Privacy policy
Last updated Written from the running product, not a template.
This policy describes what Wraith collects when you visit wraithhq.com, ask for access, sign in to the client portal, or use the subscription. It is written against what the software actually does. Where the product has no defined policy yet, this page says so rather than describing one that does not exist.
Who we are
Wraith is a productized design service operated by Tethys. Tethys is the controller of the personal data described here. For anything in this policy, including a request to see or delete your data, write to hello@wraithhq.com.
What we collect and why
Four surfaces collect personal data: the public site, the request-access form at /start, the client portal, and billing. Nothing else on the site collects anything about you.
The request-access form
Submitting the form at /start stores one row with the following. Name, email and company are required; the rest is optional or captured automatically.
- Name, email, company
- So a designer can read your request and reply to you. The reply itself is a human email, not an automated sequence.
- What you need
- The free-text description of the design work you are asking about. Please do not paste confidential material into it; a mutual NDA can be signed before any real work starts.
- Plan interest
- Studio or Scale, if you arrived from a specific pricing card. Used to shape the reply.
- How you heard about us
- The optional self-reported answer, plus the free-text detail if you choose "Something else". A large share of referrals arrive with no referrer at all, so asking is the only way to know.
- Attributionutm_* / referrer / landing path
- Any utm_source, utm_medium, utm_campaign, utm_content and utm_term on the first page you landed on, the referring site if it was not us, and the path you landed on. This measures which channels work. Referrers from our own domain are discarded, because an internal hop is not a source.
- Page variant
- Which landing-page variant the call to action was clicked on, so we can tell which version of the page works better.
Your account and workspace
- Account
- Name, email address, and either a hashed password (we never store the password itself) or a link to your Google account if you sign in with Google. Plus an optional profile image, which is stored as a publicly addressable file.
- Workspace
- Company name, website, team size, industry, whether you already have a design system, a brand colour and an optional logo image. This is what makes deliverables land on your system instead of as generic mockups.
- Team seats
- For each person you invite: their email address, an optional name, their role, and a single-use invite token. Invited people appear in your workspace before they ever create an account.
- Requests
- Everything you submit and everything the work produces: the title and brief, the stage history, the full conversation thread on the request, preview images, revision rounds, and who signed the deliverable off and when.
- Notifications
- The workspace activity feed, including which users have read which entries.
Billing
Payment is handled by Stripe. Wraith never sees or stores your card number. What we store is a Stripe customer id, a subscription id, your plan, and the subscription status Stripe reports back (active, past due, canceled and so on).
Analytics and logs
The site uses Vercel Web Analytics for aggregate page-view measurement. Vercel, as our host, also processes standard request data such as IP address in the course of serving and protecting the site. We separately keep a small log of AI and search crawler visits (which crawler, which path, the user agent) to understand how the site is being indexed; that log deliberately records no IP address and no location.
IP addresses are used in memory to rate-limit the chat endpoint against abuse. That counter is transient and is not written to the database.
Why we are allowed to
Where a legal basis is required, for example under UK or EU data protection law, we rely on the following. This framing is a starting point for review, not a legal opinion.
- Contract. Account data, workspace data, request content and billing records are necessary to provide the subscription you signed up for.
- Legitimate interests. Replying to an access request, measuring which marketing channels work, keeping aggregate analytics, logging crawler activity, and rate-limiting endpoints against abuse. These are limited, low-impact uses and you can object to any of them.
- Consent. The optional "how did you hear about us" answer, which you can simply leave blank.
- Legal obligation. Retaining billing and tax records for as long as the law requires.
Who else processes it
This is the complete list of third parties that receive personal data in the running product, verified against the codebase rather than assembled from a template. Each is used for one purpose and nothing else. We do not sell personal data, and we do not share it with advertisers or data brokers.
- Vercelhosting, analytics, file storage
- Hosts and serves the site and the portal, so all request traffic passes through it. Provides Vercel Web Analytics for aggregate page views, and Vercel Blob storage for uploaded profile images and workspace logos.
- Neonmanaged Postgres, AWS us-east-1
- The database. Every stored item described above lives here: accounts, workspaces, requests and their conversation threads, team seats, notifications, access requests and the crawler log.
- Stripepayments
- Takes payment, hosts the checkout and the customer portal where you manage or cancel your subscription, and tells us your subscription status. Card details are collected by Stripe and never reach Wraith.
- Resendtransactional email
- Sends the transactional email the product generates, from notifications@mail.wraithhq.com. Recipient address and message content pass through Resend.
- Googleoptional sign-in
- Only if you choose Sign in with Google. Google confirms your identity and returns your email and profile details, which we store against your existing account. Google sign-in cannot create a new Wraith account; if there is no account for that address already, sign-in is refused.
