Privacy

Privacy policy

This lays down the legal structure from the PRD first. Formal policy language and operational details can follow later.

What we collect

For the public clone phase we only model the data structure conceptually: account details, prompt usage, generated assets, and payment events.

When backend features go live, each data source should be tied to a concrete retention policy and access boundary.

How we use it

Usage data supports account access, credit accounting, fraud prevention, and product analytics.

Generated assets should only be processed by server-side code paths and storage integrations that are explicitly configured for the product.