Privacy policy

Last updated 6 August 2026

Who we are

Eyedropper is operated by Telescope Ltd, a company registered in the United Kingdom (“we”, “us”). Eyedropper builds a design system from your shipped code, an image you upload, or your website, and serves it to AI coding agents, your projects, and your teammates. This policy explains what data we collect to do that, and what we do with it.

What we collect

  • Account details. When you sign in with GitHub or Google, our sign-in provider Clerk receives your name, email address, and avatar from that account. We never see or store a password — there are none.
  • Team details. Your team’s name and its member list, so we can show teammates the same design systems.
  • Design-system data. The tokens, component specs, and related material Eyedropper extracts from the repositories you point it at, plus the files you upload or connect during extraction. Only point Eyedropper at code you have the right to share with us.
  • Analysis inputs. If you build your design system from an image, we process the image you upload; if you build it from your website, we take a screenshot of the address you give us and read the page’s public text. These inputs exist only to run the analysis — the uploaded image or screenshot is deleted from our storage as soon as the analysis finishes, whether it succeeds or fails, and only the extracted design system is kept.
  • Usage data. We use PostHog to record product events (pages viewed, features used) and session replays, so we can see where the product confuses people and fix it.
  • Error reports. When something breaks, Sentry captures a technical report (what failed, your browser, your account identifier) so we can repair it.
  • Payment details. Payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers; we store only your subscription status and Stripe’s reference IDs.

How we use it

To run the service: authenticate you, store and serve your design systems, bill subscriptions, and answer support requests. To improve the service: understand aggregate usage and fix errors. We do not sell your data, and we do not use your design-system data to train AI models or share it with anyone outside the services listed below.

Who processes data for us

We rely on a small set of services (“subprocessors”), each receiving only what its job requires:

  • Clerk — sign-in and team membership.
  • Convex — our database and backend, where your design-system data lives.
  • Vercel — hosts the website.
  • Stripe — payments and subscriptions.
  • PostHog — product analytics and session replay.
  • Sentry — error tracking.
  • Anthropic — the AI model that reads your uploaded image or website screenshot and extracts the design system, used only when you run an image or website analysis. Anthropic’s commercial API terms prohibit training on this data.
  • Firecrawl — takes the screenshot of your website for website analysis, used only when you run one.

Cookies

We use cookies for two things: keeping you signed in (Clerk’s session cookies — essential) and analytics (PostHog). We don’t run advertising or tracking cookies from ad networks.

Retention and deletion

We keep your data while your account is active. Images uploaded for analysis are deleted as soon as the analysis finishes; an upload that never starts an analysis is cleaned up automatically within a couple of days. If you delete your account — or email us at chris@buildgreatproducts.com — we delete your account data and your design-system data from our systems within 30 days, except records we must keep for tax or legal reasons (for example, Stripe invoices). Remember you can export your design system as DESIGN.md and design-tokens JSON at any time, on any plan.

Security

All traffic is encrypted in transit (HTTPS). Access to production data is limited to what operating the service requires. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you without undue delay.

Your rights

Depending on where you live (including under the UK GDPR, the EU GDPR, and the CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Email chris@buildgreatproducts.com and we’ll act on it — you don’t need to cite the statute. If you’re in the UK you can also complain to the Information Commissioner’s Office (ICO); in the EU, to your local data-protection authority.

Children

Eyedropper is a professional tool and is not directed at children under 16. We don’t knowingly collect their data.

Changes

If we change this policy in a way that matters, we’ll update the date at the top and, for significant changes, email account holders before the change takes effect.

Contact

Questions about this policy or your data: chris@buildgreatproducts.com. See also our terms of service.