Privacy Policy
Version 1.0 · Effective date pending publication
See also: Terms of Use · Cookie Policy
1. Who we are and how to contact us
Isotop is operated and provided by Island AI Ltd (the “we”, “us”, “our”), the controller responsible for your personal data.
- Company: Island AI Ltd — Commercial/Business License No. 07101832, established in Ras Al Khaimah, United Arab Emirates.
- Registered address: Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Riffa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates.
- Contact for privacy questions and to exercise your rights: support@isotop.app (you may also use the in-product support form, which reaches the same team).
For paid purchases, Polar acts as the merchant of record (see §7); Polar is a separate party with its own privacy notice.
2. About this Privacy Policy
This policy explains what personal data we process when you use Isotop — our web application at isotop.app, our Figma plugin, and their features including the Collider AI assistant — why we process it, who we share it with, how long we keep it, and the rights and choices you have.
Isotop is available globally, with no country-specific targeting, and is intended for users 18 and older (see §12). It serves both individual and business/professional users.
3. The personal data we process, and why
We process the categories below to provide and operate the Service you use. For each, we note whether it is required to use the relevant feature. This section reflects the actual data flows in the product.
a. Account and authentication
- What: your name, email address, and (for email/password sign-up) a password. Passwords are handled by Firebase Authentication and are never stored by Isotop. We also hold a Firebase user ID, an email-verification flag, and account timestamps.
- Google sign-in: if you choose “Continue with Google”, we receive your email and display name from your Google account through Firebase Authentication to create or sign you in.
- Why: to create and secure your account, verify your email, and sign you in.
- Required? Yes, to have an account.
b. Profile and onboarding
- What: optional profile and onboarding details you choose to provide (for example, display name, business role/segments, onboarding answers).
- Why: to set up and personalize your workspace.
- Required? Optional.
c. Figma plugin and device pairing
- What: when you connect the Isotop Figma plugin, we create pairing and session records and issue access/refresh tokens (we store only hashes of these tokens, not the tokens themselves).
- Why: to link the plugin to your account and keep you signed in on that device.
- Required? Required to use the plugin.
d. Design-system content
- What: the design-system data and design content you create, upload, or process (including content read from and written to your Figma files in response to your actions, and any images/media you upload).
- Why: to provide the core design-system features and to store and display your work.
- Note: uploaded media is served from stored download URLs. Some stored files may be accessible to anyone holding the file’s URL; do not upload content in media you do not want shared by link.
e. Collider sessions and autosave
- What: your Collider session data — the session state and its chat history — is automatically saved when you are signed in and have made progress in a session.
- Why: so you can recover, reopen, and continue your work (continuity and recovery).
- Your control: you can delete a saved session using the in-product session-deletion controls; deleting a session removes that session’s stored data (including its chat and the AI replay cache for that session).
f. AI processing (Collider)
- What is sent to the AI provider: to generate suggestions, Collider sends the relevant prompt, your questions/answers thread, and design-system context to our AI provider (Anthropic). The content sent to the provider does not include your account identifier or email address.
- Provider commitments (Anthropic’s published terms): Anthropic states that it does not train its models on customer content, that customer content is treated as confidential, and that standard API inputs/outputs are automatically deleted within 30 days (subject to legal/safety exceptions); a data-processing addendum with standard contractual clauses applies. These are Anthropic’s commitments, cited from its published terms.
- Your responsibility: AI output can be inaccurate and should be reviewed before you rely on it; do not submit credentials, secrets, or highly sensitive/regulated data to AI features unless the Service expressly supports it.
g. AI operational logs
- What: we keep operational metadata about AI operations (usage, health, timing, categorized errors) to run and debug the Service. By default we do not store the content of your prompts or the model’s outputs — logging runs at “Level 1” (metadata only).
- A governed debug mode can be temporarily enabled by an administrator to capture redacted prompt/output payloads for troubleshooting; when used it is reason-logged, time-limited, access-logged, and the payloads are deleted on a short schedule. It is off by default in production.
h. Billing and subscriptions
- What: your subscription status and billing records (plan, status, customer and subscription identifiers, and a ledger of billing events received from the payment provider).
- Payment: purchases are processed by Polar as merchant of record. We do not receive or store your full card details.
- Why: to provide paid features, manage subscriptions, and keep the accounting records we are required to keep.
i. Credits
- What: your AI-usage credit balance and a per-operation usage ledger.
- Why: to meter AI usage. Credits are a usage allowance with no cash value; see the Terms.
j. Support requests and forms
- What: the content you submit through the in-product support form or other site forms (for example, a message and any fields you fill in).
- Where it goes: support-form submissions are relayed to our internal support channel (an internal Telegram relay operated for us). Site forms may only submit to Isotop’s own endpoints.
- Why: to receive and respond to your request.
k. Transactional email
- What: we send account emails (verification, password reset, account changes, welcome) to your email address, via Resend.
- Why: to operate your account and security. Marketing email is not part of the Service.
l. Cookies, analytics, and anti-abuse technologies
- Strictly necessary: a session cookie (
__session) to keep you signed in, and a consent-preference cookie (isotop-consent). - Analytics (consent-based): Google Analytics loads only if you consent; if you withdraw consent, analytics is disabled and controllable first-party analytics cookies are cleared.
