Legal
Privacy Policy
Effective: 2026-05-01
Data we collect
- Email address and name (via Google OAuth or magic link).
- Reference images you upload (stored privately on DigitalOcean Spaces).
- Generated thumbnails (stored on DigitalOcean Spaces CDN).
- Chat messages with our AI assistant (stored to support reprompt flows).
- Credit transaction history (required for billing accuracy).
- Anonymised page views via PostHog Analytics (cookie-less mode).
How we use it
To provide the Service, send transactional emails (receipts, generation failures), and respond to support requests. We do not sell your data or use it for advertising.
Third parties
- Auth.js — authentication framework (self-hosted).
- Lemon Squeezy — payment processor and Merchant of Record (US).
- DigitalOcean — infrastructure (EU region, Frankfurt).
- Resend — transactional email (US).
- Anthropic / Google — AI providers. Your prompts are sent to their APIs per their privacy policies.
Retention and deletion
You may delete your account at any time from Account Settings. Personal data (email, chat history, reference images) is scrubbed within 30 days. Payment records are retained for 7 years as required by tax law.
Your rights (GDPR)
If you are in the EU/UK you have the right to access, rectify, or erase your data. Email [email protected] and we will respond within 30 days.
Cookies
We use only essential cookies (auth session). Analytics are cookie-less by default. No advertising cookies.