Skip to main content
Last updated: August 3, 2026 This Privacy Policy explains how Refero Inc. (“Refero”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you use Refero, including our website, search and reference library, bookmarks, boards, team features, research chat, MCP and API access, and related services (collectively, the “Service”). If you have questions or want to exercise privacy rights, contact us at support@refero.design.

1. Who we are

Refero Inc. is a Delaware corporation. This Privacy Policy applies to processing for which Refero is the controller or business responsible for deciding how and why personal information is processed. For a legacy account or subscription, another entity identified in an existing agreement, checkout, invoice, or receipt may remain the controller for processing it continues to determine, including related billing and transaction processing. The privacy notice associated with that legacy relationship continues to apply to that processing until you are notified otherwise. For certain team, business, MCP, API, or enterprise use cases, Refero may process personal information on behalf of a customer under a separate agreement or Data Processing Addendum. In that case, the customer may be the controller or business, and Refero may be the processor or service provider.

2. Information we collect

We collect personal information in the following ways.

Information you provide

We collect information you provide directly, including:
  • account information, such as email address, name, profile picture, authentication information, and account settings;
  • billing and subscription information, such as plan, billing status, billing email, payment processor identifiers, invoices, tax or location information, and transaction metadata;
  • team information, such as team name, team logo, team URL, invitations, members, roles, admin settings, shared boards, and shared folders;
  • User Content, such as images attached to Research or visual search, prompts, chat messages, saved references, bookmarks, folder names, board content, notes, and other content you submit;
  • support communications, such as messages you send to support@refero.design and information needed to respond;
  • feedback, survey responses, marketing preferences, and newsletter signups;
  • MCP, API, or integration information, such as API tokens, usage metadata, integration settings, and authentication data.
Images attached to Research or visual search do not become part of Refero’s curated reference library. They may be stored at link-accessible URLs, and anyone who obtains the URL may be able to view the image. Do not attach confidential or sensitive material unless this access model is appropriate for your use.

Information collected automatically

When you use the Service, we and our service providers may collect:
  • device and browser information, such as browser type, device type, operating system, language, screen settings, and approximate timezone;
  • usage information, such as pages viewed, searches, clicks, downloads, bookmarks, feature usage, referral sources, UTM parameters, and subscription-related events;
  • technical information, such as IP address, request logs, authentication logs, error logs, performance data, and security events;
  • cookie and local storage information, including authentication tokens, preferences, referral codes, theme settings, analytics identifiers, and similar technologies.
This policy describes these technologies at a high level. We do not currently offer an in-product cookie preference center.

Information from third parties

We may receive information from third parties, including:
  • authentication providers, such as Google, when you sign in;
  • payment processors, such as Stripe and, for legacy subscriptions, Lemon Squeezy;
  • analytics and attribution providers;
  • AI, infrastructure, storage, hosting, security, and support providers;
  • users who invite you to a team or shared workspace;
  • public sources used to maintain the design reference library.
The design reference library is selected and curated by Refero and may include publicly available screenshots, product pages, app screens, logos, names, URLs, and related metadata. Users cannot add screens to the curated reference library. We do not intentionally build the library to identify private individuals, but public screenshots may incidentally contain personal information that appeared in the public source. Rights holders or affected parties may request review, correction, or removal by contacting support@refero.design.

3. How we use information

We use personal information to:
  • provide, operate, maintain, and improve the Service;
  • create and authenticate accounts;
  • process subscriptions, payments, invoices, taxes, renewals, cancellations, and billing support;
  • provide search, bookmarks, boards, folders, teams, research chat, image uploads, MCP, API, and related features;
  • process prompts, uploaded content, and chat messages through AI and infrastructure providers when you use AI-assisted features;
  • personalize and remember settings, such as theme, previous queries, and preferences;
  • analyze usage, measure performance, debug issues, and improve product quality;
  • send transactional emails, authentication messages, billing notices, service notices, support replies, and security alerts;
  • send marketing emails, onboarding emails, product updates, and newsletters where permitted by law, with unsubscribe options in marketing emails;
  • state that people associated with an organization use Refero and use the organization’s name or logo for that limited purpose, based on account or subscription information, unless the organization or user asks us to stop;
  • prevent fraud, abuse, scraping, unauthorized access, security incidents, and violations of our Terms;
  • comply with law, enforce agreements, respond to lawful requests, and protect rights, safety, and security.
Where GDPR, UK GDPR, or similar laws apply, we process personal information under the following legal bases:
  • contract necessity, to provide the Service, manage accounts, subscriptions, teams, MCP/API access, and support;
  • legitimate interests, to secure, maintain, improve, and analyze the Service, prevent abuse, communicate about the Service, and develop our product, where those interests are not overridden by your rights;
  • consent, where required for certain marketing, cookies, optional features, or integrations;
  • legal obligation, to comply with tax, accounting, legal, payment, sanctions, consumer protection, or regulatory requirements.

