Privacy
Last updated 21 September 2026
This page says what Broom does with your data: your account, the code and design files you give us, what you pay, and what we measure. It describes the product as it works today, and it changes when the product changes. Last changed on 21 September 2026.
Who we are
Broom is run by Boburmirzo Khudoyberdiev, an individual trader in Uzbekistan. We decide what happens to the personal data described here, which makes us responsible for it.
Write to us at support@broom.design about anything on this page, including a request to see, correct or delete your data. That address reaches us and we answer it.
Where Broom is offered
Broom is not offered in the European Economic Area, the United Kingdom or Switzerland. We ask which country you are in when you create an account, and we do not open one for those.
This is about our own paperwork rather than about you. Broom is run today by one person rather than a company, and serving those countries properly asks for things a company is meant to carry. That is being set up, and we will open there when it is.
If you are in one of them and want to be told when that happens, write to support@broom.design.
The short version
- We keep your account, the work you give us, the results we produce from it, and a record of what you paid.
- We never see your card. Dodo Payments is the seller and handles the payment.
- Your code and your design files go to one model, Google Vertex AI, to produce your design system and rules.
- We train nothing on what you send us, and we do not use it to improve Broom for anyone else.
- Analytics only run if you accept them. Session recordings mask every piece of text and every input.
- Delete your account and everything we hold goes with it, in one pass, straight away.
Your account
You sign in with Google, GitHub or an email address and password. Firebase Authentication holds the sign-in itself, so we never see your password.
- The account id Firebase gives you, and your email address.
- Your name, and the role you pick if you pick one.
- A profile picture, if you upload one. Your browser downscales it before it is sent, and it is stored as a small image on your profile.
- How many analyses you have left, how many you have used, and which plan you are on.
- If you have a subscription: its id, its status, when it renews, and the network and last four digits of the card that paid for it.
- If you connect GitHub, the access token stays in that one browser tab and nowhere else. It is gone when you close the tab or sign out, and it never reaches our database.
What you give us to work on
This is the part that matters most to you, so we say it exactly. All of it is yours, and all of it goes when you delete the project or the account.
- Your answers in the brief: the product name, what it does, who it is for, its category, and your choices about colour, corners, type and motion.
- Screenshots you upload as references. These are sent to the model, which writes down what the screen is made of.
- Screenshots you attach to a redesign brief. These are stored with the brief and are not sent to the model.
- A Figma file you upload. Your browser opens the file and sends us only the document inside it. The images inside the file never leave your machine.
- A repository you connect. We download one archive of its default branch and read the files that build the interface.
- A web address, if you give us one. We open the page in a headless browser and measure what it really renders.
- What we make from all of it: the design system, the tokens, the components, the documentation, the rules for your agent, the findings, and one screen of your interface before and after our changes.
What we keep of your code, and what we do not
We do not keep a copy of your repository. The file text is held in memory while the run is going and dropped when it ends. What stays on the result is what we found in it: the colours, fonts, sizes, radii, spacing and component names, the findings with the file and line each one is on, and short excerpts of the lines a finding points at.
For a live page the same holds: the page and its stylesheets are the working set of that run and are not stored. One screenshot of the page is kept with the result, so the report can show what was measured.
The token you paste to read a private repository is used for the requests of that one call and then dropped. It is never written to the database, never logged, and never sent back to your browser.
What you pay
Dodo Payments is the merchant of record for Broom. They run the checkout, take the card and handle tax. Your card number never touches our servers, and we could not see it if we wanted to.
What we store is our own record of the sale: what was bought, how many analyses it was worth, the amount in US dollars, Dodo's reference for it and the date. From a subscription payment we also store the card network and the last four digits, so the billing screen can name the card.
What we measure
Analytics run only after you accept them. Until you do, nothing is sent anywhere.
We use two. Google Analytics 4 for traffic and revenue, and Mixpanel for the product questions a marketing tool cannot answer, such as where people stop in the brief.
- A closed list of events we wrote by hand: a screen opened, a sign-in, a run started, a run finished, a pack downloaded, a checkout started, and a dozen more of the same kind. Nothing is captured automatically.
