Privacy Policy
2026-09-14
On this page
Local tools
Your image stays in browser memory or temporary IndexedDB handoff storage.
Cloud tools
When you select Generate in a cloud AI tool, the image and instructions are uploaded over HTTPS to private Cloudflare R2 storage and sent to fal for AI hairstyle and hair color changes, or WaveSpeed for other requested inference. Limited guest use is available for text tools. Our source and result access expires after 24 hours; scheduled cleanup and R2 lifecycle rules remove temporary content. Provider retention is governed by the provider's own privacy policy. Account, task and financial metadata may be retained separately. Submitted prompts, generated prompt text and generation settings are stored separately for administrator-only operational review and support, including after temporary images expire or results are deleted. Provider billing records are retained for cost reconciliation. These records are not public and are not included in product analytics events.
Account data
D1 stores your Google subject ID, verified email, name, credits and hashed sessions.
1. Local image processing
Tools marked “Runs on your device” decode and process images inside your browser. We do not receive those images. Local AI tools may download version-pinned runtime and model files and cache them in your browser; image pixels are not included in those model requests. A result passed to another tool can remain in IndexedDB for up to 30 minutes and is deleted after use.
2. Cloud image processing
When you select Generate in a cloud AI tool, the image and instructions are uploaded over HTTPS to private Cloudflare R2 storage and sent to fal for AI hairstyle and hair color changes, or WaveSpeed for other requested inference. Limited guest use is available for text tools. Our source and result access expires after 24 hours; scheduled cleanup and R2 lifecycle rules remove temporary content. Provider retention is governed by the provider's own privacy policy. Account, task and financial metadata may be retained separately. Submitted prompts, generated prompt text and generation settings are stored separately for administrator-only operational review and support, including after temporary images expire or results are deleted. Provider billing records are retained for cost reconciliation. These records are not public and are not included in product analytics events.
3. Google sign-in
We request the OpenID Connect scopes openid, profile and email. We store Google’s stable account subject, verified email, display name and optional avatar URL. Google access and ID tokens are not persisted. Session cookies are HttpOnly and only a SHA-256 hash of the session token is stored in D1.
4. Usage events
The workspace records a small set of product events such as file selected, process success and download. Properties contain technical values such as format, byte size and latency. We do not send image pixels, original filenames, prompts or EXIF data in these events.
5. Control and deletion
You can delete a temporary cloud source immediately from your dashboard. Closing or resetting a local workspace releases its Blob URLs. To request account deletion before a self-service flow is available, contact the site operator at the address on the Contact page.
Payments and credit records
Stripe processes checkout and payment details. We store order references, payment status, credit purchases, task reservations, releases and refund adjustments. We do not store full card numbers or CVCs. Financial records are retained for account support, reconciliation and applicable recordkeeping requirements.
Guest access and abuse prevention
An HttpOnly guest cookie identifies limited free usage. We use a secret-keyed hash of the network address, account counters and Cloudflare Turnstile to prevent abuse. Turnstile processes verification data under Cloudflare's policy. Free limits reset in UTC; failed attempts may still count toward the shared service budget. Guest/network identifiers on older task records are cleared after 35 days. An image saved before sign-in or checkout stays in local browser storage, can be restored for 30 minutes and is removed when retrieved.
Advertising and your choices
Public content pages may display Google AdSense ads. Google and other advertising partners may use cookies, web beacons, IP addresses and other identifiers to deliver, measure and protect ads. Advertising cookies may personalize ads based on previous visits to this and other websites, subject to your consent where required. We do not send your images, filenames, prompts, account email or payment details in ad requests. You can manage or opt out of personalized advertising in Google’s Ads Settings and change your choices through a consent message when one is shown.