Last updated: September 12, 2026
For credit purchases, we also keep payment references, purchased credits, balances, refunds and related account records. Stripe processes card payments; we do not store your full card number or security code.
Only to run the Service: to sign you in, store your work, generate the content you ask for, publish to the platforms you connect, and keep the Service secure. We do not sell your data, and we do not use your content to train AI models.
Your data is stored in Google Firebase (Firestore and Cloud Storage). The application server runs on Railway, and traffic may pass through Cloudflare. Some generated assets are automatically deleted after a retention period (currently about 15 days for generated ad images and card images).
Stripe processes one-time credit payments and receives the information needed to process those payments.
We share nothing with anyone else, and nothing for advertising purposes.
The Service uses authentication state (Firebase) to keep you signed in. There are no third-party advertising or analytics trackers.
Saved libraries share 100 MB per account unless support grants additional space. We record file sizes and upload information to enforce storage limits. Deleting saved files removes unreferenced copies from storage; a copy shared by another saved folder remains until it is no longer referenced. Failed cleanup is retried.
Temporary generation references have a separate 100 MB limit and expire after 24 hours. Files hosted by AI providers follow their own expiry periods. Keep a downloaded copy of work you need to retain.
Media download links can be accessed by anyone who has the link. Reference links are shared with the AI provider when needed for a generation request. Avoid sharing download links to private work.
Your account data is kept while your account is active. Generated assets are cleaned up automatically on a rolling basis. To delete your account and its data, email [email protected] from your account's email address and we will remove it within a reasonable time, except where retention is required for legal or security reasons.
Access to data is restricted by per-account security rules (each account can only read and write its own data), provider secrets are kept server-side only, and connections use encrypted transport (HTTPS). No system is perfectly secure, so keep your login credentials and API keys private.
You can disconnect any linked platform at any time from the app's settings, ask us for a copy of your data, or ask for deletion (section 6). If you believe data is held about you in error, contact us.
We may update this policy from time to time; the "Last updated" date above reflects the current version. Meaningful changes will be visible here before they take effect.
Privacy questions: [email protected].