSense” below — but that service uses its own data, not this analytics data.)
  • Legal basis: your consent (Article 6(1)(a) GDPR and, for the underlying cookies, the Swedish implementation of the ePrivacy Directive). We ask before anything loads — see “How consent works” below.
  • Retention: Google retains event-level data for 14 months on a rolling basis, after which it is automatically deleted, per Google’s default Analytics retention setting.
  • International transfer: personal data processed by Analytics may be transferred to and processed in the United States. This is safeguarded under the European Commission’s Standard Contractual Clauses, which Google incorporates into its data processing terms.
  • Google’s own policy: policies.google.com/privacy.

Advertising — Google AdSense

We show a small number of clearly-labelled advertisements on the site, served by Google AdSense (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This helps fund the directory alongside the affiliate links described in section 5 and the placements we sell directly. Ads are always visually distinct from editorial content and are never disguised as tool listings or recommendations — every paid placement is labelled, and no advertiser can influence what is listed or how it ranks.

  • What AdSense does: Google’s ad systems decide which ad to show based on the content of the page and, for visitors who consent to personalised ads, on your prior browsing activity as known to Google. You can control personalised advertising at any time via Google’s Ad Settings.
  • Data: AdSense sets cookies (for example _gads) and may read existing Google cookies to decide which ads to show, to limit how often you see an ad, and to measure ad performance. This is processed by Google under its own privacy policy — see How Google uses data when you use our partners’ sites or apps; we receive only aggregate earnings reports, not data about individual visitors.
  • Legal basis: the same consent as analytics (Article 6(1)(a) GDPR and the ePrivacy Directive via the Swedish implementation). Outside the EEA, the UK and Switzerland, nothing from AdSense loads until you click Accept on our consent banner, and if you decline no ads are served to you at all. In the EEA, the UK and Switzerland, consent for ads is collected through Google’s certified consent message instead — see “How consent works” below.

How consent works

If you are in the EEA, the UK or Switzerland, we ask through Google’s consent message, a consent management platform certified under the IAB Europe Transparency & Consent Framework, which Google requires for ads shown in those regions. So that it can ask you, this message is loaded from Google (fundingchoicesmessages.google.com) before you choose, on every page except this privacy policy. You can consent, decline with one click, or choose individual purposes and partners. On pages that carry ads, the AdSense script also loads and follows your choice: if you do not consent, Google may still show ads that are not personalised, and where you refuse storage on your device those ads use no cookies. Google Analytics loads only if you consent to analytics in that message, and our own banner is not shown to you.

Everywhere else, no part of Google Analytics or Google AdSense loads for you until you actively click Accept on the banner shown on your first visit. This isn’t just a signal we send to Google asking it to behave — the scripts themselves are not requested from Google’s servers at all unless you accept. If you click Decline, nothing loads — no analytics and no ads — and we remember that choice in your browser (via localStorage, not a tracking cookie) so you aren’t asked again.

If your browser sends a Global Privacy Control signal, we treat that as a decline before we ask you anything: no analytics and no ad scripts are requested, and you are not shown the banner at all. We do not store that as a choice, so if you turn the signal off later the question comes back. You can still opt in by hand using the footer link below.

You can change your mind at any time using the “Privacy and cookie settings” link in the footer of every page, which reopens whichever of the two applies to you. Choosing to decline after previously accepting stops future data collection and clears the Analytics cookies already set in that browser.

3. Cookies and similar technologies

We do not set any cross-site tracking cookies ourselves, and we do not sell personal information. If you consent to analytics, Google Analytics sets the following cookies in your browser, on our domain:

If you consent and ads are shown, Google AdSense may additionally set advertising cookies (for example _gads) on Google’s domains, used to decide which ads you see, to limit how often an ad appears, and to measure ad performance. You can opt out of personalised advertising through Google’s Ad Settings.