- Vercel AI Gateway and AnthropicAI drafting and chat
- Text you send to the site's chat assistant, and request briefs processed by the drafting features, are sent through Vercel AI Gateway to Anthropic's Claude model to produce the response. See the section below.
- Figmaclient design files
- For subscribers, deliverables are produced in your own Figma file. Figma notifies us when that file changes and we read its structure through Figma's API, so design system content in the files you connect is processed by Figma under your own Figma account and ours.
- GitHubcode deliverables
- For subscribers who connect a repository, deliverables arrive as pull requests on your own repo, and an optional design-token check can comment on your pull requests. Repository content and pull request metadata are processed by GitHub.
Typefaces are self-hosted from our own domain at build time, so loading a page on this site makes no request to a font CDN.
AI drafting and the chat assistant
Wraith's model is that AI drafts and a named human designer reviews and signs every deliverable. That means content does reach an AI provider, and it is worth being precise about which content and when.
- The chat assistant on the public site. Anyone can use it, including people who are not customers. What you type is sent through Vercel AI Gateway to Anthropic to generate the reply. Public chat conversations are not written to our database. Please do not put confidential or personal details into it.
- Portal chat and request drafting. For subscribers, the brief you write and the conversation on a request are stored in our database, and are sent to the same AI provider to produce drafts and structure requests.
- We do not train models on your work. Wraith does not use your files, requests or design system to train models, and nothing from your workspace is reused as context for another client's work. AI drafts against your system to do your work, and that is the only thing it is used for.
What our AI provider does with content in transit is governed by their own terms rather than ours, so this page does not make claims on their behalf. If the provider's handling of your content is material to you, ask us at hello@wraithhq.com and we will point you at the current terms.
How long we keep it
Honestly: Wraith does not yet have a published retention schedule. Rather than invent one, here is exactly how the product behaves today.
- Bounded automatically. The attribution cookie expires after 24 hours. Sign-in verification tokens and workspace invite tokens carry their own expiry and stop working once it passes.
- Kept for the life of the account. Account, workspace, request, thread and team-seat data is kept while your subscription is active and afterwards, unless you ask us to delete it.
- Kept until we clear it. Access-request submissions, workspace notifications and the crawler log accumulate and have no automatic expiry today.
- Billing records. Retained as long as tax and accounting law requires, which is longer than the rest.
If you want something gone sooner, ask. A deletion request is honoured regardless of the absence of a schedule, and we intend to publish defined retention periods here.
Your rights
Depending on where you live you may have some or all of the following rights. We will honour these requests from anyone, rather than checking your jurisdiction first.
- Access. Ask for a copy of the personal data we hold about you.
- Correction. Ask us to fix anything inaccurate. Most account and workspace fields you can also edit yourself in the portal.
- Deletion. Ask us to delete your data. We will do it except where we are legally required to keep something, such as billing records.
- Objection and restriction. Ask us to stop a particular use, including the analytics and attribution uses described above.
- Portability. Ask for your data in a machine-readable form. Design deliverables are already yours and already live in your own Figma file and your own repository.
- Withdraw consent. Where we relied on consent, you can withdraw it at any time without affecting anything done before.
To exercise any of these, email hello@wraithhq.com from the address on your account, or tell us which address the request concerns. We aim to respond within 30 days. There is no charge. If you are unhappy with how we handle it, you can complain to your local data protection authority.
International transfers
Wraith is operated from the United States, and the database, the hosting and every processor listed above store or process data in the United States. If you are in the UK, the EEA or another region with transfer rules, using Wraith means your data is transferred there. We rely on the processors' own standard contractual clauses and equivalent transfer safeguards. The specific mechanism for each processor is part of what is under review, and we will name them here once that review is complete.
Children
Wraith is a business service sold to companies. It is not directed at children, we do not knowingly collect data from anyone under 16, and there is no part of the product intended for them. If you believe a child has given us personal data, write to hello@wraithhq.com and we will delete it.
Security
Passwords are stored only as salted hashes, never in a recoverable form. Traffic is served over HTTPS. Portal data is scoped to your workspace, so one customer's requests and files are not reachable from another's account. Card details never touch our systems. No system is perfectly secure, and we will not claim certifications we do not hold: Wraith has no SOC 2, ISO 27001 or equivalent audit today.
Changes to this policy
When this policy changes, the date at the top of the page changes with it, and the previous version is replaced rather than kept alongside. For a change that materially affects how we use data from existing customers, we will email the workspace owner before it takes effect rather than relying on you noticing the date. Continuing to use Wraith after a change means the updated policy applies.
Contact
Privacy questions, rights requests and complaints all go to the same place: hello@wraithhq.com. A person reads it.
Related
If this is the work you need
Tell us what your design system needs next. A senior designer replies within one business day, and will say so plainly if the request falls outside what Wraith does.