Privacy Policy
Effective date: July 22, 2026
This Privacy Policy describes how Cre8tiv Development Group, LLC (“InterfaceGuard,” “we,” “us,” or “our”) collects, uses, and shares information when you use the InterfaceGuard platform, including the web application, API, VS Code extension, Chrome extension, and MCP server (the “Service”). By using the Service, you agree to the practices described here.
1. Information We Collect
Account Information
When you register, we collect your email address, display name, and (optionally) profile photo via Firebase Authentication. If you sign in with Google or another OAuth provider, we receive only the information that provider shares with us.
User Content
The Service stores screenshots and images you upload, along with any design context, annotations, or metadata you attach to a project. Analysis jobs, including the submitted images and the AI-generated results, issues, and recommendations, are stored in our infrastructure for the duration specified by your plan's history retention period.
Usage Data
We automatically collect usage information when you interact with the Service: pages viewed, features used, job submission timestamps, API key usage counts, and error events. This data helps us operate, debug, and improve the Service.
Billing Information
Payments are processed by Stripe. We do not store your full credit card number, CVV, or bank account details. Stripe shares with us a billing token, subscription status, and the last four digits of your payment method for display purposes.
API Keys
InterfaceGuard API keys you generate are stored as one-way hashes. We cannot recover the plaintext value; neither can anyone who accesses our database. If you configure a Bring Your Own Key (BYOK) AI provider key, it is encrypted at rest using a server-side encryption secret before being stored.
Cookies and Local Storage
We use strictly necessary cookies and browser local storage to maintain your authentication session (Firebase Auth tokens). We do not use third-party advertising or tracking cookies. The Chrome extension stores your API key and settings locally on your device using the Chrome Extensions Storage API.
2. How We Use Your Information
- Provide the Service: Process analysis jobs, store results, manage projects and teams, authenticate API requests, and run billing.
- Communicate with you: Send transactional emails (job completion, billing receipts, invitation emails, security alerts). We do not send marketing email without your consent.
- Improve the Service: Analyze aggregate usage patterns to fix bugs, tune performance, and develop new features. We do not use individual User Content to train AI models without explicit opt-in consent.
- Enforce our policies: Detect abuse, rate-limit violations, and fraudulent activity.
- Legal obligations: Comply with applicable laws, respond to lawful government requests, and enforce our Terms of Service.
3. Infrastructure and Sub-Processors
We rely on the following third-party sub-processors to operate the Service:
| Provider | Purpose | Data location |
|---|---|---|
| Google Firebase / GCP | Authentication, Firestore database, Cloud Storage (images & results), Cloud Run (API) | United States |
| Redis (Cloud Run sidecar) | Rate limiting, job queue | United States (same GCP region) |
| Stripe | Payment processing, subscription management | United States |
| Your AI provider (BYOK) | AI analysis when you configure your own API key | Governed by your provider's privacy policy |
| InterfaceGuard AI (platform key) | AI analysis when you use the built-in platform key | United States |
BYOK note: When you configure a Bring Your Own Key AI provider key, your screenshot data and generated prompts are sent directly to your chosen AI provider under your own agreement with them. InterfaceGuard does not intermediate or log these API calls beyond the encrypted key storage described above.
4. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service:
- Analysis jobs and results: Retained for the number of days specified by your subscription plan (visible on the Pricing page). Jobs outside the retention window are automatically purged, including their stored screenshots.
- Account data: Retained while your account exists. After you delete your account, we delete your personal information within 30 days, except where required to retain it for legal or financial compliance purposes.
- Billing records: Retained for at least 7 years as required by applicable tax and financial regulations.
- Server logs: Aggregated and anonymized server logs may be retained for up to 12 months for security and performance analysis.
5. Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest in Firestore and Cloud Storage is encrypted by Google using AES-256
- BYOK AI provider keys are encrypted with a server-side encryption secret before storage
- InterfaceGuard API keys are stored as one-way hashes (bcrypt)
- Firebase Authentication handles password hashing and session management
- Our Cloud Run services run with least-privilege IAM roles
No method of electronic transmission or storage is 100% secure. Please notify us immediately at security@interfaceguard.com if you discover or suspect a security vulnerability.
6. Sharing and Disclosure
We do not sell your personal data. We share data only in the following circumstances:
- Service providers: With sub-processors listed in Section 3 for the purposes described.
- Team members: If you belong to an Organization, other Organization members can see shared projects and jobs. Organization owners can manage team membership and permissions.
- Legal requirements: If required by law, regulation, legal process, or governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to you and subject to the same privacy commitments.
- Protection of rights: To enforce our Terms, prevent fraud, or protect the safety of our users.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data. You can update most profile information from the Settings page.
- Deletion: Request deletion of your personal data. You can delete your account from Settings, which triggers deletion within 30 days.
- Portability: Request an export of your data in a structured, machine-readable format.
- Objection / Restriction: Object to or restrict certain processing of your data.
- CCPA (California residents): You have the right to know what data we collect, to delete your data, and to opt out of the sale of your personal information (we do not sell personal data).
To exercise any of these rights, email privacy@interfaceguard.com. We will respond within 30 days.
8. International Data Transfers
Our infrastructure runs primarily in the United States on Google Cloud Platform. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data is transferred to the United States under Standard Contractual Clauses (SCCs) as authorized by the European Commission, or under other lawful transfer mechanisms.
9. Children's Privacy
The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice in the Service and updating the effective date at the top of this page. We encourage you to review this policy periodically.
11. Contact
For privacy-related questions, requests, or complaints:
Cre8tiv Development Group, LLCInterfaceGuard Platform — Privacy Team
privacy@interfaceguard.com