Payment and account cookies. On checkout and account pages, Stripe sets its own strictly necessary cookies (for example __stripe_mid and __stripe_sid) to process the payment and detect fraud, and signing in sets a session cookie so that you stay signed in. These are not used to track you across other sites and are exempt from the consent requirement because the service cannot work without them.

Your browser may also hold strictly necessary technical cookies used by our website software (WordPress) to keep the site functioning — for example to maintain a session if you log in as an editor. Under the ePrivacy Directive these are exempt from the consent requirement because the site cannot function without them, and they are not used to track you.

Our own banner does not set a cookie to remember your choice — it’s stored locally in your browser (localStorage) instead, which never leaves your device and isn’t accessible to us or anyone else. Google’s consent message (EEA, UK and Switzerland) records your choice in cookies on this domain (for example FCCDCF and FCNEC) so that you are not asked on every page; these exist only to store that choice.

Tool logos loaded from a third party

Each tool listed in the directory displays that company’s site icon. To avoid storing hundreds of logo files ourselves, these icons are requested from DuckDuckGo’s public icon service (icons.duckduckgo.com) as your browser renders the page.

This means your IP address and browser user-agent are visible to DuckDuckGo when a page containing tool cards loads, in the same way they would be for any externally hosted image. We chose this service specifically because DuckDuckGo does not build advertising profiles from these requests; their handling is governed by the DuckDuckGo privacy policy. No cookie is set by this request, and we receive nothing back about you from it.

Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in presenting a usable, recognisable directory without hosting and maintaining several hundred third-party trademarks ourselves.

Job listings

The Jobs page lists design, product and creative roles aggregated automatically, refreshed at least once a day, from public job-board APIs (including Remotive, Arbeitnow, Himalayas and We Work Remotely) and directly from individual companies’ own public job-board feeds (such as Greenhouse and Lever) — several dozen sources in all. This feature does not collect any personal data about you — it only displays publicly available information about job openings and the companies hiring for them.

Clicking “Apply” on a listing takes you to that job’s original posting — either on the source job board or directly on the employer’s own careers page — which is outside our control and governed by that site’s own privacy policy, in the same way as any other outbound link described in section 5. We are not the employer and not a recruiter, and we never receive your application. As with the tool logos above, some listed companies’ icons are loaded from DuckDuckGo’s public icon service as the page renders.

Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in offering a useful, current jobs resource to visitors, without processing any personal data of the people browsing it.

4. The free tools, and AI

The free browser tools listed on /free-tools/ run entirely on your own device. What you type, paste or open in them is never sent to us. There is a fuller statement at the end of this page.

AI tools we use — and what we never send them

We use an AI language model (currently DeepSeek, with OpenRouter as a fallback provider) to help draft editorial copy: news summaries, first drafts of listing text, and drafts of advertising copy for customers. A person reviews everything before it is published.

What is sent: publicly available material we are writing about — a vendor’s own published description, a public web page, a release note — and business content that a customer has deliberately given us to publish, such as advertising copy or a tool description.

What is never sent: your email address, your account, your payment records, your correspondence with us, server logs, analytics data, or anything you entered into one of our browser tools. None of that ever reaches an AI provider.

We use the providers’ standard API, which is not used to train their models on our inputs. Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in producing editorial copy efficiently, and performance of a contract (Article 6(1)(b)) where we are drafting copy a customer has paid us to produce.

We also use a third-party screenshot service (thum.io) to capture an image of a public website when somebody nominates one for the inspiration gallery. All we send it is the address of the public page.

5. Affiliate links and how we make money

Some links from this directory to a tool’s own website are affiliate links. If you follow one and subsequently subscribe or purchase, we may receive a commission from that company. This costs you nothing extra.

We also earn from the clearly-labelled Google AdSense ads described in section 2, from advertising placements, Maker Verified listings we sell directly, and from monthly listings in the designers & agencies directory. Same rules apply to all of them: they never influence what is listed, how it is described, or where it ranks.

