Detos UI
General
Workspace
LEGAL
Last updated 27 September 2026.
DRAFT — this document has not yet been reviewed by a lawyer, and the passages in square brackets are still to be filled in. Do not treat it as final.
The short version: we store what an account needs in order to exist, plus the three answers you give when you sign up and the design work you create. We do not sell it, we do not profile you, and there is no advertising here. What follows is the specific list, taken from the database itself rather than from a template.
[Legal name], [tax ID], [registered address], contactable at [contact email]. If you are in the EU or the UK, that is the data controller.
To have an account: your email address, a cryptographic hash of your password, and whether you have confirmed the address. We never store the password itself and cannot recover it — a reset replaces it.
In your profile: the display name you choose, the address of an avatar image if you upload one, your language preference, and the three answers from the sign-up questions — how you found us, what you do, and what you want to build — plus a free-form field we keep for future questions. The three answers are stored as short codes, not as free text.
About your session: a coarse device label ("Phone" or "Desktop"), your browser's user-agent string, when the session started, when it was last seen, and — if it ended because you signed in elsewhere — when and why. This exists so that one account is one session, which is the rule stated in the Terms.
If somebody invites you: the email address the invitation was sent to, the role offered, who sent it, when it expires, and a hash of the invitation token — never the token itself.
Your work: workspaces and their members, projects, the colours you seed, your palettes and token values, which components you selected, and a frozen copy of every specification you export, together with the settings it was generated from. Those copies are kept deliberately, so that a specification you already used can be looked up again unchanged.
No payment information of any kind, because there is nothing to pay for. No card numbers, no billing address, no tax details. Our own session records hold no IP addresses — only the device label and the user-agent described above.
Detos UI adds no advertising trackers and no analytics of its own. One honest caveat: our hosting providers keep their own server request logs, which do include IP addresses, and we do not control those beyond the retention their platforms apply. [Confirm before publishing whether the site host sets any cookies of its own, and list them here if it does.]
Your email and password hash exist so you can sign in — without them there is no account. Your name and avatar exist so that other members of a shared workspace know who did what. The session record exists to enforce one session per account. The sign-up answers exist so we can tell which channels bring people who actually finish a system, which is the only product question we use them for; they are never sold and never joined to anything outside Detos UI. Your design work is stored because storing it is the service.
The database is hosted by Supabase in the us-east-1 region, which is in Virginia, in the United States. The website itself is hosted by WeWeb. If you are in the European Union or the United Kingdom, that means your data is transferred outside your region, and you should treat that as a deliberate fact about this service rather than an oversight. [Confirm the transfer mechanism — standard contractual clauses — with the providers' current terms.]
If you join a shared workspace, the other members of that workspace can see your display name, your email address and your avatar. This is not optional: a team screen that hid who its members were would be useless. Nobody outside a workspace can see anything inside it — that boundary is enforced by the database, per row, not by the interface.
Three companies process data on our behalf: Supabase (database, accounts and file storage), WeWeb (the website and app you are looking at) and [email provider, once configured] for the confirmation, password-reset and invitation emails. We do not share your data with anyone else, and we have never sold data of any kind.
Signing in stores a session token in your browser's local storage — that is what keeps you signed in, and clearing your browser data signs you out. Alongside it we keep three small things: the identifier of your current session, a colour you saved from the generator before creating an account, and interface preferences such as whether the side menu is open. None of it is used for tracking and none of it leaves your browser except the session token, which goes only to Supabase.
While your account is open, we keep it. When you delete a project, archive a workspace or close your account, it enters a 30-day window in which you can undo it; after that a daily job removes it permanently and we cannot recover it. Exported specification copies live as long as their project does. Invitations expire on their own and are cleaned up with the workspace they belong to.
You can see and change your name, avatar and email from your account settings. You can export your specifications from inside a project. You can close your account from your account settings, which starts the 30-day window described above.
Beyond that, write to [contact email] and we will act on it: a copy of everything we hold about you, a correction, deletion sooner than 30 days, or a machine-readable export. We aim to answer within 30 days. If you are in the EU or the UK and you think we have handled this badly, you can complain to your national data protection authority. [Name the authority for the jurisdiction once it is fixed.]
Detos UI is a professional tool and is not intended for children. We do not knowingly create accounts for anyone under [16]. If you believe a child has an account here, write to us and we will remove it.
The list in section 2 is the part most likely to change, because it changes whenever the product does. If we start collecting something new, this page changes on the same day, and the date at the top changes with it. If the new thing is significant, you will get an email rather than a silent edit.
See also
Terms of ServiceSection 2 was written by reading the database schema, column by column, rather than by adapting a template. If you find something stored that is not on that list, that is a bug in this page and worth telling us about.
A design system for WeWeb, generated from one hex code. Built natively no wrappers, no embeds.
© 2026 Detos UI