Privacy Policy
Last updated: 29 August 2026
This policy explains which data is processed while you use the service, why it is processed and with whom it is shared.
Data processed
Account data: the name and email address received when signing in with Google. On accounts created without an email, no name or email is collected; the record consists only of an identifier generated by the system.
Usage data: the record of the generations you run, the prompt text you send, the model and size you select, the credits spent, and the status and time of the generation.
Payment data: the payment amount, the selected cryptocurrency, the payment status and the payment id returned by the provider. Card details and wallet keys never reach us.
Technical data: request ids and error logs. These are kept in order to monitor the operation of the service.
Purposes of processing
Providing the service, running generations and delivering their results to you.
Maintaining your credit balance and payment records, and building your billing history.
Preventing abuse and the generation of prohibited content.
Meeting legal obligations.
Parties data is shared with
Generation provider: the prompt you send and any reference image URLs are passed to the third-party provider that performs the generation.
Payment provider: the crypto payment flow is carried out through a third-party payment provider.
Hosting provider: the application, database and file storage are hosted with a cloud infrastructure provider.
Authentication: account sign-in is performed through Google or, on accounts without an email, with a recovery code.
Some of these providers are located outside Türkiye; transferring data abroad is necessary in order to provide the service.
Retention periods
Generated files are deleted after 14 days.
Generation and payment records are kept for the duration of legal retention obligations.
When an account is closed the account data is deleted; billing records are kept for the period prescribed by law.
Cookies
Only strictly necessary cookies are used: a session cookie to keep you signed in and a consent cookie to remember your age confirmation.
No cookies are used for advertising, tracking or profiling.
Administrator access
The administrator operating the service can access generation records, submitted prompts and generated outputs for the purpose of monitoring abuse.
This access is used only to identify and block prohibited content — depiction of persons who are not of age and non-consensual content involving real people — and to resolve account and payment issues.
Credit and account actions performed by an administrator are recorded.
Security
API keys are stored only as a hash; they cannot be viewed again after creation.
Connections are encrypted end to end. Even so, no system can promise absolute security.
