Who we are
Fil (fil.design) is operated by Design+Code (“we”, “us”). This policy covers Fil’s website, studio and MCP server: what we collect, why, who we share it with, and the choices you have. We handle personal data under Singapore’s Personal Data Protection Act 2012 and, where they apply to you, the GDPR and UK GDPR.
Questions and requests go to support@designcode.io, which also reaches our data protection officer.
What we collect
- Account details. Your email address. If you sign in with Google, the name, email address and profile picture link that Google shares for basic sign-in; we ask for no other Google access. Your display name is your Google name or, without one, the part of your email before the @.
- What you make. Prompts, canvases and their nodes, files you upload, links you paste (we fetch the public page or image they point to), the text of documents you attach (the document file itself isn’t kept), and everything generated for you: images, video, 3D models, pages, audio and skills.
- Teams. The workspaces you belong to, your role in each, and the email addresses you invite. Invite links are stored only as a hash and expire after seven days.
- Runs and credits. Each run’s model, settings, status, cost and credits, and your credit balances, transfers and history.
- Payments. If you buy a plan or credits, Stripe collects your payment details. We keep your Stripe customer ID, plan, invoices, orders and the payment events Stripe sends us. We never see or store your full card number.
- Agents. Agent keys you create (stored as a SHA-256 hash with their last four characters, name and daily cap), apps you approve over MCP, and a log of each change an agent makes: the app, tool, canvas, run, credits and a short summary.
- Technical data. Our hosting providers record IP addresses, browser details and requests to run and secure the service.
How we use it
- To sign you in, run Fil, and show your work to you and the teammates you share it with.
- To run what you ask for, by sending each run’s inputs to the provider of the model you chose (below).
- To charge and refund credits, bill plans and credit packs, and prevent fraud and abuse.
- To send the email the service needs: sign-in codes and links, and team invitations.
- To keep Fil secure, fix problems and enforce our Terms of Service.
We don’t sell personal data, use it for advertising, or use your prompts and files to train AI models.
AI model providers
When you run a node, its prompt, settings and the references wired into it (images, video, earlier pages and document text) go to the provider of the model you chose. Images usually go as links that expire within an hour; some providers receive the file itself.
- OpenAI: GPT Image images, edits and cutouts, GPT pages and skills, and GPT-4o mini voiceover.
- Anthropic: Claude pages and skills.
- Google: Nano Banana images, Gemini Omni video, Gemini pages, Gemini voiceover and Lyria music.
- xAI: Grok Imagine video.
- Higgsfield: Grok Imagine 2.0 and Soul 2 images, and Seedance, Kling and MiniMax video. Higgsfield may pass requests on to those models’ developers.
- Ideogram: Ideogram images, edits and cutouts.
- Magnific: upscaling and cutouts.
- Tripo and Meshy: 3D models, rigging and animation.
- ElevenLabs: voiceover, sound effects and music.
Fil also uses some of these models itself to help you. Anthropic’s Claude reviews a run’s prompt, settings and up to four reference images before it starts, plans nodes from an Auto prompt, suggests variations, plans a page’s images, checks a 3D reference image, and names canvases from their prompt and a small preview. OpenAI’s GPT Image paints covers for videos, pages and 3D models from their prompts.
Providers can refuse a run under their own safety rules. Each handles what it receives under its own terms and privacy policy, and some keep requests for a limited time to monitor abuse.
Other services we use
- Supabase handles sign-in and stores accounts, the database and your files, in Singapore.
- Netlify hosts the website and runs our server code.
- Stripe processes payments.
- Resend delivers sign-in and invitation emails.
- Google provides Google sign-in and the fonts the site loads from Google Fonts.
- The public Images, Videos and 3D pages load pictures from Aura Assets’ storage and sample 3D models from jsDelivr, which see your IP address as any site you load content from does.
These providers process data for us to run Fil and may be outside your country, including in the United States. Where the law requires it, we rely on their data processing terms to protect these transfers.
What becomes public
What you make is private to your workspace. A team workspace is shared with its members, who can see your display name, your work in that workspace and, while you’re on a shared canvas, your cursor and selection.
If you choose Share to Explore, that file becomes public on Fil’s Images, Videos or 3D pages, with its prompt, model, type and size, the date you shared it and your display name. Anyone can view it and reuse the prompt. Unsharing it, or moving it to the trash, takes it off Explore, but we can’t recall copies others have already saved.
To change your display name, email support@designcode.io.
Cookies and local storage
Fil uses no advertising or analytics cookies and no third-party trackers. Your sign-in session, your preferences (such as theme, recent models and settings) and short hand-offs (such as a prompt you start on the public site, kept for an hour) are stored in your browser’s local storage. Clearing it signs you out.
How long we keep it
- Your account, content and run history: while your account is open.
- Files in the trash: they stay recoverable until your account is deleted, or until you ask us to remove them sooner.
- Sign-in codes expire after an hour, invitations after seven days and MCP approval codes after five minutes.
- Payment records: as long as tax and accounting law requires, even after your account is deleted.
- Server logs: for the limited time our hosting providers keep them.
Deleting your data and your rights
To delete your account, email support@designcode.io from the address you sign in with. Within 30 days we’ll delete your account, your personal workspace and its files, revoke your agent keys and take down anything you shared to Explore. Teams you own are handed to another member if you ask, or deleted. We keep only the payment records the law requires, and copies in backups are overwritten on their normal cycle.
You can also ask for a copy of your data, to correct it, to delete particular files for good, or to stop a use you’ve agreed to. You can download your files from the studio at any time.
Depending on where you live, you may have further rights, such as to object to or restrict how we use your data, or to complain to a data protection authority (in Singapore, the Personal Data Protection Commission). We answer requests within 30 days.
Security
Files are kept in private storage and opened through links that expire. Database rules limit every record to the people who should see it. Server keys for model providers and payments never reach your browser, and agent keys are stored only as hashes. No system is perfectly secure, so keep your sign-in email and agent keys safe, and tell us at once if you think someone else has used them.
Children
Fil isn’t meant for anyone under 18, and we don’t knowingly collect data from children. If you believe a child has given us personal data, contact us and we’ll delete it.
Changes to this policy
We’ll post changes here and update the date at the top. If a change materially affects how we use your data, we’ll tell you by email or in the studio before it takes effect.