5. How we share information

We do not sell personal information for money. We may share personal information with:
  • service providers and subprocessors that help us provide the Service, including hosting, storage, infrastructure, analytics, authentication, payment processing, email delivery, support, security, error monitoring, and AI providers;
  • payment processors, such as Stripe and Lemon Squeezy for legacy subscriptions, to process payments and manage subscriptions;
  • AI routing and model providers, such as OpenRouter, OpenAI, Anthropic, Google, and similar providers, when you use AI-assisted features. This refers to AI feature inputs and context, not Google Sign-In/API user data;
  • authentication providers, such as Google, when you use sign-in or OAuth features;
  • team admins and team members, as needed to provide team features and shared workspaces;
  • legal, accounting, banking, compliance, and professional advisors;
  • authorities, courts, regulators, or third parties when required by law or necessary to protect rights, safety, security, or the integrity of the Service;
  • counterparties in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction.
We may share aggregated or de-identified information that does not reasonably identify you.

6. AI-assisted features

If you use AI-assisted features, your prompts, chat messages, uploaded content, search context, tool results, and related metadata may be processed by Refero and by third-party AI routing, model, or infrastructure providers. These providers may include OpenRouter, OpenAI, Anthropic, Google, and similar services. We may change AI providers, models, routing, and processing methods over time. We do not generally disclose the specific model used for each request. Refero does not use your prompts, chats, uploaded content, or AI outputs to train general-purpose AI models under its control unless you opt in. Third-party AI providers process data under their applicable terms and configured settings. Where Refero controls those settings, we do not intentionally select settings that permit general-purpose model training. You should not submit sensitive personal data, confidential business information, trade secrets, regulated data, or third-party confidential information to AI features unless you have the right to do so and accept the related processing.

7. Google user data

If you use Google sign-in or another Google-connected feature, we may receive Google account information such as your email address, name, and profile picture, depending on the permissions shown during authentication. Our current Google sign-in uses basic profile and email information. We use Google user data to provide account authentication, maintain your Refero account profile, secure the Service, provide requested user-facing features, and operate the Service through service providers under appropriate obligations. We do not sell Google user data. We do not use Google user data for advertising, credit decisions, lending decisions, or generalized AI/ML model training. We do not transfer Google user data except as needed to provide, secure, support, analyze, or operate the Service, comply with law, or with your consent. Google Sign-In/API user data is separate from any content you submit to AI-assisted features. If Google or a Google-affiliated service is used as an AI routing, model, or infrastructure provider, that processing concerns the prompts, uploads, context, and related feature data you submit to AI-assisted features, not Google Sign-In/API user data. Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If we materially change how we use Google user data, we will update this Privacy Policy and obtain any required consent.

8. Payments

We use third-party payment processors to process payments. Refero does not store full payment card numbers. Payment information is processed by the payment processor, and we receive limited billing and transaction metadata needed to manage subscriptions, invoices, tax, support, fraud prevention, and accounting. New subscriptions are currently processed through Stripe. Some legacy subscriptions may be processed through Lemon Squeezy.

9. Marketing emails

If you create an account, sign up, subscribe, or otherwise interact with Refero, we may send you product updates, onboarding messages, newsletters, and marketing emails where permitted by law. You can unsubscribe from marketing emails using the unsubscribe link in the email. Even if you unsubscribe from marketing emails, we may still send transactional or service messages, such as authentication codes, billing notices, account notices, security alerts, and support replies.

10. Cookies and similar technologies

We use cookies, local storage, and similar technologies to:
  • keep you signed in;
  • remember preferences and settings;
  • store referral and UTM information;
  • measure usage and performance;
  • prevent fraud and secure the Service;
  • support analytics and product improvement.
We currently use Google Analytics and Mixpanel for usage and product analytics. We use Microsoft Clarity for session-interaction analytics, such as clicks, scrolling, and navigation behavior. These services load when the site or product loads. You can learn about Google’s analytics opt-out options and Mixpanel’s opt-out options.

