Privacy policy
1. What is collected
- Account data. Your email address and a hash of your password. The password itself is never stored.
- Prompts and parameters. The text you write and the settings you choose for each generation.
- Generated media. The images and videos produced for you, plus their dimensions, duration, and size.
- Payment references. Identifiers issued by the payment provider for your customer record, subscription, and payments. Card numbers are entered on the provider’s page and never reach this service.
- Operational records. A hashed IP address, the browser user-agent string, credit ledger entries, and an audit log of security- and billing-relevant actions.
2. Prompts are encrypted at rest
Prompt text is encrypted with an authenticated cipher before it is written to the database and decrypted only to run your job or to show it back to you. Database backups therefore contain ciphertext, not readable prompts.
3. No prompt text goes to analytics
Prompt text is never sent to analytics, error reporting, or any third-party measurement tool. Application logs carry identifiers, status, and timing; sensitive fields are redacted before a log line is written. Moderation records store reason codes and a policy version, not a copy of the text that triggered them.
4. Who else sees your data
To run a generation, the prompt and its parameters are sent to the model provider selected for that model. Generated media is held in private object storage. Payments are processed by the payment provider. Each of these acts as a processor under contract; none is given your data for its own purposes.
Nothing you generate is public. There is no gallery, no sharing, and no default under which one account can see another’s output.
5. How long things are kept
Generated media is kept for the retention window of the plan that produced it, then deleted from storage. The window for your plan is shown on the plans page. Prompts are kept alongside their generation record for the same period.
Credit ledger entries, invoices, and audit records are kept longer because they are financial and security records and must remain reconstructible. They identify an account, not the content of what was generated.
6. Deleting your account
Account deletion is available from your dashboard and requires an explicit typed confirmation, because it cannot be undone. It removes your generated media, your prompts, and your active sessions, and closes the account.
Ledger and audit records survive deletion in a minimised form, retained only as long as accounting and anti-fraud obligations require. Any remaining credits are forfeited on deletion; cancel first and use them if you intend to. Backups are overwritten on their own rotation schedule, so a copy may persist there briefly after the live record is gone.
7. Your rights
You may request access to, correction of, or export of your personal data, and you may object to or restrict certain processing. Deletion can be exercised directly from the dashboard as described above. The contact point for every other request, and the supervisory authority you may complain to, must be named here before this page is published.
8. Support access
Support staff cannot access identity or age-verification materials by default; only a minimal reference and a pass or fail status is stored, and access to anything beyond it requires a separate, logged authorisation. Support access to account data is limited to what a specific request needs and is recorded in the audit log.
9. Security
Data is encrypted in transit and at rest. Generated media is served only through short-lived signed links. Session cookies carry a random token whose hash alone is stored, so a database leak yields no usable sessions.