Privacy
What we store about your account
Your email address, your name if you give one, and a hash of your password. If you buy credits or subscribe, a Stripe customer reference. API keys are stored only as a SHA-256 hash, so a key can be replaced but never recovered — not by you, and not by us.
Identity verification
Age and identity verification runs through Stripe Identity. Your identity document and selfie go to Stripe, not to us: we never see or store them. What we store is the outcome — two boolean flags, the provider’s session reference, and a note if the check could not be completed. We derive the age flag from the verified date of birth, and we keep the flag rather than the date.
Generation requests
Every request you make — allowed or refused — is recorded with its prompt, the creator, the decision, the rule that fired if it was refused, and the boundary version it was evaluated against. This record is the point of the product. It is what a creator sees in their audit log, what a takedown is answered from, and what makes a refusal evidence that a rule was applied rather than an assertion.
The signed provenance manifest attached to authorised output carries a SHA-256 hashof your prompt, not the prompt itself. So a manifest can be published, quoted in a dispute or handed to a card network without disclosing what you typed — while anyone holding the prompt can still prove it is the one that was used.
What the creator’s agency sees
The managing agency for a creator sees requests made against that creator: the prompt, the context, the decision and the rule. It does not see your email address or your name. If you would rather a creator’s representatives did not see a phrasing, do not send it — the audit log exists precisely so that what was asked for is not deniable.
Reports
A report filed at /report stores what you wrote and, if you give one, your email address so the outcome can be sent to you. You may file without an email address; the report is recorded either way.
Processors
Stripe handles payments and identity verification. The database is hosted on Neon. Hosting is on Vercel. Generation, where an image provider is configured, sends the prompt to that provider — never your account identity.
Your rights, and one limit on them
You can request a copy of your data or its deletion by emailing contact us. Deleting your account removes your API keys, your credit ledger and your subscriptions.
Provenance manifests for output that was actually produced are the limit. They are retained after account deletion, with the requester field reduced to an opaque identifier, because a creator whose likeness is circulating needs the record to remain answerable. Deleting the consent record for an image that still exists would leave the person depicted worse off than the person who commissioned it.