Privacy Policy

Effective date: September 1, 2026

Bergside LLC ("Bergside," "we," "us," or "our") operates the TypeUI website, dashboard, design skill registry, prompt catalog, workspace design systems, MCP access, downloadable resources, and related UI prompt resources (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1. Information We Collect

We collect only the information reasonably necessary to provide, secure, bill for, and improve the Service:

  • Account Information: When you create an account, we may collect your email address, name, profile metadata, authentication provider information, avatar URL, and account identifiers.
  • Purchase, Subscription, and Billing Activity Information: When you buy or manage a TypeUI Creative, Insights, or All-access subscription through Stripe Managed Payments or Polar, or redeem a TypeUI offer purchased through AppSumo, we receive or store the purchase, subscription, redemption, cancellation, invoice, payment status, and plan-change information needed to provide access. We keep an action history for checkout attempts, customer-portal sessions, subscription updates, scheduled plan changes, cancellations, payment events, provider synchronization, code status, and related errors. It may include customer, subscription, schedule, checkout, invoice, provider event, internal request, and redemption identifiers; the previous and selected plan; amount and currency; status; timestamps; and a limited error summary. AppSumo codes are stored as keyed cryptographic hashes with a short suffix for support lookup, not as plaintext codes. We do not store full card numbers, raw payment credentials, or raw webhook payloads in this activity history.
  • Entitlement Data: We store information needed to determine whether your account is on Free access, an active Creative, Insights, or All-access subscription, or TypeUI Creative Lifetime redeemed through AppSumo, including status, plan, billing or redemption period, cancellation or deactivation status, usage allowance, and related identifiers.
  • Workspace and Creative Data: We store projects, design systems, brand settings, imported content, publishing settings, saved audits, and requested audit images when you use those features.
  • Authentication and Security Data: We process sign-in, MFA, account recovery, request, security, and abuse-prevention records needed to protect accounts and the Service.
  • Connected Services: If you authorize a supported integration, we process the connection and imported content needed to provide it. For optional Polar, Stripe, and Paddle revenue integrations, an authorized workspace member supplies a scoped, read-only credential. TypeUI sends that credential only from its server to the selected provider, stores it using authenticated encryption in Supabase Vault, and restricts decryption to privileged server operations. We retain normalized revenue facts such as amount, currency, status, time, a short purchased-product label, hashed order and event identifiers, and an optional pseudonymous Insights session reference; we do not retain customer identity, payment-method details, complete line items, raw provider identifiers, or raw provider responses returned during synchronization. The active credential remains encrypted while the integration is connected and is deleted from active storage when it is replaced, disconnected, or its Insights website is deleted. You can disconnect supported integrations from their settings.
  • Product Usage Data: When you use the website, dashboard, prompt catalog, design skill pages, workspace design systems, MCP server, downloads, or copy actions, we may process basic request data such as IP address, approximate country signals supplied by our hosting providers, timestamp, account identifiers, requested resource, usage counts, and browser metadata to deliver the Service, select an available hosted billing provider for new purchases, enforce account-gated access, report usage, prevent abuse, and troubleshoot issues.
  • Essential Cookies and Storage: We use cookies and local storage that are necessary for authentication, account security, fraud prevention, theme and interface preferences, saved privacy choices, and core Service functionality. These technologies cannot be disabled through our preference controls because the affected features cannot operate reliably without them.
  • Optional Website Analytics: After you provide optional analytics consent, we use TypeUI Insights on non-sensitive public pages to understand pathname-level traffic, pseudonymous sessions, engagement, conversion events, product interest, and aggregated UI interactions. Analytics remains disabled unless you accept optional analytics and stays disabled on account, authentication, checkout, billing, dashboard, and private analytics pages. You can change or withdraw this choice through the Cookie preferences link in the website footer. We do not use analytics data to sell personal information.
  • Support and Communications: If you contact us, subscribe to our newsletter, or request support, we may collect the information you choose to provide and records of our communications.

2. TypeUI Insights

TypeUI Insights customers may install the tracker on websites they control. For this service, the customer determines why and how visitor interaction data is processed and is generally the data controller; Bergside processes the data to provide Insights and is generally the processor.

The Insights tracker is designed to collect sessions, pageviews, active engagement time, bounce signals, page-by-page journeys, quantized click locations, rage-click and dead-click signals, device class, browser and operating-system family, approximate country, region, city, and scroll-depth bands associated with opaque site and route identifiers. At session start, the tracker may also record a broad acquisition channel and normalized referring hostname without the referrer path, query string, or fragment. Location, browser family, and operating-system family are derived at Cloudflare's edge; IP addresses and full user-agent strings are not written into Insights analytics or session journeys. The tracker also records normalized URL pathnames, without query strings or fragments, so pages containing the tracker can be discovered automatically. After analytics consent, it creates a random, site-scoped pseudonymous session identifier in local storage. The identifier expires after 30 minutes of inactivity, is transmitted with journey events, and is not reused to recognize a visitor across separate sessions. A separate random page identifier associates time and interactions with one step of the journey.

