01 · TL;DR
This notice covers three surfaces, and they do not behave alike. The pages you are reading are a statically generated marketing site: no user accounts, no login, no cookies, no product data. The only telemetry is Vercel Web Analytics, an aggregate pageview counter that sets no cookie and no client-side identifier. There is no advertising and no third-party SDK beyond that.
The documentation at docs.daes.app is the one place where an account exists. It is invite-only while the product is in closed beta, so reading it means signing in, and signing in means one session cookie and an email address held for us by Supabase (§ 06).
The plugin runs inside Figma and talks to the Figma API and to the sync provider you configure. Your tokens do not pass through any server of ours. Beyond the sign-in above, the only personal data processed directly is what you voluntarily send through the contact form, through the early access survey, or by email, plus the standard server logs of the host.
02 · Who's responsible
The data controller in the sense of Art. 4(7) GDPR is:
Represented by Benjamin Zschoche · Dario Iannone · Anna Drewes. The same details, in their statutory form, are on the imprint.
03 · What data exists, and where it lives
There are three surfaces: this site, hosted at www.daes.app, the documentation at docs.daes.app, and the Figma plugin, which runs on your machine. What each one handles:
clientStorage on your machineWe never receive a copy of your tokens. The plugin talks to the Figma API and to the provider you configured; there is no intermediate service in that path.
04 · This marketing site
The pages you are reading (www.daes.app) are statically generated. Apart from the contact endpoint there is no application code and no database. The host (currently Vercel) writes standard HTTP access logs: IP address, user agent, requested path, response code, timestamp. These are held by the host under its own retention policy and used for abuse prevention and security, under Art. 6(1)(f) GDPR (legitimate interest in operating the site).
The site includes Vercel Web Analytics, an aggregate pageview counter. It is cookieless, sets no client-side identifier, and does not use localStorage or browser fingerprinting. Visitors are de-duplicated for the day via a hash of IP and user agent with a daily-rotating salt that Vercel discards; after rotation the hash is unrecoverable. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in basic reach measurement).
The same counter also records a handful of interaction events: a click on a call-to-action, on a GitHub link or on a share button, and a contact-form message that was sent successfully. An event carries only which control it was, where on the page it sat, whether a share was copied or handed to the system share sheet, and which of the fixed topic labels a message was filed under. Nothing you type is attached and the events set no identifier of their own; they travel the same cookieless route as the pageviews above. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in seeing which parts of the site are used).
One further count runs on the server rather than in your browser, because the thing it counts has no browser. The two files written for language models, /llms.txt and /llms-full.txt, record which crawler fetched them (matched against the same list published in robots.txt) and which of the two files it was. No other address on this site is counted this way. The requesting IP address and any cookie header are not passed on; the only thing forwarded is the user-agent string the caller sent, and only in order to name the crawler. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing whether the published material is being read).
Fonts are self-hosted. Next.js downloads Geist and Geist Mono at build time and serves them from this domain, so loading a page makes no request to a font CDN.
05 · Forms on this site
Submitting the form on /contact sends your name, email address, chosen topic, and message to the controller by email over SMTP. The data is used only to answer you. Legal basis: Art. 6(1)(b) GDPR where your message concerns a potential or existing use of the product, otherwise Art. 6(1)(f) (legitimate interest in responding to enquiries).
Both forms are protected by a simple arithmetic question and a hidden field that bots tend to fill in. Neither stores anything in your browser. Messages are kept in the controller's mailbox for as long as the matter needs and are deleted at the latest six months after it is closed, unless the exchange counts as business correspondence, which German tax and commercial law (§ 147 AO, § 257 HGB) requires us to retain for six or ten years.
Providing this data is voluntary; it is required neither by statute nor by contract. Without it your enquiry cannot be answered. You can write to the same address by email instead, with the same effect.
The early access survey on /early-access works the same way. Your answers, your email address and the name you may optionally give are sent to the controller by email over SMTP; they are not written to a database and are not passed to any analytics or marketing tool. They are used to grant you access and to decide what to build next. Legal basis: Art. 6(1)(b) GDPR for the access request itself, and Art. 6(1)(a) for contacting you about it, your consent being given by ticking the box. If you also agree to a short call, that consent covers the call. Either can be withdrawn at any time by writing to contact@daes.app, with effect for the future. Responses are kept for as long as the closed beta runs and are deleted at the latest twelve months after it ends.
