Privacy Policy
Last updated: 11/5/2025
1. Information We Collect
Account Information
When you sign up using GitHub or Google OAuth, we collect:
- Email address (required for account identification)
- Name (optional, from your OAuth provider)
- Profile image URL (optional, from your OAuth provider)
- OAuth provider account ID (for authentication)
Usage Data
- Image generation prompts and selected attributes
- Generated images and associated metadata
- Gem usage statistics (remaining, used, purchased)
- API request logs (for debugging and rate limiting)
Payment Information
- Stripe customer ID and transaction details
- Payment amounts and transaction history
- Billing email address
2. How We Use Your Information
- Provide AI image generation services using OpenAI's DALL-E 3
- Store and manage your generated images securely
- Process gem purchases and manage transactions
- Track gem usage and enforce usage limits
- Provide customer support and technical assistance
- Improve our services and prevent abuse
3. Data Storage and Security
Database Storage
Your data is stored in a secure PostgreSQL database with:
- Encrypted connections and data at rest
- User-specific data isolation
- Automatic data deletion when accounts are removed
Image Storage
Generated images are stored securely in AWS S3 with:
- Private access with presigned URLs (7-day expiration)
- User-specific folder organization
- Automatic cleanup of expired URLs
4. Third-Party Services
Authentication
We use NextAuth.js with GitHub and Google OAuth providers. These services collect and process your authentication data according to their own privacy policies.
AI Services
We use OpenAI's DALL-E 3 API for image generation. Your prompts are sent to OpenAI and processed according to their privacy policy and terms of service.
Payment Processing
We use Stripe for payment processing. Payment data is handled by Stripe according to their privacy policy and PCI compliance standards.
Cloud Storage
We use AWS S3 for image storage. Images are stored securely in AWS data centers with appropriate access controls.
5. Data Retention
- Account data: Retained until account deletion
- Generated images: Retained until account deletion or manual removal
- Payment records: Retained for legal and accounting purposes (typically 7 years)
- API logs: Retained for debugging and security purposes (typically 30 days)
6. Cookies and Tracking
We use session cookies for authentication purposes only. We do not use tracking cookies, analytics, or third-party advertising services.
7. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13.
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes via email or through our service.
9. Contact Information
If you have questions about this privacy policy or our data practices, please contact us at:
- Discord: .rudarz
Sign up