- Your account id travels with them, so a purchase lands on the same person as the screens that led to it. Your email address, your name, a project or product name, a repository address, a token, or anything you typed never does.
- Mixpanel records sessions. Every recording masks all text and all inputs, so it shows the shape of what happened and never the words on your screen or in your fields.
- Mixpanel keeps its id in your browser storage rather than in a cookie.
Errors
When something breaks, in our API or in your browser, we write the error and its stack to Google Cloud Error Reporting. With it goes the address of the page, the request method, your browser's user agent and your account id.
Before any of it is written we strip out anything shaped like a credential: bearer tokens, API keys, GitHub tokens, sign-in tokens, webhook secrets. Google keeps these reports for about 30 days and then drops them.
Why we are allowed to do this
Under the GDPR every use of your data needs a basis. These are ours.
| What | Why we have it | Basis |
|---|---|---|
| Your account: id, email, name, role, picture | To sign you in, run the product for you and reach you about it | Performing our contract with you |
| What you send us to work on, and the results | To run the analysis you asked for | Performing our contract with you |
| Analyses left, used, and your plan | To sell you runs and count them honestly | Performing our contract with you |
| Our record of a payment | To sell you analyses and keep our books | Performing our contract with you, and our legal obligation to keep records |
| Product analytics and session recordings | To see where people get stuck, and fix it | Your consent, which you can withdraw at any time |
| Error reports | To find out what broke and repair it | Our legitimate interest in a service that works |
| The note that an account was deleted | So one person cannot take the free trial again and again | Our legitimate interest in preventing abuse |
Cookies, and what is stored in your browser
The marketing site at broom.design sets no cookies and stores nothing in your browser. It loads no analytics at all.
The app at app.broom.design stores a few things, all of them in your browser rather than as tracking cookies:
- Your theme: light, dark or system.
- Your language: English, Russian or Uzbek.
- Your answer to the analytics question, so we do not ask it again.
- Your sign-in, kept by Firebase Authentication so that you stay signed in.
- The GitHub access token for that one tab, if you connect GitHub. It is dropped when the tab closes or you sign out.
- Mixpanel's own id, and only once you have accepted analytics.
No advertising
Broom carries no advertising, no advertising cookie, no pixel and no advertising partner. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Who else sees your data
We keep this list short on purpose. These are everyone.
| Who | What they do for us | Where the data sits |
|---|---|---|
| Google Cloud and Firebase | The database, the app, the API, sign-in, secrets and crash reports | Firestore in Frankfurt, Germany. The API on Cloud Run in Belgium. Sign-in and crash reports on Google's own infrastructure. |
| Google Vertex AI | The model that writes your design system, your rules and the audit | Called at Google's global endpoint from our own Google Cloud project, so the request may be served outside Europe. |
| Mixpanel | Product analytics and masked session recordings, once you accept them | Mixpanel's European instance. |
| Google Analytics 4 | Traffic and revenue, once you accept analytics | Google, in the United States and elsewhere. |
| Dodo Payments | The seller of record: checkout, your card, tax, subscriptions and the billing portal | As stated in Dodo Payments' own privacy notice. |
| GitHub | Only when you connect a repository: they serve the archive we read | GitHub, in the United States. They see the request and, if you signed in with GitHub, your own token. |
Where your data sits, and what covers it leaving
Our database is Firestore in Frankfurt, Germany. Our API runs on Cloud Run in Belgium. Both are in the European Union.
Two things leave it. Model calls go to Google Vertex AI at Google's global endpoint, which means Google may serve the request from a data centre outside Europe. Google Analytics and Dodo Payments also process outside the European Economic Area.
Where a provider is outside the EEA or the UK, the transfer runs on the European Commission's standard contractual clauses in that provider's own data processing terms, or on an adequacy decision where one covers it.
