Effective: 19 August 2026
Data we process
Google sign-in provides an account identifier, email, display name and avatar. We never receive or store your Google password.
Generation uses prompts, uploaded images, model settings, results and a truncated SHA-256 network identifier for rate limiting and abuse prevention.
Service providers
Google provides authentication, ApiMart and upstream models process generation, Waffo processes payments, and Cloudflare D1/R2 store application data and files. Each provider processes necessary data under its own policy.
We do not sell personal information or store payment-card numbers in our database.
Advertising and cookies
Only after AdSense approval and configuration may Google and its advertising partners place or read cookies, or use web beacons, IP addresses and other identifiers on public editorial pages for ad delivery, measurement and fraud prevention. Account, studio, pricing, order and payment pages do not load ads.
How Google uses partner-site data: https://policies.google.com/technologies/partner-sites . Before serving ads to visitors in the EEA, UK or Switzerland, the site will enable a Google-certified CMP supporting IAB TCF with consent, rejection and management choices.
Retention and rights
Account, order and credit ledgers are retained for fulfilment and audit. Reference uploads expire after one day and generated results after no more than 30 days.
Use the public GitHub Issues contact channel to request access, correction or deletion, except records required for legal or payment audit.