- Anti-abuse: Google reCAPTCHA and Firebase App Check help protect the Service from abuse.
- Fonts: when previewing a design system, the app may request the relevant font family from Google Fonts so the preview renders correctly.
- Full details are in our Cookie Policy.
m. Security and server logs
- What: our servers and functions keep operational logs (for example, request identifiers, route, status, and timing). We minimize personal data in logs — for example, recipient email addresses are not written to our email-sending logs.
- Why: to operate, secure, and troubleshoot the Service.
4. Our legal bases for processing
Where data-protection law requires a “lawful basis,” we rely, depending on the activity, on: performance of our contract with you (to provide the Service and features you request — e.g. accounts, plugin, Collider, billing); our legitimate interests (to secure the Service, prevent abuse, and keep it working); compliance with legal obligations (e.g. keeping billing/accounting records); and your consent (e.g. analytics cookies, and any optional feature that asks for it). Where we rely on consent, you can withdraw it at any time.
6. AI features in detail (Collider)
- Collider uses Anthropic to generate design-system suggestions from the prompt and context you provide.
- The content sent to Anthropic does not carry your account ID or email.
- By default we do not store the content of prompts or outputs (Level-1 logging, §3g).
- Anthropic’s published commitments (no model training on customer content; ~30-day standard deletion; DPA/SCCs) are described in §3f and are Anthropic’s own terms.
- You are responsible for reviewing AI output before relying on it, and for not submitting secrets or sensitive/regulated data to AI features unless supported (see the Terms).
7. Service providers and sub-processors
We share personal data with providers who process it on our behalf to run the Service, under contracts that limit their use of it. We do not sell your personal data and do not share it for cross-context behavioral advertising (§13).
| Provider | Purpose | Role |
|---|---|---|
| Google / Firebase | Authentication, database (Firestore), file storage — the data tier | Processor |
| Application hosting | Runs the Isotop web application and its server logs | Processor |
| Anthropic | AI generation (Collider) | Processor (per DPA) |
| Resend | Transactional email delivery | Processor |
| Polar | Payment processing as merchant of record | Merchant of record / independent party |
| Google reCAPTCHA / Firebase App Check | Abuse prevention | Processor |
| Google Fonts | Font rendering for design-system previews | Processor (functional request) |
A current sub-processor list is maintained internally and will be published/kept available.
8. International data transfers
Island AI Ltd is established in the United Arab Emirates. Because we use the global providers listed in §7, your personal data may be processed in countries outside the UAE (for example, our AI provider Anthropic operates from the United States, and our infrastructure providers operate in one or more regions).
Where a provider transfers data across borders, it does so under its own transfer terms — for example, Anthropic’s data-processing addendum incorporates standard contractual clauses.
9. How long we keep your data
We keep personal data only as long as needed for the purposes above, then delete or anonymize it, subject to records we must keep by law. Our approved retention schedule includes:
| Data | Retention |
|---|---|
| Account, profile, design-system content | For the life of your account (until you delete it) |
| Collider sessions & chat | Until you delete the session or your account |
| AI operational logs (metadata) | Up to 90 days, then deleted |
| AI debug payloads (when the governed mode is used) | Up to 30 days, then deleted |
| Collider AI replay cache | Up to 90 days, then deleted |
| Plugin auth tokens/sessions/pairings | Removed on expiry/logout by a scheduled clean-up |
| Billing / accounting records | Retained as required for legal and accounting purposes, then deleted or anonymized |
Time-based deletions are enforced by scheduled clean-up jobs.
10. Your privacy rights and choices
Subject to the law that applies to you, you may have the right to access your data, receive a copy (portability), correct it, delete it, object to or restrict certain processing, and withdraw consent.
- Access / export: you can export your account-controlled data from within the Service (a self-service download that includes your identity, Collider, design-system, plugin-session metadata, and your own billing records).
- Deletion: you can delete your account from the Service’s Privacy & Security settings (this re-verifies your identity, then erases your account-controlled data and deletes your login). Some records — for example billing/accounting — may be retained where required by law, and copies held by providers are handled under their terms.
- Other requests (correction, restriction, objection): contact support@isotop.app.
- How we respond: we aim to respond to rights requests within 30 days, extendable where the law allows.
- Complaints: you may have the right to complain to a data-protection authority.
11. How we protect your data
We use technical and organizational measures including: transport encryption (HTTPS/TLS); Firebase Authentication for identity; database and storage access rules that restrict writes to authorized staff and reads to the appropriate scope; abuse protection (reCAPTCHA, App Check); and minimization of personal data in logs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children
The Service is intended for people aged 18 and older and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact support@isotop.app and we will address it.
13. No sale of data; no advertising
We do not sell your personal data, do not share it for cross-context or targeted advertising, and have no advertising business model. Your data is used only to provide and operate the Service and goes only to the functional providers in §7.
14. Changes to this Privacy Policy
We may update this policy. Each version will carry its own version identifier and effective date, and we will provide notice of material changes by a reasonable means.
15. Applicable law and how to raise concerns
You can raise any privacy concern with us at support@isotop.app, and we will work with you to resolve it.
16. Contact
Island AI Ltd — Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Riffa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates. Privacy contact: support@isotop.app.