While you are answering, nothing is written to your browser: the survey holds your answers in memory only, so leaving the page discards them.
06 · The documentation site
The documentation at docs.daes.app is a separate surface, hosted on Vercel like this site. While the product is in closed beta it is not public: every page requires a sign-in, and the sign-in is handled for us by Supabase.
Access is invite-only, so there is no public sign-up. Signing in means entering the address you were invited with; Supabase then emails you a link that works once and expires shortly, and following it exchanges the link for a session. There is no password to choose and none to store. The form answers the same way whether or not an address is on the list, so it cannot be used to find out who is in the beta.
The data processed is your email address, the timestamps Supabase keeps alongside it (when the account was created, when it last signed in), and the session itself. Legal basis: Art. 6(1)(b) GDPR, because the sign-in delivers the beta access you asked for.
The session lives in a cookie set by our server, not in localStorage. Every page request re-verifies it against Supabase, which is what makes the gate real rather than decorative, and which means Supabase sees those requests the way any authentication service sees them. Because the cookie is strictly necessary to keep you signed in, it needs no consent; § 08 sets out the storage on each surface.
The sign-in exists because the beta is closed, and not beyond it. When the documentation opens to the public there is nothing left to gate, so the accounts, the sessions and Supabase along with them are removed rather than repurposed. Until then, accounts last for as long as the beta runs and are deleted when it ends, or earlier if you ask us to. Signing out ends the session immediately.
The documentation carries no analytics: the counter described in § 04 runs on this marketing site only.
07 · The Figma plugin
The plugin runs inside Figma's plugin sandbox. Your tokens are stored on the Figma file itself. When you connect a sync provider, the access token and repository settings are stored in Figma's clientStorage, scoped to the plugin. Those credentials stay on your machine and are not transmitted to us.
Pushing or pulling tokens is a direct request from the plugin to the provider you configured (for example the GitHub or GitLab API). The plugin does not phone home.
09 · Third parties
The following third parties are involved, either directly or as a result of your own configuration:
Each of these providers acts on our instructions under a processing agreement per Art. 28 GDPR. Those agreements are contracts between us and the provider rather than public documents, but you are entitled to know who is involved, which is what the table above is for.
Transfers outside the EU.Vercel, Namecheap and Supabase are US companies, so hosting, reach measurement, email delivery and the documentation sign-in can involve processing in a third country. Such transfers rest on the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's standard contractual clauses. You can ask us for a copy of the safeguards in place for any one of them by writing to contact@daes.app.
Where this is going. We would rather not rely on that mechanism at all. The stack above is what the closed beta was built on, and we intend to move it to European providers — hosting, mail and sign-in — so that the question of a third-country transfer stops arising instead of being papered over. This paragraph is a statement of intent, not a description of processing: what is listed in the table above is what is true today, and the table changes only when the move actually happens.
If you point the plugin at a remote URL instead of a Git provider, that host sees the plugin's requests in the same way any HTTP server would. Choosing it is your decision, not ours.
10 · Your rights under GDPR
To the limited extent your personal data is processed here, you have the right to:
- Request access (Art. 15)
- Request correction (Art. 16)
- Request deletion (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw a consent you have given (Art. 7(3))
- Lodge a complaint with a supervisory authority. For this controller that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit
One thing here rests on your consent under Art. 6(1)(a) GDPR: being contacted about the early access survey, and the optional call, as described in § 05. You can withdraw that consent at any time with effect for the future by writing to contact@daes.app; what happened before the withdrawal stays lawful (Art. 7(3) GDPR). Everything else rests on contract or on legitimate interest, and where it is legitimate interest you can object under Art. 21 GDPR at any time.
There is no automated decision-making and no profiling in the sense of Art. 22 GDPR. No data protection officer is appointed, because neither Art. 37 GDPR nor § 38 BDSG requires one at this size.
For tokens and files inside your Figma workspace or your repository, those rights are between you and those providers, and we have no access to act on them.
11 · Contact
Privacy questions, deletion requests, or anything else: contact@daes.app. Replies usually take about 24 hours on a weekday.
12 · Changes to this notice
If this notice changes, the version and effective date at the top get bumped. The current version is 1.1, effective 28.08.2026. Every version is listed below, so you can see what you were told and when, rather than having to take the current text on trust: