done.·PrivacyTermsCookiesAccessibilityCredits

Privacy Policy

This is an English translation provided for convenience. The Hebrew version is the binding version; if the two differ, the Hebrew version prevails.

Last updated: [[PLACEHOLDER: effective date, set at launch]]

Draft — not legal advice. This page was written from the codebase to describe real data flows as accurately as possible. It has not been reviewed by a lawyer and must not be treated as a finished document until it is.

This policy explains what done. (the “Service”) collects, why, where it is stored and who receives it. It was written by reading the Service’s own source code, not copied from a template: every third party named here is one the Service actually contacts.

1. Who we are

The Service is operated by [[PLACEHOLDER: operator name]], ID [[PLACEHOLDER: ID / business / company number]], of [[PLACEHOLDER: address]] (“we”). We own and are responsible for the database. For any question or request about your data: done.design.app@gmail.com.

2. The short version

  • You can use the Service without an account. Your project then lives only in your browser and is never sent to us.
  • Sign-in is with a Google account only. We never see or store a password.
  • Your floor plans and images are never sent to any AI service.
  • We run no analytics, advertising, pixels or tracking of any kind. We do not sell data or use it for marketing email.
  • Anyone you give a live share link can view (and, depending on the role you pick, edit) that shared project. You can revoke every link you have sent, at any time.
  • We do not keep separate backups of our database. The cloud copy is there to sync your devices, not to serve as a backup, so keep an export of anything you cannot afford to lose.
  • You can download all your data and delete your account yourself, at any time, from the Your data page.

3. What we collect, why, and who receives it

You are under no legal obligation to give us any information. Doing so depends on your choice and consent. If you choose not to sign in, you can still use the Service on your device, but syncing across devices, cloud storage and account-based sharing will not be available.

Account & project data — Supabase

If you sign in, authentication and cloud storage are handled by Supabase, Inc.:

  • Sign-in: via Google. We receive your name, email address and profile picture URL from Google. Purpose: to identify you and attach your projects to you.
  • Project details: project name, created/updated times and a revision counter. Purpose: to save your projects and sync them across your devices.
  • Project content: the 3D model you built (walls, rooms, furniture and so on), any plan image you imported, and a thumbnail. Files are kept in private storage, and access is restricted so only your account can read or write them.

Live collaboration — Liveblocks

When you make a project “live” or join through a share link, co-editing runs through Liveblocks, Inc.:

  • Presence: a display name and picture or colour are shown to everyone in the same room. Signed in, that is your Google name and profile picture; otherwise you get a random name (e.g. “Swift Fox”).
  • The shared scene is synchronised through Liveblocks for as long as the room exists.
  • Access is granted by a signed link valid for 30 days, not by identity. Anyone holding a valid link can join, with or without an account.

Hosting, abuse protection and profile pictures

  • Vercel, Inc. hosts the site and server APIs, and so processes ordinary connection data such as IP address, as any web host does. It also serves the furniture and material library, which is read-only; nothing you create is stored there. [[VERIFY: Vercel request-log retention period]]
  • Upstash, Inc. provides rate limiting to protect the Service from abuse. Your IP address or account ID is used briefly as the key of a short-lived request counter. That counter is not stored in our database or written to logs.
  • UptimeRobot checks every few minutes that the site is up, by requesting our public health page. That page contains no personal data, and the monitor receives no information about visitors.
  • Google: your profile picture loads directly from Google’s servers, so your browser contacts Google when it is shown.

Error reports — Sentry

When the Service crashes or hits an error, a report may be sent to Functional Software, Inc. (Sentry) so we can fix it. A report contains the error message and technical trace, your browser, device and operating-system type, the version of the Service, and the page address. Before a report leaves the Service we strip the secret part of a share link and any sign-in code from that address, and we remove cookies, request contents, your name and email. Reports never contain your floor plan or images, and session replay is switched off deliberately so your plan is never recorded. Performance tracing is off. Reports are stored in the United States and kept for 30 days.

A service wired in but currently switched off

  • Resend, Inc., for operational email only, such as an account-deletion receipt or a policy-change notice. No marketing email.

If we switch it on, we will update this policy first.

AI — none

The Service does not send your plans, images or any other content to an AI provider. An early feature that did was removed on 23 August 2026, together with the code that sent the data.

