Privacy Policy
Your product data stays tied to a private order.
Effective July 19, 2026This policy explains which information the service processes, why it is needed, where it is sent, and how access works without an account.
Information we process
We process the product photos, product facts, target channel, chosen style and package, buyer email, payment references, technical request metadata, generation records, and files needed to fulfill and support an order. Stripe handles payment details; the service does not store full card or bank-account information.
How the information is used
Information is used to validate the order, secure payment, create and deliver product cards, send the private result link, prevent duplicate processing, handle technical failures and refunds, protect the service, and meet accounting or legal obligations. Product inputs are not used to create public galleries or testimonials.
Service providers
The service relies on Vercel for application hosting and workflows, Supabase for private database and file storage, Stripe for payment, Google Gemini for AI-assisted planning and visual generation, and Resend for transactional email. Each provider processes the information needed for its role under its own data-processing terms.
Private links and browser history
Every order uses an unguessable private capability link instead of an account. Anyone with that link can access the order, so treat it like a password and share it only with people you trust. After paid access is confirmed, the full private link and a small order summary are stored in this browser's local storage. This history remains until you remove the order, clear site data, use private browsing, or the browser evicts it.
Retention and deletion
Abandoned drafts and failed temporary artifacts are removed on a state-aware schedule. Successful paid source and result files have no automatic product-level expiry in this first version so the buyer can recover the order. Minimal financial and operational records may be kept where required for support, accounting, fraud prevention, or law. To request deletion, use the support contact included in your order email. Some records may need to be retained where the law requires it.
Security and your choices
Files are kept in private storage and downloads use short-lived signed URLs. Access tokens are stored server-side only as cryptographic hashes. You can remove an order from one device through Your purchases; this does not delete the server order. Keep the emailed link if you need recovery after clearing browser storage.