How long we keep it
| What | How long |
|---|---|
| Your account and profile | Until you delete it. |
| Your projects, briefs, results and findings | Until you delete the project, or the account. |
| The text of a repository or a live page, in full | Only while the run is going. What stays is what we found, the findings and one screen before and after. |
| A repository access token | Not kept at all. Used for the requests of one call, then dropped. |
| The images inside a Figma file | Never uploaded. They stay on your machine. |
| Our record of a payment | Until you delete the account. Dodo keeps its own record as the seller, under its own terms. |
| The note that an account was deleted | Kept after deletion. It holds your account id and the date and nothing else. |
| Error reports | About 30 days, which is Google's own limit on that service. |
| Analytics events and session recordings | We set no deletion schedule for them today. We delete them on request. |
Deleting your account
Deleting the account runs a real cascade, not a flag. Your projects go, and with them their briefs, design systems, versions and components. Then your jobs, then your payment records, then your profile, then the sign-in itself.
One thing survives: a note holding your account id and the date, so that signing up again does not hand out the free trial a second time. It contains nothing else about you.
If you also want your analytics events removed, ask us and we delete them from Mixpanel and Google Analytics.
The model, and what it is given
This is the question every serious buyer asks first, so here is the whole answer.
One model does the writing: Google Gemini, called through Google Vertex AI in our own Google Cloud project. The deployed service calls no other model provider. If that ever changes we will say so on this page before it does.
- What is sent: the text of the interface files we read from your repository, what we derived from your Figma file, the rendered page and its stylesheets if you gave a web address, your brief answers, and any reference screenshot you uploaded.
- What is not sent: your sign-in, your email address, your payment details, any access token, the screenshots attached to a redesign brief, and the images inside a Figma file.
- What comes back: the design system, the component documentation, the rules and skills for your agent, the critique and the findings. All of it is stored in your project and shown to you.
Training
We train nothing on your content. Not a model, not a fine-tune, not an evaluation set. Your code and your design do not make Broom better for anybody else.
Google's terms for Vertex AI say that Google does not use what customers send to the service to train its models. We rely on that, and you can read it in Google's own Vertex AI service terms rather than in our summary of them.
Your rights, wherever you are
These are written into European law and we give them to everybody, because they are the right way to treat somebody's data and because we had to build them into the product anyway.
You can ask for any of these and we do it. Write to support@broom.design from the address you signed in with, and we answer within one month.
- A copy of what we hold about you, in a form you can read and take elsewhere.
- A correction, if something is wrong. Your name, role and picture you can change yourself in your profile.
- Deletion. You can do it yourself from your profile, and it takes effect at once.
- A restriction on what we do with it, or an objection to it, where the law gives you that.
- Withdrawal of your consent to analytics, at any time. It stops the moment you withdraw it, and it does not undo what was lawful before.
Complaining
If you think we got this wrong, tell us at support@broom.design. One person reads that address and answers it.
Where you live may have a data protection authority you can complain to as well, and nothing here takes that away.
If you are in California
You can ask what personal information we collected about you in the last twelve months, where it came from, why we have it and who received it. You can ask for a copy, ask us to correct it, and ask us to delete it. We will not treat you any differently for asking.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing here to opt out of.
The categories are the ones described above: identifiers such as your account id and email address, commercial information such as what you bought, internet activity such as which screens you used, and the content you upload to be analysed.
Ask at support@broom.design. We may need to check that the request is really yours, which usually means answering from the address you signed in with. An agent may ask on your behalf with your written permission.
Children
Broom is not for anyone under 16, and no account may be created for a person under 16. We do not knowingly collect anything from a child.
If you believe a child has an account here, write to support@broom.design and we will delete it.
How we look after it
Sign-in runs through Firebase Authentication, so we never handle your password. Every request to our API carries a signed token that we verify, and a token belonging to a deleted or signed-out account stops working at once.
Our database rules let an account read only its own documents, and let nobody write from the browser at all. Every write goes through our API.
Keys and secrets live in Google Secret Manager, never in the code and never in an image. Anything credential-shaped is stripped out of logs before they are written. Everything travels over HTTPS.
We do not claim a security certification. We have not been audited against SOC 2 or ISO 27001 and we will not pretend otherwise. What is written on this page is what the code does, and you can hold us to it.
Changes to this page
When we change this page we change the date at the top. If a change matters to you, for example a new company receiving your data or a new purpose for it, we tell you in the app before it takes effect.
Reaching us
support@broom.design. One person reads it. Boburmirzo Khudoyberdiev, Uzbekistan