11. Do Not Track and global privacy signals

Some browsers offer “Do Not Track” or Global Privacy Control signals. The Service does not currently respond automatically to these signals. If you wish to exercise an applicable opt-out right, contact support@refero.design.

12. Data retention

We keep personal information for as long as needed to provide the Service, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud or abuse, and maintain backups and business records. Retention periods vary depending on the type of information:
  • account and subscription information is generally kept while your account is active and for a reasonable period afterward;
  • billing, tax, and accounting records may be kept as required by law;
  • support communications may be kept to manage support history and legal compliance;
  • logs and analytics data may be kept for security, debugging, analytics, and product improvement;
  • uploaded content, boards, bookmarks, chats, and team data may remain until separately deleted or retention is no longer needed.
Account closure and deletion requests are handled manually through support@refero.design. Closing an account disables access and de-identifies certain account identifiers. We separately review associated personal information and content for deletion or de-identification, subject to product functionality, technical limitations, backup retention, and legal requirements. We may retain certain information where required or permitted by law, including for tax, accounting, security, fraud prevention, dispute resolution, and legal compliance.

13. Security

We use administrative, technical, and organizational measures intended to protect personal information, taking into account the nature of the Service and Refero’s size and risk profile. Our practices evolve over time, and no method of transmission or storage is completely secure. You are responsible for keeping your account credentials secure and promptly notifying us of suspected unauthorized access.

14. International transfers

Refero Inc. is a Delaware corporation. Refero is operated from Spain and uses service providers located in the United States and other countries. Your information may be processed in countries that may have privacy laws different from those in your country. Transfer mechanisms vary by provider and processing context. Where applicable, safeguards may include Standard Contractual Clauses, adequacy decisions, Data Privacy Framework participation by eligible providers, or other lawful mechanisms. You may request information about applicable safeguards at support@refero.design.

15. Your privacy rights

Depending on where you live, you may have rights to:
  • access personal information we hold about you;
  • correct inaccurate personal information;
  • delete personal information;
  • object to or restrict certain processing;
  • receive a copy of certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of certain marketing communications;
  • appeal or complain to a privacy regulator.
To exercise rights, contact support@refero.design. We may need to verify your identity before responding. If your information is controlled by a team, organization, or business customer, we may direct you to that customer or assist them in responding.

16. California privacy information

If the California Consumer Privacy Act or similar laws apply, the categories of personal information we may collect include:
  • identifiers, such as email address, name, account ID, IP address, and online identifiers;
  • customer records information, such as billing and subscription details;
  • commercial information, such as plan, purchases, invoices, and subscription history;
  • internet or network activity, such as usage, searches, clicks, logs, and interactions;
  • approximate geolocation, such as location inferred from IP address;
  • audio, visual, or similar information, such as images you upload;
  • professional or employment-related information, if you provide it in team, billing, support, or business communications;
  • inferences, such as product preferences and feature usage patterns.
We use these categories for the purposes described in this Privacy Policy. We disclose these categories to service providers, processors, payment providers, analytics providers, AI providers, infrastructure providers, team admins or members, professional advisors, legal authorities, and business transaction counterparties as described above. We do not operate as a data broker or exchange personal information for money. We also do not knowingly sell or share personal information of children under 16. We do not use sensitive personal information to infer characteristics about you. If our analytics or similar practices are considered a “sale” or “sharing” under California law, you may submit an applicable opt-out request to support@refero.design. California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. To exercise rights, contact support@refero.design. California residents may also request information under California’s “Shine the Light” law about certain disclosures of personal information to third parties for their own direct marketing purposes, if applicable. To make that request, contact support@refero.design and include “California Privacy Rights Request” in your message.

17. Children

The Service is not directed to children or minors under 18, and we do not knowingly collect personal information from them. If you believe a child or minor has provided personal information to us, contact support@refero.design and we will take appropriate steps.

18. Changes to this Privacy Policy

We may update this Privacy Policy periodically. If we make material changes, we will take reasonable steps to notify you, such as by posting the updated policy, updating the “Last updated” date, sending an email, or showing an in-product notice.

19. Contact

Refero Inc.
Delaware corporation
Registered agent: Corporation Service Company, 251 Little Falls Drive, Wilmington, Delaware 19808, USA
Privacy contact: support@refero.design