TypeUI uses available Cloudflare bot signals, rate limits, and conservative automation patterns to protect the collector. Requests identified as automated are excluded before pageview allowance accounting and analytics storage; only an aggregate per-site bot-request count is retained. Connection addresses may be processed transiently to deliver and protect the service but are not written into Insights analytics or bot-request aggregates.

The tracker is not designed to collect persistent visitor IDs, fingerprints, query strings, URL hashes, full referrer URLs or referrer paths, DOM text, CSS selectors, form values, keystrokes, or full user-agent strings. Network providers necessarily process connection data such as IP addresses to deliver requests. TypeUI retains only the derived browser and operating-system family and approximate location in Insights data. Withdrawing consent clears the site-scoped session state and stops collection.

Customers must configure their consent-management platform to load the external tracker only after any consent required by applicable law, honor consent withdrawal, provide required notices, and avoid marking sensitive or prohibited pages for tracking. The tracker also respects supported Global Privacy Control and Do Not Track signals.

A session is counted as live when it recorded activity during the previous 90 seconds. This is an approximate recent-presence signal, not a precise count of identifiable people, and it may be affected by consent, network conditions, browser behavior, and bot filtering.

3. How We Use Your Data

We use the information we collect to:

  • Provide, maintain, secure, and improve the Service.
  • Create and manage accounts, Free access, Creative, Insights, All-access, and TypeUI Creative Lifetime entitlements, plan changes, invoices, cancellations or deactivations, usage reporting, and access to account-gated resources.
  • Process purchases, reconcile provider records, investigate billing errors, provide support, and enforce our Terms of Service and EULA, subject to applicable law.
  • Respond to support requests and send service-related communications.
  • Detect, prevent, and address fraud, abuse, security issues, unauthorized account sharing, and attempts to bypass access controls, subscription checks, or abuse-prevention rate limits.
  • Comply with legal, tax, accounting, and regulatory obligations.

4. Project and Code Privacy

TypeUI provides design skill markdown files and UI prompts for you to use in your own workflow. We do not collect, read, transmit, or store the code, proprietary logic, or files from your local projects.

You may choose to use TypeUI resources with third-party AI coding tools or services. Any code, prompts, files, or other information that you choose to send to those third-party tools is governed by your agreement with those providers, not this Privacy Policy.

5. Data Sharing and Disclosure

We do not sell, rent, or use personal information for third-party advertising. We disclose information only to operate the Service, follow your instructions, complete a business transaction, protect rights and safety, or comply with law.

We use providers for hosting and infrastructure, authentication and application records, billing and tax, communications, customer support, abuse prevention, product analytics, and integrations. This currently includes Vercel, Supabase, Cloudflare, Stripe, Polar, Resend, Crisp, hCaptcha, and user-authorized integrations such as Figma. Providers process information under their own terms and the contractual protections applicable to their role.

TypeUI Insights uses Cloudflare for edge delivery, configuration, immediate aggregate processing, and private snapshot storage. Service providers may process data in countries other than the visitor's country. Where required, we use contractual and other safeguards for international transfers.

6. Data Retention

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

Insights detailed sessions, page journeys, and connected custom events use a rolling 90-day retention period. Aggregate traffic, engagement, and UI-interaction totals remain available while the applicable Insights subscription is active. If Insights access ends, collection pauses and remaining data is held for a 30-day recovery period before automatic deletion. Product-inaccessible recovery copies may remain protected in private Cloudflare storage for up to 32 additional days before scheduled cleanup. The Data Retention page explains these periods in more detail.

7. Legal Bases and Your Choices

Depending on the context and applicable law, we process information to perform our contract with you, operate and secure the Service, comply with legal obligations, pursue legitimate interests that do not override your rights, or act on consent that you may withdraw. You may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to complain to a supervisory authority. These rights are subject to applicable law and may require identity verification. TypeUI Insights customers remain responsible for visitor requests where they act as the controller; our DPA explains our assistance.

8. Security and Service Limitations

We use the safeguards described on our Security page, but no hosted service or third-party provider can guarantee absolute security, availability, or recoverability. Keep independent copies of information you must preserve. The Terms of Service explains applicable disclaimers, liability limits, and mandatory rights that remain available under law.

9. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us.