Legal

Privacy Policy

Effective 1 October 2026Last updated 1 October 2026

The short version

  • We collect what we need to run Livery: your account details, the brand materials you upload, the assets you make, and what you tell us when you book a demo.
  • Much of it stays on your own device. Accounts, brands and uploads are kept in your browser's storage, and client instances are folders on your own disk.
  • If you connect an AI assistant, the copy it writes passes through the Livery connector. The assistant's provider handles your prompts under its own privacy terms.
  • We don't sell personal information, show ads, or use your brand materials or copy to train AI models.

Who we are

Livery is operated by [Legal entity name], registered at [Registered address] ("Livery", "we", "us"). We are responsible for the personal information described in this policy, except where section 12 says a studio or client is.

What this policy covers

This policy applies to:

  • The website, including the demo request form.
  • The Livery app: sign-in, the dashboard, the onboarding wizard, the generated design system and the builder apps.
  • The Livery connector, the companion service that lets an AI assistant send copy into your builders.

It doesn't cover third-party services you choose to use with Livery, such as Claude, ChatGPT or your email provider. Their own policies apply.

Information we collect

Information you give us

WhatDetails
Demo requestsYour name, work email, company, how many brands you'd run, and anything you write in the message field.
Account detailsYour name, email address and password. Passwords are hashed (PBKDF2-SHA256 with a unique salt) and never stored in plain text.
Brand materialsLogo files, font files or font names, colour values, corner radii, icon settings and other brand choices you make during onboarding.
ContentThe copy, images and other material you add in the builders, and the assets you export.
Messages to usAnything you send us by email or during a call, including support requests.

Brand materials and content are usually about a business, not a person. They can include personal information, for example a photo or a staff member's name in a slide. You decide what goes in.

Information collected automatically

  • Connector data. Your workspace's connection key, the drafts your AI assistant sends, whether each draft was applied or discarded, and basic request logs (time, IP address, which tool was called).
  • Technical data. When you load our pages, your browser sends standard information such as your IP address, browser type and the page requested. This goes to us and to Google Fonts (see section 7).

We don't use advertising trackers, and the website doesn't run analytics scripts.

Where your data is stored

Livery is designed to keep your work close to you.

  • In your browser. Your account, your brands (OSs), wizard drafts and uploaded files are kept in your browser's storage on your device (IndexedDB, localStorage and sessionStorage). Clearing your browser's site data for Livery deletes them.
  • On your disk. When a studio writes a client instance, it is saved as a folder on a drive you choose, using your browser's folder access. That folder is yours. We have no copy of it.
  • On the connector. Drafts from your AI assistant wait on the connector until a builder picks them up, along with your connection details.
  • With us. Demo requests, and anything you send us directly.

If we later offer cloud accounts or hosted storage, we will update this policy before that happens and tell you what moves where.

AI assistants and the connector

You can connect an AI assistant such as Claude or ChatGPT to your Livery. When you do:

  • The assistant can read your workspace through the connector: your brand's name and settings, the list of builders, which ones are open, and the copy in an open builder. It uses this to write copy that fits.
  • The assistant can send copy, which the connector checks against the builder's rules and holds as a draft. You review it in the builder's AI inbox, unless you have turned on Live.
  • Your prompts, and whatever the assistant reads from Livery, are processed by the assistant's provider under that provider's terms and privacy policy. We don't control how they store or use it. Check their settings if you don't want your conversations used for training.
  • The connector URL contains a connection key, and anyone who has the URL can send drafts. Treat it like a password. You can revoke it at any time by creating a new connection key in the hub's connector settings.

The AI can only fill the copy fields your components already have. It can't change your logos, colours, fonts or layout.

How we use information

PurposeLegal basis (where the law asks for one)
Provide Livery: sign-in, generate your design system, run the builders, deliver AI draftsPerforming our contract with you
Reply to demo requests and arrange callsSteps you asked for before a contract, or our legitimate interest in responding
Support, billing and account messagesPerforming our contract with you
Keep the service secure and prevent abuseOur legitimate interest in protecting the service and its users
Improve Livery, for example by fixing bugs you reportOur legitimate interest in improving the product
Product news and offersYour consent, which you can withdraw at any time
Meet legal, tax and accounting dutiesLegal obligation

We don't use your brand materials, copy or exported assets to train AI models, and we don't make decisions about you based solely on automated processing.

When we share information

We don't sell or rent personal information. We share it only:

  • With service providers who help us run Livery, such as hosting, email and payment processing. They may use it only to provide their service to us.
  • With Google Fonts. Our pages and builders load fonts from Google's servers, which receive your IP address and browser details. See Google's privacy policy for how it handles this.
  • With the AI provider you connect, as described in section 5. You choose to share it; we don't send it on our own.
  • Within your team or studio, when you share a brand or instance with them.
  • If the law requires it, or to protect the rights, safety or property of Livery, our users or others.
  • In a business transfer, such as a merger or sale, where the new owner keeps the protections in this policy.

Cookies and browser storage

Livery doesn't use advertising or tracking cookies. The app uses browser storage because it needs it to work:

  • IndexedDB holds your account, brands, drafts and uploaded files.
  • localStorage remembers that you're signed in and which brand is open.
  • sessionStorage unlocks the current tab, so a new tab asks for your password again.

This storage is essential, so we don't ask for consent to it. If you block or clear it, Livery can't keep your work.

How long we keep it

  • Browser data stays on your device until you delete it, sign out and clear it, or clear your browser's site data.
  • Connector drafts are kept until they are applied or discarded, and then for up to [30] days so your assistant can check their status.
  • Demo requests are kept for up to [24] months after our last contact, unless you become a customer.
  • Billing records are kept for as long as tax and accounting law requires.

Security

We hash passwords, keep connector traffic behind a per-workspace key, require HTTPS for hosted connections, and limit who on our side can reach your information. No system is completely secure. Data in your browser is only as safe as the device and the accounts on it, so lock your computer and keep your connector URL private.

If a breach affects your personal information, we will tell you and the relevant regulator where the law requires it.

Your rights

Depending on where you live (for example under the GDPR, the UK GDPR, South Africa's POPIA or California's CCPA), you may have the right to:

  • access the personal information we hold about you, and get a copy;
  • correct it if it's wrong;
  • delete it;
  • object to or restrict how we use it;
  • take it with you (Livery exports your brand as brand.json or brand.config.js);
  • withdraw consent where we rely on it;
  • complain to your data protection authority.

Much of your data never reaches us, and you can view, export or delete it yourself in the app. For anything we hold, email us at [privacy contact email]. We'll reply within 30 days and won't treat you differently for asking.

Studios and their clients

When a studio or agency onboards a client brand, the studio decides what goes into that brand and who on the client's team can use it. For personal information inside client brands and content, the studio (or the client) is responsible for it, and we process it on their behalf. If you're on a client's team and have a question about that information, contact the studio or client first. We'll help them respond.

International transfers

We and our service providers may process information outside your country. When we do, we use safeguards the law recognises, such as standard contractual clauses, so your information keeps the same level of protection.

Children

Livery is a business tool and isn't meant for anyone under 18. We don't knowingly collect personal information from children. If you think a child has given us information, contact us and we'll delete it.

Changes to this policy

We'll update this page when our practices change and revise the date at the top. If a change is significant, we'll tell you by email or in the app before it takes effect.

Contact us

Questions about privacy, or a request about your data:

  • Email: [privacy contact email]
  • Post: [Legal entity name], [Registered address]
  • Information Officer / Data Protection Officer: [Name, if required]