Skip to main content

Privacy Policy

Last updated: September 1, 2026

1. Who we are

Dembrandt (dembrandt.com) is an open-source CLI tool and web application for extracting and tracking design tokens from websites.

2. What data we collect

The CLI is local by default. Dembrandt CLI performs extraction locally on your machine and does not make requests to Dembrandt servers during normal use. Network requests to Dembrandt are made only when you explicitly provide an API key or use a feature such as comparison that requires the Dembrandt API. What that request contains is described below, under "Extraction results".

We collect the following:

  • Email address. Collected only if you subscribe to the newsletter, and stored by EmailOctopus. Dembrandt App accounts have no email address attached to them.
  • App account identity.GitHub OAuth sign-in stores your GitHub user ID and username. If you accept the onboarding checkbox, we also keep the email address GitHub returns for your account, so we can contact you if a bug or incident affected your account specifically. Nothing else from your profile is kept, and if you don't accept, no email is stored.
  • Extraction results.Sent to Dembrandt only when you provide an API key or use comparison against a stored baseline — never during a plain local run. What's sent is the URL you submitted and its extracted design tokens (colors, typography, spacing, and similar), which are public by definition and contain no personal data. It never includes the page's raw HTML, CSS, or a screenshot.
  • API keys. Stored as hashes, tied to your account, used to authenticate CLI requests.
  • Usage analytics. Page views and interactions through Google Analytics, loaded only after you accept cookies. IP addresses are truncated, no identifier is written to your browser, and there is no cross-site tracking.
  • Technical data. Server logs held by our host Vercel: IP address, browser, referrer. Used for security and debugging.

We collect no names and no payment information. We do not process special categories of personal data (health, ethnicity, religion, and similar, as defined by GDPR Article 9).

Domains and accounts are not combined in any way that would identify who extracted what. Extraction history is not profiled, sold, or used for marketing. An incident email, when we send one, is never marketing either — it is sent to your account's email directly, one account at a time, only about a bug or incident that affected that account, and never through a mailing list.

3. Legal basis for processing

  • Newsletter. Consent, given when you opted in.
  • App account and extractions. Contract, covering account creation and use of the service.
  • Analytics. Consent, given when you accepted cookies.
  • Server logs. Legitimate interest in security and uptime.
  • Incident emails. Consent, given via the checkbox shown the first time you use the App. You can withdraw it at any time by emailing us; we will delete the stored address and stop.

4. Third-party processors

We use the following sub-processors:

  • Vercel. Hosting and serverless compute. USA, EU data transfer covered by DPA.
  • Vercel Blob. Storage of extraction snapshots. USA, same DPA.
  • GitHub. OAuth authentication for app accounts. USA, GDPR compliant.
  • EmailOctopus. Newsletter delivery. UK, GDPR compliant.
  • Google Analytics. Consent-gated analytics. USA, EU data transfer covered by Google's DPA.
  • Google reCAPTCHA. Spam protection on the newsletter form, which processes your IP address. USA, same DPA.
  • Resend. Delivery of incident emails, sent only to accounts that gave consent. USA, GDPR compliant.

5. Cookies

We only set analytics cookies after you give consent via the cookie banner. You can withdraw consent at any time by clicking the cookie settings link in the footer, which clears stored consent and stops analytics from loading.

The newsletter form may load a reCAPTCHA widget from Google to prevent spam. This may set cookies from Google. See Google's Privacy Policy for details.

6. Data retention

  • Newsletter email. Kept until you unsubscribe. Every email carries an unsubscribe link.
  • App account data. Your GitHub ID, API keys, settings, and extraction snapshots are kept while the account is in use, and deleted on request. See section 7.
  • Incident email address. Kept until you withdraw consent or delete your account, whichever comes first.
  • Analytics data. Deleted automatically by Google Analytics after 14 months.
  • Server logs. Kept by Vercel under their retention policy, typically 30 days.

7. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Withdraw consent at any time
  • Object to processing or request restriction
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email dembrandt@tutamail.com. We will respond within 30 days.

8. Data breaches

In the event of a personal data breach that risks your rights and freedoms, we will notify the relevant data protection authority within 72 hours of becoming aware of it, as required by GDPR Article 33. If the breach is likely to result in a high risk to you, we will also notify you directly, without undue delay, explaining what happened and what we are doing about it.

9. Children

This service is not directed at children under 16. We do not knowingly collect data from minors.

10. Changes to this policy

We may update this policy occasionally. Material changes will be communicated via the newsletter or a notice on this page. The date at the top of this page reflects the most recent update.

11. Contact

Questions about this policy: dembrandt@tutamail.com