1. Overview
SceneStudio ("we", "us") operates the AI image generation service SceneStudio (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Service. By using the Service, you agree to the data practices described in this policy.
2. Information We Collect
2.1 Information you provide
- Account information: your email address and an encrypted password (or a Google sign-in identifier) when you create an account or log in.
- Payment information: subscription payment details processed securely by our payment provider, Paddle. We do not store your card number directly.
- Uploaded images: images you upload as input for AI generation. These are processed transiently and are not permanently stored on our servers.
- Prompts and settings: the text prompts and configuration you use for image generation.
2.2 Information collected automatically
- Usage data: how you interact with the Service, including features used and generation history.
- Device information: browser type, operating system, and language settings.
- Log data: IP address, access times, and pages viewed.
- Cookies: authentication tokens, session, and language preferences needed to operate the Service.
3. How We Use Information
- To provide, operate, and maintain the Service.
- To process your image generation requests using AI technology.
- To manage your account and process subscription payments.
- To track your generation quota and usage history.
- To improve the Service, prevent fraud, misuse, and security incidents, and comply with legal obligations.
4. AI-Generated Content and Data
- Uploaded images and prompts are sent to our AI processing provider (Google Gemini) for processing.
- Uploaded images are used only to generate the requested output and are not retained after processing.
- Generated images may be stored temporarily for download and are not used to train our AI models.
5. Third-Party Services
The Service integrates with the following third parties:
- Supabase: database and authentication infrastructure.
- Google (OAuth, Gemini API): social login and AI image generation.
- Paddle: Merchant of Record for subscription payments and billing.
- Vercel: hosting and content delivery.
Each third party maintains its own privacy policy, which we encourage you to review.
6. Data Security
- Passwords are hashed using industry-standard encryption (bcrypt).
- Authentication is managed via secure HTTP-only cookies.
- All data transmission is encrypted using HTTPS/TLS.
- We apply reasonable security measures, but no method of transmission over the internet is 100% secure.
7. Data Retention
- Account information is retained while your account is active.
- Uploaded images are processed in real time and not permanently stored.
- Payment and subscription records are retained as required for accounting and legal purposes.
- You may request deletion of your account and associated data at any time.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate information.
- Deletion: request deletion of your personal information.
- Object: object to certain processing of your information.
To exercise these rights, please contact us using the details below.
9. Children's Privacy
The Service is not directed to children under 14, and we do not knowingly collect their personal information. If we become aware that we have done so, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date, and your continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this policy or our data practices, please contact us at support@thegreat.io