GDPR & data protection

Your data,
on your terms.

What we collect, why we are allowed to, how long we keep it, and the buttons in the product that let you act on all of it without emailing anybody.

Your rights

Six rights, and where to use them.

Under the GDPR and equivalent regimes you have these rights. Every one of them is a control in the product rather than a support ticket.

Access

Get a copy of everything we hold about you — account record, generations, credit ledger and audit trail.

Settings → Privacy → Request data export

Rectification

Correct anything inaccurate. Name, email and profile fields are editable directly.

Settings → Account

Erasure

Delete your account and personal data. Deletion is queued with a short cancellation window, then applied.

Settings → Privacy → Delete account

Restriction & objection

Ask us to stop a particular processing activity, including analytics and non-essential cookies.

Cookie preferences, or the contact form

Portability

Your export is machine-readable, so you can take it to another service without re-keying anything.

Included in the data export

Withdraw consent

Where we rely on consent — analytics cookies, marketing email — you can withdraw it at any time without losing access to the product.

Cookie preferences / email footer

What we hold

Every category, and why.

CategoryWhat that meansWhy
Account recordEmail, name, optional avatar, authentication provider, verification and roleRequired to give you an account
Security metadataPassword hash, session and token version, login timestamps, lockout counters, two-factor settingsProtecting your account
Content you createPrompts, settings, generated images, video and audio, collections and presetsDelivering the product
Credit & billing ledgerCredit balance and movements, plan, transaction records held by our payment processorBilling and fraud prevention
Support conversationsMessages you send us in chat or the contact formAnswering you
Technical logsRequest ids, IP address, user agent, error tracesSecurity, debugging and abuse prevention
Analytics (consent-based)Aggregated product events, only if you accept analytics cookiesUnderstanding what to improve

Lawful bases we rely on

  • Contract — running your account, delivering renders, keeping your credit balance correct.
  • Legitimate interests — security, abuse prevention, fraud detection and keeping the service reliable.
  • Consent — analytics cookies and marketing email. Both are off until you turn them on, and both can be withdrawn without losing access.
  • Legal obligation — retaining financial records for the period tax law requires.

Processors we use

We use a small number of specialist providers to run the service: cloud hosting and managed databases, a PCI-compliant payment processor, a transactional email provider, a support messaging platform, an error monitoring service, and the AI model providers that execute your renders.

Each is bound by a data processing agreement and receives only the minimum needed for its function — the payment processor never sees your prompts, and model providers never see your account identity. A current list of subprocessors is available on request with a DPA.

Prompts and generated content

Your prompt is sent to the model provider you selected in order to execute the render. It is not used to train our models — we do not train models. Generated output is private to your account and is never published, promoted or used as a marketing example unless you explicitly share it.

Retention

  • Generated assets — retained according to your plan's history window, then expired. You can delete any asset immediately at any time.
  • Account record — kept while your account is open; removed when you delete it.
  • Security and audit logs — kept for a limited period, then rotated out automatically.
  • Financial records — retained for the statutory period, even after account deletion, because we are required to.

International transfers

Some processors, including model providers, operate outside the EEA and UK. Where that happens we rely on Standard Contractual Clauses or an equivalent transfer mechanism, and we minimise what crosses a border.

Security

  • Encryption in transit everywhere, with strict transport security enforced.
  • Passwords stored as salted one-way hashes — never reversible, never logged.
  • Optional two-factor authentication with recovery codes.
  • Role-based access control internally, with an audit trail on privileged actions.
  • Rate limiting, bot protection and account lockout on repeated failed logins.

Breach notification

In the event of a personal data breach that presents a risk to you, we will notify the relevant supervisory authority within 72 hours and tell affected users directly, with what happened and what to do about it.

Requests, complaints and DPAs

Rights requests are handled in the product first — that is faster than any inbox. If you need a signed DPA, a subprocessor list, or want to raise a complaint, use the contact form and pick the matching topic. You also have the right to complain to your local data protection authority at any time.

Want the paperwork?

DPA, subprocessor list and security overview are available for teams that need them before they sign.

110+

AI models

Image, video & music — one prompt bar

22 / day

Free credits

Plus 0-credit models. No card to start.

Auto-refund

On failed renders

Credits reserved on start, refunded if it fails

One balance

For everything

Image, video and music on the same credits