Privacy Policy
This Privacy Policy explains how Françoise (“we”, “us”, “our”) collects, uses, and protects information when you use our products, websites, and services (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy.
1. Who we are
Françoise is a design quality assurance tool that analyzes Figma-based design systems and mockups to detect visual and system-level inconsistencies.
If you have any questions about this Policy or our data practices, you can contact us at:
Email: [email protected]
2. Information we collect
We collect the following categories of information when you use the Service:
2.1. Account information
- Name (if you choose to provide it)
- Email address
- Role and organization name (if provided)
We use this information to create and manage your account, communicate with you, and provide access to the Service.
2.2. Workspace and usage information
- Workspace metadata (e.g., team or project names/IDs)
- Log data about how you interact with the Service (features used, timestamps, error logs)
- Aggregated statistics about checks (number of checks, types and frequency of violations, model accuracy metrics)
This information helps us operate, secure, and improve the Service.
2.3. Design system and mockup information
To provide the core functionality of Françoise, we process:
- Design system data: tokens, component definitions, rules, configuration and related metadata required to run checks against your design system.
- Mockup content: rendered images of mockups and limited fragments of layout code that are needed to perform a specific check.
We do not intentionally require or collect your own customers’ personal data as part of design checks. If such data appears inside mockups (for example, names or email addresses in UI screenshots), it is processed only as part of the visual content necessary to perform the requested analysis.
3. How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Configure the tool to your design system and run design checks
- Maintain and improve product performance, reliability, and user experience
- Communicate with you about the Service, including updates and support
- Monitor, prevent, and address security issues, fraud, and abuse
- Generate anonymized, aggregated analytics about product usage
We do not use your design system, mockups, layout fragments, or any customer content to train, fine-tune, or otherwise improve our machine learning models.
Use of third-party AI services (Technical Validation & Business Proof)
As part of Technical Validation and Business Proof phases, we may use third-party AI services (such as Google Gemini) to process mockup images and layout fragments strictly for the purpose of running design checks. These services act as our processors and are contractually restricted from using your data for their own model training, in line with their enterprise data protection commitments.
4. Data handling: design systems, mockups, and analytics
4.1. Design system data
Your design system (tokens, components, rules, configuration) is stored solely for the purpose of running checks against it and keeping your configuration consistent over time.
- We do not share your design system with third parties, except with infrastructure providers that host our systems as described in Section 5.
- We will permanently delete your design system data upon your written request or within a reasonable period after contract termination, subject to any legal retention requirements.
4.2. Mockups and layout fragments
Mockup images and layout fragments are processed ephemerally for each check:
- They are used only to perform the analysis and deliver results back to you.
- They are not retained beyond the duration that is technically required to process the check.
Where third-party AI APIs (such as Google Gemini) are used to assist with analysis during Technical Validation and Business Proof, mockup content is transmitted over encrypted channels and processed only to fulfill the requested check, in line with those providers’ enterprise privacy commitments.
4.3. Anonymized analytics
We retain anonymized, aggregated operational statistics, such as:
- Total number of checks
- Distribution of error types
- Tool accuracy and performance metrics
- High-level usage patterns (for example, how often certain features are used)
These statistics do not identify you or your end users and are used only to understand how the product performs and to guide product decisions.
5. How we share information
We do not sell your personal data. We share information only in the following limited circumstances:
5.1. Service providers (subprocessors)
We use third-party vendors to help us operate and secure the Service. These providers act as our processors and are contractually bound to:
- Process data only on our documented instructions
- Apply appropriate technical and organizational security measures
- Not use the data for their own purposes
Examples of such providers include:
- Microsoft Azure (United States): cloud hosting, databases, and related infrastructure services for our backend.
- Google (United States): Google Gemini APIs used for certain AI processing tasks during Technical Validation and Business Proof phases.
We maintain an up-to-date list of subprocessors on a dedicated page on our website.
5.2. Legal requirements and safety
We may disclose information if we reasonably believe it is necessary to:
- Comply with applicable laws, regulations, legal processes, or governmental requests
- Enforce our agreements, including investigation of potential violations
- Detect, prevent, or otherwise address fraud, security, or technical issues
- Protect the rights, property, or safety of our users, the public, or Françoise
5.3. Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to confidentiality obligations and this Privacy Policy (or an equivalent, updated policy that will be communicated to you).
6. Legal basis for processing (EEA/UK users)
Where applicable (for example, under the GDPR or UK GDPR), we process personal data on the following legal bases:
- Performance of a contract: to provide and operate the Service you or your organization have requested.
- Legitimate interests: to secure and improve the Service, prevent abuse, and generate high-level product analytics, provided these interests are not overridden by your rights.
- Compliance with legal obligations: to comply with applicable laws and regulations.
If we ever rely on your consent for specific processing, we will clearly request it and explain how you can withdraw it at any time.
7. Data retention
We retain information only for as long as necessary for the purposes described in this Policy or as required by law.
- Account data: retained for as long as your account is active, and for a limited period thereafter if needed for billing, legal, or legitimate business purposes.
- Design system data: retained for the duration of the contract and deleted upon your written request or within a reasonable period after contract termination, subject to legal retention requirements.
- Mockups and layout fragments: processed per check and not retained beyond what is technically required to perform and deliver that check.
- Anonymized analytics: retained as long as necessary for internal reporting and product improvement; these datasets do not identify individuals or specific customer organizations.
8. Your rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Access: to obtain confirmation whether we process your personal data and receive a copy.
- Rectification: to correct inaccurate or incomplete personal data.
- Erasure: to request deletion of your personal data in certain circumstances.
- Restriction: to request restriction of processing in certain circumstances.
- Objection: to object to certain types of processing (for example, direct marketing or processing based on legitimate interests).
- Portability: to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.
To exercise these rights, contact us at [email protected]. We may need to verify your identity before responding. Some rights may be limited where we have an overriding legitimate interest or legal obligation.
If you believe your rights have been violated, you may also lodge a complaint with your local data protection authority.
9. Security
We use technical and organizational measures designed to protect your information against unauthorized access, loss, misuse, or alteration, including:
- Access controls and least-privilege principles for production systems
- Encryption in transit where applicable
- Logical separation of customer environments at the application level
- Monitoring and logging for security-relevant events
Our backend runs on Microsoft Azure data centers located in the United States, which implement industry-standard physical and infrastructure security controls. A separate Security Overview document provides more details on our security practices.
10. International data transfers
Because we rely on Microsoft Azure and Google Gemini services hosted in the United States, your information may be transferred to and processed in the United States and other countries outside your country of residence.
Where required by applicable law, we implement appropriate safeguards for such transfers, such as standard contractual clauses or equivalent mechanisms, to ensure a level of protection essentially equivalent to that in the EEA/UK.
11. Children’s privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have collected personal information from a child, we will take steps to delete it. If you believe a child has provided us with personal data, please contact us at [email protected].
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If we make material changes, we will notify you through the Service or by email where appropriate.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
Contact
For any questions or requests related to this Privacy Policy or your personal data, please contact: [email protected]