In line with the US Federal Trade Commission’s Endorsement Guides (16 CFR Part 255), we disclose this material connection clearly and close to the links themselves, not only on this page. Affiliate relationships have no bearing on whether a tool is included in the directory, how it is described, or where it ranks — every listing is written with its drawbacks as well as its strengths, and no company can pay to be listed. Where a placement is paid, it is labelled and kept visually separate from editorial listings.

When you click an outbound link you leave our site. The destination operates under its own privacy policy and may set its own cookies. We have no control over, and accept no responsibility for, how third-party sites process your data — we would encourage reading their policy.

How affiliate tracking works

Affiliate programmes are administered by the tool vendor or by an affiliate network acting for them. So that a sale can be credited to us, these networks typically set a cookie or comparable identifier in your browser when you follow one of our links, recording that you arrived from this site. Any such cookie is set by that network, on their domain, after you leave our site — we neither set it nor read it, and we receive only aggregate commission reporting, never your identity.

Where an affiliate link would place such an identifier on a visitor in the EEA or UK, the relevant consent obligation sits with the network under whose domain it is set. If we ever introduce affiliate tracking that runs on our own pages rather than after the click-through, we will gate it behind consent and say so here first.

6. Who we share data with

We do not sell your personal data, and we do not disclose it for anyone else’s marketing. We share it only with the service providers needed to operate the site, each acting as a processor on our instructions and bound by a data processing agreement under Article 28 GDPR — except Stripe, which is also a controller in its own right for the purposes described in section 2.

Hosting — HOSTINGER, UAB

This website is hosted by HOSTINGER, UAB, a company organised under the laws of Lithuania (company code 302710386), registered at Švitrigailos str. 34, LT-03230 Vilnius, Lithuania. Hostinger stores the website, its database and its media, and generates the server logs described in section 2 — including your IP address.

  • Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in providing a reliable, secure website.
  • Data processing agreement: Hostinger’s terms incorporate a data processing addendum governing their handling of personal data on our behalf.
  • Their policy: Hostinger Privacy Policy. Their data protection contact is gdpr@hostinger.com.

Payments — Stripe

All payments are processed by Stripe (Stripe Payments Europe, Limited, Dublin, Ireland, for customers in Europe; Stripe, Inc. in the United States). Stripe receives your card details directly, along with your email address, billing country and the amount, and returns to us only the purchase record described in section 2.

  • Their policy: stripe.com/privacy.
  • Transfer safeguard: Standard Contractual Clauses, together with Stripe’s certification under the EU–US Data Privacy Framework.

Email delivery

Two services send email on our behalf, and both receive the address the message is going to and the content of that message:

  • Hostinger (same company as our host, above) runs the hello@thedesigntools.site mailbox and sends our transactional email — submission outcomes, sign-in codes, receipts and replies — and the one-time invitations to tool makers described in section 2.
  • Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France) sends the newsletter and acts as a fallback for transactional email. Brevo processes data within the EU under its own privacy policy and data processing terms.

Analytics and ads — Google Ireland Limited

Google Analytics 4 and Google AdSense, as described in section 2, and only in line with your consent. Google acts as our processor for Analytics under its own data processing terms; the international transfer safeguard is the Standard Contractual Clauses referenced above. We also use Google Site Kit to read our own Search Console and Analytics reporting inside WordPress; it shows us aggregate figures about the site, not information about individual visitors.

AI providers

DeepSeek, with OpenRouter as a fallback, receive the editorial and customer-supplied business content described in section 4 — and none of the personal data listed there as never sent.

Google reCAPTCHA (forms)

To keep our forms free of spam and abuse, the newsletter, tool-submission, prompt-submission, inspiration-submission and sign-in forms are protected by Google reCAPTCHA v3. reCAPTCHA runs invisibly in the background and does not interrupt you with puzzles.

In the process, Google may process technical data about your device and browser — such as your IP address, cookies and on-page behaviour signals — and sends it to Google for analysis. Google uses that data to judge whether the interaction is human. We rely on our legitimate interest in operating a spam-free site as the legal basis (Article 6(1)(f) GDPR).

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Because the reCAPTCHA badge is hidden, this statement also appears in the site footer.

Everyone else

Separately, and as described in section 3, your browser makes a direct request to DuckDuckGo’s icon service to fetch tool logos. DuckDuckGo receives your IP address as a consequence of that request; it is not something we send them, and we share no other data with them. thum.io receives only the address of a public website submitted to the inspiration gallery.

We may also disclose data where we are legally obliged to — for example in response to a valid legal request — or to establish or defend legal claims. If the site were ever sold or transferred, customer and subscriber records would transfer with it, and we would tell you before that happened.

7. International data transfers

Some of the service providers described above may store or process data outside your country, including in the United States. Where personal data of individuals in the EEA or UK is transferred outside those areas, we rely on an appropriate safeguard under Chapter V GDPR — normally the European Commission’s Standard Contractual Clauses, or the provider’s certification under the EU–US Data Privacy Framework where applicable.

You may request a copy of the relevant safeguard by emailing hello@thedesigntools.site.

8. How long we keep data

  • Newsletter subscribers: until you unsubscribe or ask for deletion, after which your address is removed from the mailing list promptly.
  • Unsubscribe (suppression) records: when you unsubscribe, your address may be kept on a minimal suppression list for the sole purpose of making sure you are not accidentally re-added and contacted again. This is in your interest as much as ours, and rests on our legitimate interests (Article 6(1)(f) GDPR) in honouring your opt-out. It is never used for any other purpose, and you can ask for it to be erased entirely — accepting that we then lose the ability to recognise the opt-out.
  • Maker offers (opt-ins): your address stays on the list until you unsubscribe. The record of your consent, and of your opt-out, is kept for as long as we might need to show it, and at most 3 years after you unsubscribe.
  • Tool makers we contacted first: the contact address is deleted 90 days after our email unless you reply, and addresses we find but do not use are never stored. The company’s domain and a one-way fingerprint of the address are kept only so that we never contact you again.
  • Claimed pages and maker replies: for as long as the tool is listed, or until you ask us to remove them.
  • Tool and prompt submissions: retained while under review and for a reasonable period afterwards to avoid re-reviewing the same submission, then deleted. In practice this means no longer than 24 months.
  • Inspiration submissions: for as long as the image is published, and deleted on request. A declined submission and its image are deleted within 6 months.
  • Designer and agency listings: published while the subscription is active. If you cancel, the profile comes down at the end of the paid month and the content is kept for 12 months so that you can restart without rewriting it — or deleted sooner if you ask.
  • Advertising copy and campaign records: kept for the run of the placement and for 12 months afterwards for support and dispute purposes.
  • Accounts: kept while the account is open, and deleted within 6 months of closure apart from the purchase records below.
  • Purchase, invoice and payment records: kept for seven years, because Swedish accounting law (bokföringslagen) requires it. This is a legal obligation, so a deletion request does not remove these — but they are used for nothing else.
  • Server logs: retained on a short rolling basis by our hosting provider, typically measured in weeks, then overwritten.

9. Your rights if the GDPR applies to you (EEA and UK)

You have the right to:

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted (“right to be forgotten”).
  • Restriction — ask us to limit how we use your data while a concern is resolved.
  • Data portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller.
  • Object — object to processing based on legitimate interests, including at any time and for any reason where the processing is for direct marketing.
  • Withdraw consent — at any time, where we rely on consent.

To exercise any of these, email hello@thedesigntools.site. We will respond within one month, as required by Article 12(3) GDPR. We do not charge for this. The one limit is the accounting records described in section 8, which the law requires us to keep.

Right to complain: if you believe we have handled your data improperly you may lodge a complaint with a data protection supervisory authority — in particular the authority in the EU or UK country where you live, where you work, or where the issue arose. Our own supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se). A list of EEA authorities is published by the European Data Protection Board, and UK residents can contact the Information Commissioner’s Office (ICO). You are not required to raise it with us first, though we would welcome the chance to put things right.

