Data we process
- Google account email, display name, avatar, and authentication identifiers.
- Prompts, uploaded references, generated media, task status, and credit records.
- Subscription identifiers and invoice status from Stripe. We do not store card numbers.
- Security logs, device information, and privacy-safe product events.
Processors
Supabase provides authentication, database, and private storage. Kie processes generation inputs and returns model outputs. Stripe processes payments and billing.
Private storage
User media is stored in private buckets and delivered with short-lived signed URLs. A media URL is not used as the durable history record.
Deletion
You can request account and media deletion through the configured support channel. Legal billing records and abuse-prevention records may be retained where required.
Analytics boundaries
Analytics events do not include prompt text, upload filenames, generated media, or other private user content.