Privacy Policy
Effective: 2026-08-15 · Updated: 2026-09-11 (key storage, result retention and browser storage now match what the service actually does)
1. What we collect
- Account: your email, name and Google account identifier when you sign in with Google.
- API keys (optional): Gemini and OpenAI keys you add are stored only on your computer (browser storage) and are not sent to our servers. Keys added on our servers before 2026-08-25 may still exist — see sections 4 and 5.
- AI requests: your prompt, the selected part of the image, the generated result, and the model, time and estimated cost.
- Usage records: access and error logs. Prompt text is not written to server logs.
- Visit details: the time you first arrived, the page you landed on, where you came from (referrer), your chosen language, and your country (two letters). We do not store IP addresses — the country is the two-letter value Cloudflare attaches to the request. It tells us which regions use the service and cannot identify a person.
2. How images and prompts are handled
- Editing happens inside your browser. Only when you use an AI feature is the needed part of the image sent to our server.
- The original image and mask sent for AI processing are deleted as soon as the job finishes.
- Generated results are kept for 30 days so you can receive them, then deleted automatically. The period is an operational setting (AI_RESULT_RETENTION_DAYS); if it changes we update this page.
3. Third parties (AI processing)
When you use an AI feature, the selected image area and your prompt are sent to the services below. Each service handles data under its own policy.
- Google (Gemini API) — when you use your own key.
- OpenAI (Images API) — when you use your own key.
- AI processing relay (credits) — when you use credits, your image and prompt are sent to an overseas AI processing relay. The image is uploaded to that provider's file server and kept for up to 24 hours, then deleted automatically. During that time the file can be opened by anyone who knows its address. The relay in turn forwards the request to the model provider (Google, OpenAI and others). We will name the relay, its location and contact on request through our support channel. For sensitive images we recommend using your own key (BYOK) instead of credits.
- Paddle (payments) — when you buy credits, Paddle handles the sale as merchant of record. Your email and billing details go to Paddle; we never receive card numbers. See the Paddle Privacy Policy.
4. How long we keep things
- Account and generation records: until you ask us to delete your account.
- AI source images and masks: deleted as soon as the job finishes.
- AI results: deleted automatically after 30 days.
- API keys: we no longer store them on our servers. Keys added before 2026-08-25 remain encrypted until you delete them or your account is removed.
5. Your choices
- You can delete any old API key still held on our servers from the settings screen.
- Keys and settings held in your browser are removed by clearing site data in your browser. We cannot see those values, so we cannot clear them for you.
- You can ask us to delete your account and all records (keys and generation history included). Contact us and we will act without delay.
6. Security measures
- Any old API key still on our servers is encrypted (Active Record Encryption).
- All traffic is encrypted with HTTPS in production.
- Administrators cannot read your API keys or the contents of your images. For failure diagnosis only the first 40 characters of a failed prompt are shown to administrators.
7. Cookies and browser storage
- Cookies: a session cookie to keep you signed in, and a cookie that remembers your chosen language (one year). For our own traffic statistics, a random browser identifier cookie expires 30 days after the latest page request. We store its keyed hash with country, page-request counts, editor-entry and signup signals, and automation indicators; we do not store IP addresses in these visit records. We do not use advertising cookies.
- Browser storage: tool settings, presets, workspace layout and any API keys you add are kept in your browser. These are not sent to our servers.
8. Changes
We post changes on this page. Important changes, such as adding a third party, are announced on the sign-in screen.
9. Contact
Privacy contact: the operator ([email protected])
← Back to sign-in