Most data is kept while your account is open and deleted when you ask us to delete it. This page summarizes the privacy policy; where they differ, the policy applies.

What we keep and for how long

DataHow long
Account, prompts, uploads, results and safety recordsWhile your account is open
Credit history and billing statusWhile your account is open
Invoices and payment records at StripeAs tax and accounting law requires
Password reset tokensStored only as a hash, valid for a short time
Rate limit countersIn memory only, never written to disk, cleared when the server restarts
Deleted data in backupsUntil the backups rotate out, as the privacy policy states

Where your files are stored

Uploads and results are stored in cloud storage, and the app and database run on servers in the EU; the privacy policy names the providers and locations. Your files reach you through access checks or short-lived signed links. A result you share to the gallery becomes public until you unshare it.

What model providers keep

Your prompt and files also pass through the gateway and the model provider that ran your job. Their own policies govern how long they keep request data; some keep it for a limited time to monitor abuse. See Do you train on my images.

Deleting data

You can do these yourself:

  • Unshare a result to take it out of the gallery.
  • Remove a saved API key on your account page.

For everything else, email us from the address you sign in with:

  • Specific generations: tell us which ones (date and tool or model), and we delete them.
  • Your whole account: see Delete your account. Unused credits are lost when an account is deleted.

Note

Downloaded files are copies on your own device. Deleting them from your account does not remove copies you or others already saved.

Browser storage

Your browser also keeps some data for the site, such as the sign-in cookie and a draft of your prompt and settings while you sign in. The privacy policy lists the cookies and browser storage the site uses.