Legal
Privacy Policy
Last updated: 7 September 2026
This policy explains which data is processed while you use the service, why it is processed and with whom it is shared.
Data processed
Account data: the name and email address received when signing in with Google. On accounts created without an email, no name or email is collected; the record consists only of an identifier generated by the system.
Usage data: the record of the generations you run, the prompt text you send, the model and size you select, the credits spent, and the status and time of the generation.
Payment data: the amount of the top-up, the payment method used, the payment status, the order id we generate, and the payment and checkout ids returned by the payment provider. For a payment made with cryptocurrency, the selected coin, the amount in that coin, and the payment address, the memo where the network requires one, and the network are also recorded. Card details are entered on the payment provider's own checkout page; the card number, the expiry date and the security code never reach us, and neither do wallet keys.
Technical data: request ids and error logs. These are kept in order to monitor the operation of the service.
Signup source: when an account is created, the path of the page on this site you entered through (for example /pricing) and, where you arrived from another site, that site's domain name. The full address, the query string and the full referring URL are not recorded, nothing is stored on your device for this, and the record is not updated after the account is created.
Purposes of processing
Providing the service, running generations and delivering their results to you.
Maintaining your credit balance and payment records, and building your billing history.
Seeing which pages of this site lead to accounts, so that what is written is measured rather than guessed. This is not used to build a profile of you or to target advertising.
Preventing abuse and the generation of prohibited content.
Meeting legal obligations.
Parties data is shared with
Generation providers: the prompt you send and any reference image URLs are passed to the third-party providers that perform the generation.
Payment providers: both the card and the cryptocurrency payment flows are carried out through third-party payment providers. The card flow runs through a provider acting as merchant of record, which is the seller of record for that transaction and collects the payment; the payment is completed on that provider's own checkout page.
Hosting provider: the application, database and file storage are hosted with a cloud infrastructure provider.
Authentication: account sign-in is performed through Google or, on accounts without an email, with a recovery code.
Some of these providers are located outside Türkiye; transferring data abroad is necessary in order to provide the service.
Retention periods
Generated files are deleted after 14 days.
Generation and payment records are kept for the duration of legal retention obligations.
When an account is closed the account data is deleted; billing records are kept for the period prescribed by law.
Cookies
Only strictly necessary cookies are used: a session cookie to keep you signed in.
No cookies are used for advertising, tracking or profiling.
Administrator access
The administrator operating the service can access generation records, submitted prompts and generated outputs for the purpose of monitoring abuse.
This access is used only to identify and block prohibited content — depiction of persons who are not of age and non-consensual content involving real people — and to resolve account and payment issues.
Credit and account actions performed by an administrator are recorded.
Security
API keys are stored only as a hash; they cannot be viewed again after creation.
Connections are encrypted end to end. Even so, no system can promise absolute security.
