Legal
Privacy Policy
Effective and last updated: July 29, 2026
This policy explains what data Image To Image processes, why we process it, who helps us provide the service, and how you can exercise your choices.
1. Information we collect
We collect account details such as your name, email address, authentication records, and basic security data including IP address and user agent. When you use the service, we process prompts, settings, uploaded images, generated images, task history, credit balances, and support communications.
Creem, KyrenPay or NOWPayments processes checkout information, depending on the payment option you choose. We receive transaction identifiers, payment status, pack details, and limited billing metadata, but we do not store full card numbers, wallet private keys, or recovery phrases.
2. How we use information
We use information to authenticate you, operate image tools, submit requested generation jobs, store and deliver results, process purchases, prevent fraud and abuse, provide support, maintain service reliability, and comply with legal obligations.
We do not sell personal information. We do not use your private uploads or generated results to train our own general-purpose AI models.
3. Service providers and transfers
We use Cloudflare for hosting, database, storage, security, and delivery; Kie.ai for AI generation; Creem, KyrenPay and NOWPayments for payments; Google for optional sign-in; and Resend for transactional email. These providers process only the information needed for their role and may process it in other countries under their own privacy and security terms.
Input images and prompts required for a generation request are sent to Kie.ai. Generated files are copied into our private storage after completion so they remain available through your authenticated account.
4. Retention and deletion
Uploaded images, generated images, and completed task history are retained for up to 100 days, then automatically removed from active storage. Security, payment, ledger, and legal records may be retained longer where needed for fraud prevention, accounting, disputes, or legal compliance.
You can delete individual assets from your account and request account deletion. Some transaction records may remain in a restricted form when retention is legally required. Provider-side temporary files may follow the provider's shorter retention period.
5. Security and your choices
We use access controls, private object storage, short-lived signed provider links, encrypted transport, webhook verification, rate limits, and least-necessary data access. No internet service can guarantee absolute security.
You may request access, correction, deletion, or a copy of your personal data, subject to applicable law. You may also revoke optional Google access through your Google account.
6. Children and policy changes
The service is not directed to children under 13, or under the higher minimum age required in their country. We do not knowingly collect children's personal information.
We may update this policy as the service or law changes. Material updates will be identified by a new effective date and, when appropriate, an in-product notice.
7. Contact
For privacy requests or questions, email hello@image-to-image.org.