Privacy
Your design work stays under your control.
IroGuide is built for private design critique. We use your uploaded design, brief, and account session only to provide the product features you ask for, such as creating a critique, saving it to your dashboard, or sharing a selected critique to the community.
What we collect
- Account details needed for sign in, such as your email, display name, provider, and profile avatar.
- Review context you provide, including design category, audience, purpose, style direction, goals, and concerns.
- Uploaded image bytes while generating a critique. Image bytes are sent to the review API and configured vision provider for analysis.
- Saved critique outputs, checklist items, scores, comments, likes, saves, and community posts you choose to create.
- Operational metadata such as request timing, route names, status codes, and request IDs. Logs must not include uploaded images, briefs, signed tokens, or provider responses.
How reviews are handled
Private critiques are saved to your signed-in account so they can appear in your dashboard. IroGuide does not publish private reviews by default. Community sharing is a separate action that requires your explicit choice.
AI provider use
When live critique is configured, your uploaded image and brief may be sent to the selected vision provider to generate the critique. Provider credentials stay on the server. Do not upload work you are not allowed to share with an AI analysis provider.
Deletion and access
You can request deletion of account data, saved critiques, and community content through the contact page. Some operational logs may remain for security, abuse prevention, or legal reasons, but they should not contain image bytes or critique text.
Security baseline
- Authentication uses Firebase-supported sign-in methods.
- Server routes verify signed-in sessions before creating or syncing reviews.
- Review API requests are rate limited and logged with request IDs for operational monitoring.
- Server credentials and vision provider keys are stored only in the server environment.
Contact
For privacy, deletion, or account questions, use the contact page. This privacy notice should be reviewed by qualified counsel before broad commercial launch.