Privacy and data notice

Your data, without vague promises.

This page explains what the pre-release service processes, why it is needed, which service providers may receive it, and which controls are available to you. Launch-region privacy, residency, age-limit, and legal-basis review is still pending; this notice does not claim production legal approval.

Account and access data

We process the name and email attached to your account, verification state, connected sign-in identities, and the device and session information needed to authenticate you and protect access.

Passwords are stored as password hashes. Session, security, OAuth-state, and API-key secrets are stored as hashes where the product contract requires them; full API keys are shown only when first created.

Prompts, settings, and images

A generation request contains your prompt, selected model, aspect ratio, style, quality, and optional project. The service stores generation metadata and private result assets so you can use history, projects, favorites, variations, and downloads.

Generations are private by default. The product does not place them in a public gallery or publish them automatically.

Billing and support records

Stripe handles payment collection. The service stores the customer, subscription, order, payment, refund, dispute, and credit-ledger references required to fulfill purchases and reconcile billing, but it does not ask you to send full card details through the product.

Private support tickets retain the subject, category, priority, messages, and related account context needed to investigate your request.

Analytics and security events

Google Analytics 4 measures page visits when the site loads. Advertising storage, advertising user data, personalization, Google Signals, and ad-personalization signals are disabled. Prompts, generated images, account identifiers, emails, billing identifiers, and project names are not added to analytics events.

Operational logs and request records may include timestamps, coarse network hints, request IDs, status, latency, and security or billing-review events needed to detect abuse, debug failures, and protect account balances.

Service boundaries

When data leaves the application boundary.

Cloudflare

The acceptance runtime uses a Cloudflare Worker, D1 for relational records, and private R2 objects for generated assets.

Image providers

The selected model and provider are shown before generation. If an external provider is configured and selected, the prompt and generation settings required for that request are sent to that provider. No verified Qwen Image 3 provider is connected today.

Stripe and sign-in providers

Stripe processes paid Checkout and billing management. Google or GitHub receives the standard OAuth request only when you choose that sign-in method; provider availability is shown in the interface.

Google Analytics

GA4 receives reviewed page-view data. Product code is designed not to add prompts, generated assets, user IDs, email addresses, billing identifiers, or project names to those events.

Your controls

Export, review, and delete account data.

Studio provides account-data export, session review, API-key revocation, project controls, and account deletion. Account deletion first attempts to cancel the Stripe subscription and remove the Stripe customer; local identity, assets, projects, credits, sessions, keys, and connected identities are deleted only after that external cleanup succeeds.

No universal public retention period is claimed yet. Scheduled maintenance removes expired operational state and continues draining legacy guest assets, while backup deletion, restore evidence, and production retention telemetry remain unverified.