Fonts

Fonts (Manrope, IBM Plex Mono, Rubik) are served from our own servers. Your browser does not contact Google to load them.

Abuse & takedown reports

Anyone — with or without an account — can report a plan, a share link, a live collaboration room, or an uploaded image at Report content. We store what you tell us in that form: what you are reporting, why, the details you write, and — only if you choose to give it — an email address to hear back on. We also record the IP address a report was sent from, to keep the form itself from being abused. A report is visible only to us, is not shown to the person or account it names unless the law requires it, and is used only to review and, where warranted, act on what you reported.

4. What is stored where

In your browser: every project is saved automatically to your browser’s local storage (IndexedDB), signed in or not. It does not leave your device unless you sign in and it syncs, or you choose to share it.

In the cloud (only if signed in): the same data is synced to Supabase so it is available on your other devices, and stays private to your account. This is a sync copy, not a backup: we do not keep separate backups of the database. If our server ever loses a project you had synced, a device of yours that still holds it uploads it again instead of deleting it.

To keep storage and abuse in check, an account can hold up to 500 projects, each project document up to 16 MB, and each imported plan image up to 50 MB. Only PNG, JPEG, WebP and GIF images are accepted for cloud storage.

Cookies and local storage are listed in the Cookie Policy.

5. What a share link exposes

A share link grants access to the shared project only, not to your account or your other projects. The role you choose (view / decorate / build) sets what the recipient can do. A view link cannot edit. Take care with the other two: “decorate” limits the editor’s controls but is not a technical barrier, so treat anyone holding a decorate or build link as able to change the shared project.

A link works until it expires (30 days), you revoke it, or the room is deleted, for example when you delete your account. In the share panel, “Revoke all links” cancels every link you have sent for that project at once; links you create afterwards work normally. Revoking stops new entries: someone already inside the room may stay connected until they reload or their access expires. Share a link as you would any editable document: only with people you trust.

6. Transfers outside Israel

The providers above are foreign companies, mostly in the United States, and data may be stored or processed outside Israel, including in countries whose privacy laws differ from Israel’s. We work only with providers that commit by contract to protect the data and use it only to provide their service to us. By using the Service and signing in, you consent to this transfer. [[VERIFY: legal basis under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations 2001, and the Supabase storage region]]

7. Retention & deletion

  • A deleted project is removed from your browser and marked deleted in the cloud. The files and records themselves are permanently purged within 30 days.
  • Deleting your account from the Your data page immediately erases every project, file, share room you created and the account itself. It cannot be undone. It does not delete rooms that other people created and shared with you, and it cannot reach copies that people you shared with saved for themselves.
  • Because we keep no separate backups, deleted data does not linger in backups. A device that was offline for more than 30 days may upload again a project you deleted elsewhere; you can delete it again.
  • We keep no personal data beyond what the purposes here require, unless the law requires it.
  • Abuse and takedown reports are not covered by the 30-day purge above. They are kept for 12 months after we finish handling them, as our record of what was reported and what we did about it, and are then deleted.

8. Security

Traffic is encrypted (HTTPS). Cloud data is protected by row-level access rules so each account sees only its own data. Share links are cryptographically signed, time-limited and revocable. Error reports are stripped of secrets and account details before they leave the Service. No system is completely secure. If you find a security problem, please write to done.design.app@gmail.com; our security contact is also published at /.well-known/security.txt. If a serious security incident occurs, we will act as the Privacy Protection (Data Security) Regulations 2017 require, including notifying the Privacy Protection Authority where required.

9. Your rights

  • Access: to receive the data held about you. Download it yourself (“Export” on the Your data page) or ask by email.
  • Correction and deletion: to ask us to correct data that is wrong, incomplete or out of date, or to delete it. Most of this you can do yourself in the Service.
  • Withdrawing consent: to stop using the Service and delete your account at any time.

Requests: done.design.app@gmail.com. We reply within 30 days. If you are not satisfied, you may contact the Privacy Protection Authority at the Israeli Ministry of Justice, or a court.

10. Children

The Service is not directed at children. You may not open an account under the age of 16, and we do not knowingly collect personal data from anyone younger.

11. Changes to this policy

When we change this policy we update the “Last updated” date above. Material changes are announced in advance, in the Service or by email to registered users.

12. Contact

Questions about this policy or your data: done.design.app@gmail.com.