10. Your rights if you are in the United States

Residents of California and of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Texas, Oregon, Delaware, Montana, New Jersey, Minnesota, Maryland, New Hampshire, Nebraska and others — have rights over their personal information. We extend the rights below to all US visitors regardless of state, rather than tracking which law applies to whom.

Categories of personal information we collect

Using the categories defined in the CCPA, in the past 12 months we have collected:

  • Identifiers — an email address, if you provided one; a name, if you submitted something to be credited or listed; IP address via server logs.
  • Commercial information — records of what you bought from us, when, and for how much, if you are a customer.
  • Internet or network activity — pages requested, browser/device type, referring page, via server logs; and, if you consent, analytics and advertising data as described in section 2.
  • Professional information you chose to publish — the contents of a designer or studio listing, or an advertisement, that you asked us to display.

We collect these directly from you (forms, account, checkout), automatically from your device (server logs, and analytics if you consent), and from Stripe for payment records — plus, for the one-time invitations to tool makers, from Product Hunt and your company’s own website. We do not buy personal information from data brokers, and we do not collect sensitive personal information, biometric data, precise geolocation, or information about your employment, education or finances.

Sale and sharing

We do not sell personal information, and we have never done so.

On the question of “sharing” for cross-context behavioural advertising: we do not disclose anything to anyone for that purpose ourselves, and we receive nothing from Google about individual visitors. But if you actively opt in to advertising cookies, Google may then serve personalised ads on the pages that carry them, and under the CPRA that can count as “sharing”. We would rather say so plainly than rely on a technicality. Three things follow:

  • Nothing loads unless you opt in. In the United States no advertising or analytics script is requested from Google at all until you click Accept on our banner. Doing nothing, or clicking Decline, means no ad cookies and no personalised advertising.
  • We honour Global Privacy Control. If your browser sends a GPC signal, we treat it as an opt-out automatically: nothing loads and you are not even asked. This is the opt-out mechanism required by the CCPA/CPRA, applied before the fact rather than after.
  • You can change your mind at any time through the “Privacy and cookie settings” link in the footer of every page, which is also where you withdraw a previous opt-in.

Your rights

  • Right to know what personal information we have collected, the sources, the purposes, and who it was disclosed to.
  • Right to delete personal information we hold about you, apart from records we are legally required to keep.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing — exercised through the consent banner, the footer link, or a GPC signal, as described above.
  • Right to limit use of sensitive personal information — we do not collect any.
  • Right to non-discrimination — we will never deny you service, change the site’s quality, or charge you differently for exercising any privacy right.

To make a request, email hello@thedesigntools.site. We will verify your request by replying to the email address concerned, and respond within 45 days (extendable once by a further 45 days where reasonably necessary, in which case we will tell you). An authorised agent may submit a request on your behalf with written proof of authorisation.

11. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you, and we do not build behavioural profiles of visitors, within the meaning of Article 22 GDPR.

We do use automation editorially — AI drafts copy for review, and software scores submissions for spam and flags them for a human. No decision about a person, a submission, a listing or a refund is made by a machine alone; a person decides, and you can always email us to have any outcome looked at again.

12. Children

This site is aimed at working design professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States), and you must be 18 to buy anything from us. If you believe a child has given us personal data, contact us and we will delete it.

13. Security

We apply reasonable technical and organisational measures appropriate to the limited data we hold — including encrypted connections (HTTPS) across the whole site, access controls on the administrative interface, brute-force protection on sign-in, payment handling delegated entirely to Stripe so that card details never reach us, and keeping the underlying software updated. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever affected your personal data and posed a risk to you, we would notify the supervisory authority within 72 hours and tell you directly where the law requires it.

14. Changes to this policy

If we make a material change — for example naming a new processor, or beginning to use data for a new purpose — we will update this page and revise the “last updated” date above before the change takes effect. Where the change requires your consent, we will ask for it rather than assume it.

15. Contact

For any question, request or complaint about this policy or your personal data:
hello@thedesigntools.site

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.