designer-skill: cleaner UI from your agent.

Get it

Privacy Policy

Last updated: September 30, 2026

Niblet Designer UI is a hosted reference service operated by PyModel LLC (“PyModel”, “we”). This policy covers what is collected when you browse niblet.pymodel.com, create an account, or call the API at niblet-api.pymodel.com, or buy a plan. Short version: account and API-key records support authenticated MCP access, payments are handled by Polar, and there are no advertising trackers or third-party ad networks.

1. What we collect

  • • Server logs. Like any web server, the infrastructure briefly logs request metadata (IP address, user agent, requested URL, timestamp) for availability and abuse prevention. Logs are not used to profile visitors and are not sold or shared.
  • • Account data. Creating an account stores the name and email address you provide, along with the authentication, verification, and session records needed to protect the account. Transactional verification and recovery messages are delivered through Brevo, our transactional email provider.
  • • Billing data. If you buy a plan, Niblet stores your Polar customer id, your subscription or purchase status, plan, amount, and key dates (start, renewal, cancellation, end), the order history we read from Polar, and a log of the billing emails we send you (such as receipts, renewal reminders, and cancellation notices). Billing emails are sent through Brevo as transactional messages.
  • • Checkout consent records. When you buy a plan (Monthly or the One-time plan), we keep a record of your checkout consent: your user id, the plan, the terms version, the consent statement you agreed to, and a timestamp. We keep it to evidence your consent to automatic renewal and to immediate supply of the service, for at least three years or one year after your subscription ends, whichever is longer. A confirmation of that consent is emailed to you.
  • • API keys and usage. The plaintext key is shown only when it is created. Niblet keeps the key record, its display name and status, and per-key request metadata needed for authentication, rate limiting, usage totals, and abuse prevention.
  • • Cookieless analytics. The site loads a self-hosted Umami script that records aggregate page views without cookies and without cross-site tracking.
  • • Product analytics and error reports. The site uses PostHog (PostHog Inc., US cloud) to count page views and a small set of actions (for example signing up or copying a setup prompt), to report JavaScript errors, and to record a sample of sessions for debugging. It sets a first-party cookie. Recordings mask all page text and every input, request bodies and headers are never captured, and URLs are stripped of their query string before they are sent, so search text does not reach it. A signed-in visit is labelled with the account’s internal id only, never the name or email.
  • • Local preferences. Your light/dark theme choice is stored in your browser’s localStorage under niblet-theme. It never leaves your device.

2. What we do not collect

  • • No payment-card numbers. Card details are entered on Polar’s checkout and stored by Polar; they never reach Niblet.
  • • No advertising cookies, pixels, or third-party ad trackers of any kind.
  • • No search-history retention tied to you; API search queries are not linked to identity.

3. The catalogue itself

The catalogue contains screenshots of publicly distributed apps and publicly published web design packs, indexed for design research. Those images belong to their respective owners. If you are a rights holder, our Copyright & DMCA policy explains how to request removal.

4. API keys

Account keys authorize the hosted MCP endpoint. Treat a key as a secret: it identifies requests made through it. A key can be revoked from the account dashboard, and the plaintext is not shown again after creation.

5. Payments

Payments are processed by Polar, the Merchant of Record for Niblet purchases. Polar collects and processes your payment details, billing address, and tax information as an independent controller under its own privacy policy. Polar shares with us only what we need to run your plan: the customer id, subscription and order records, and the email address used at checkout.

6. Data location

The site, API, media, account database, and Umami analytics run on operator-controlled infrastructure. PostHog analytics are processed by PostHog Inc. in the United States. Transactional and billing email passes through Brevo. Payment data is processed by Polar. No advertising network or data broker receives account or catalogue-use data from Niblet.

7. Changes and contact

If this policy changes materially, the date above will change. Questions: contact page · [email protected]

← Back to Home

© 2026 Niblet. All rights reserved.