Privacy Policy

Effective 2026-04-15

We care about your privacy. This page explains what we collect, how we use it, and the rights you have over your data. Plain English first; legalese only where unavoidable.

Data we collect

  • Account info: email, optional name, optional avatar URL (from OAuth provider).
  • Uploads: photos you upload to generate from. Stored privately in our object storage; only you and our admins can access them.
  • Generated images: stored in our public CDN bucket. Not listed publicly unless you mark them as public.
  • Usage: which tools you use, prompts and presets selected, credit transactions, IP address and basic device metadata.
  • Payments: processed by our payment provider (Stripe). We never store full card numbers — only an opaque reference.

How we use your data

  • To run the service: authenticate you, generate images, charge your account.
  • To send transactional email (purchase receipts, security notices, expiry warnings).
  • To improve the service: aggregated anonymous analytics on which features are used.
  • To comply with legal obligations and prevent abuse.

We do notsell your data to third parties. We do not use your uploaded photos to train any AI model unless you explicitly opt in (we don’t currently offer such an opt-in).

Third-party processors

  • Supabase — database, authentication, file storage.
  • Replicate (and/or other model providers) — runs the AI generation; your photo is sent to them solely for that purpose.
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Vercel / Cloudflare — hosting and CDN.

Your rights

Depending on your jurisdiction (GDPR / CCPA / similar) you may have the right to:

  • Access a copy of your data.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Withdraw consent / opt out of marketing email.

You can exercise these by emailing us via /contact. We respond within 30 days.

Data retention

  • Account data: kept while your account is active.
  • Uploaded source photos: retained for 90 days then automatically purged.
  • Generated images: kept until you delete them.
  • Payment + audit records: kept for at least 7 years for tax/legal compliance.

Cookies

We use first-party cookies for authentication and a referral cookie when you visit a/r/<code> link. We do not use third-party advertising cookies.

Children

The service is not directed at children under 13. If you believe a child has uploaded a photo of themselves, contact us and we will delete it promptly.

Contact

Privacy questions go to /contact.