Privacy Policy
Last updated: 2 August 2026
This policy covers everything at 60fps.design: browsing the site, a 60fps PRO subscription, and the 60fps MCP server at mcp.60fps.design.
Our Terms of Use cover the rules for using 60fps, and sit alongside this policy.
60fps is operated as a sole proprietorship from Bengaluru, India, and is the data controller for the information described here. Contact: admin@60fps.design.
We do not sell data, we do not run advertising, and we do not build profiles for anyone else.
The short version
Browsing the site is measured with analytics, including a tool that records how people move through pages. Subscribing means we hold your email and licence key so we can check your subscription and stop one key being shared across a crowd. Using the MCP means we keep the searches your AI tool sends, so we can see which ones come back empty and fill the gaps.
We do not store your conversations with any AI tool, and we do not train any machine learning model on your data.
When you browse 60fps.design
Analytics. We use Google Analytics to count visits and see which pages get used.
Session recording. We use Microsoft Clarity, which records how people move through pages: clicks, scrolling, mouse movement, and the pages visited. This is how we find parts of the site that are confusing or broken. It is behavioural, so we want to be plain about it rather than bury it in a list.
Both set cookies and both send data to their own providers. They run on 60fps.design only. They do not run on the MCP server, which is covered in clause 4.
If you would rather not be measured, browser level tracking protection and Do Not Track settings block both, and we do not attempt to work around them.
When you subscribe to 60fps PRO
Your email address and subscription status. These come from Gumroad when we check your key, along with a purchase ID, product ID, and your subscription dates. We keep them to tell whether your subscription is active. Payment is handled by Gumroad and we never see your card details.
Your licence key. We store it so we can check it without asking Gumroad on every request. The same key works on the website and on the MCP.
Sign in sessions. When you sign in on the website we issue a signed token, stored in your browser, that lasts 30 days. We keep a record of the sessions attached to your licence so the two device limit can be enforced and so a session can be ended.
Device fingerprints. A PRO licence works on two devices. To count them we derive a one way hash from characteristics of your connection and a secret we hold. It tells one device apart from another without identifying you, and it cannot be reversed.
IP addresses. Your IP is used for a moment to apply rate limits, then discarded. For longer term counts we keep only a short one way hash of it, never the address.
When you use the 60fps MCP
mcp.60fps.design sets no cookies, runs no analytics, and makes no third party requests. This is true of the MCP server specifically. It is not true of the website, which is covered in clause 2.
Your licence key. Every request carries one, and we store it so we can check it without asking Gumroad each time.
IP addresses. Used momentarily for rate limits, then discarded. Only a short one way hash is kept for longer term counts. IP addresses also appear in our hosting provider's request logs, and in a short line we write when a request fails to authenticate.
Device fingerprints. As described in clause 3. Connections made through an app connector such as Claude or ChatGPT are not counted against the device limit.
Searches sent to the MCP. When your AI tool searches the library, the search text is stored. This is the signal that shows which searches return nothing, which is how gaps get found and filled. We keep your most recent 50 searches, and the most recent 1,000 across everyone.
Usage counts. Which tools were called, how often, and whether a search found anything. These are attached to a hash of your licence key, not to your name or email.
OAuth connections. If you connect through an app such as Claude or ChatGPT, we store what that app sends us when it registers, and we store access and refresh tokens only as one way hashes. We never keep a usable copy of a token.
What we do not collect, and what we do not do
We do not store your conversations with Claude, ChatGPT, Cursor or any other AI tool. The MCP receives one search or one shot identifier at a time and nothing else from the conversation.
We do not train, fine tune, test or evaluate any machine learning model on your searches, your usage, or anything else you send us.
We do not receive card details. Gumroad handles payment.
We do not read files, code, or anything else from your computer.
We do not touch your AI tool's memory, chat history, or saved files.
Why we are allowed to hold it
Where data protection law such as the UK or EU GDPR applies, our lawful bases are:
Performance of a contract, for the licence check, the device cap, sign in sessions, and delivering the service you have paid for.
Legitimate interests, for rate limiting, spotting abuse, and the usage counts and stored searches that tell us which parts of the library are missing. We keep this to the minimum that answers the question, which is why IP addresses are hashed and licence keys are reduced to a hash before being attached to usage.
Consent, where it is required for the analytics and session recording in clause 2.
Legal obligation, where we are required to keep or produce records.
How long we keep it
Licence checks are kept for 30 days and refreshed whenever you use the service. A rejected key is remembered for 60 seconds so a broken setup does not hammer Gumroad.
Rate limiting counters live for 60 seconds.
Sign in sessions last 30 days, and end sooner if you sign out or the session is replaced.
Device fingerprints stay until the device has been idle long enough for its slot to be reclaimed, which takes 15 minutes.
OAuth access tokens expire after 1 hour. Refresh tokens last 30 days, and the registration an app creates lasts 90 days. Removing the connector in your tool deletes all of them at once.
Searches, hashed IP addresses and day by day usage are kept for 90 days, then deleted.
Running totals per licence, such as how many searches you have made, are kept while your subscription is active.
Analytics and session recordings are kept under the retention settings of Google Analytics and Microsoft Clarity.
Hosting request logs are held by Vercel under their own retention policy, not ours.
Who else handles your data
We use a few providers, only for the purposes below, and we share your data with nobody else.
Gumroad issues licence keys and processes payment. When we check a key, we send that key to Gumroad.
Upstash hosts the database behind clauses 3 and 4.
Vercel hosts the website services and the MCP server. Their request logs record the IP address, user agent and path of each request. The lines we write ourselves record an IP address and a shortened user agent, and never a licence key.
Framer hosts and serves 60fps.design.
Google Analytics and Microsoft Clarity measure use of the website, as described in clause 2.
Where your data is processed
60fps is operated from India. Requests are received at an edge location near you and processed on servers in the United States, and the providers above operate their own infrastructure across several countries.
Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected or deleted, to object to or restrict how we use it, and to withdraw consent for the analytics in clause 2. Email admin@60fps.design and we will deal with it. If you are unhappy with how we handle a request you can complain to your local data protection authority.
Cancelling your subscription and asking us to delete your data are separate things. Cancelling happens in Gumroad. Deletion happens by emailing us.
Changes
If this policy changes in a way that matters, we will update the date at the top and, for anything significant, tell subscribers by email.
Questions: admin@60fps.design