Privacy Policy
1. What we collect
| Data | Why (purpose) | Legal basis (GDPR) |
|---|---|---|
| Account: email, name, salted password hash, optional profile fields and phone (for SMS reset), OAuth identifiers (GitHub/Google) | Create and secure your account; sign-in; recovery | Contract |
| Generation content: prompts, uploaded reference images, generated assets and previews | Run your generations; keep your library and history | Contract |
| Billing: token ledger, plan and subscription state, payment events from our processor (never card numbers), point-of-sale consent records | Deliver what you bought; refunds; legal record-keeping | Contract; Legal obligation |
| Operational: IP-derived request logs, rate-limit counters, security events | Keep the Service safe, debug problems, prevent fraud and abuse | Legitimate interests |
| Email/SMS content we send: confirmations, receipts, password resets, renewal reminders | Transactional messaging | Contract |
| Marketing preferences (only if you opt in) | Product news | Consent (withdrawable anytime) |
2. What we do NOT do
- No AI training on your content. Your prompts, images, and generated assets are never used to train, fine-tune, or improve AI models — ours or anyone's.
- No selling or sharing of personal information (including as "sell" and "share" are defined by the California CCPA/CPRA). We are currently below the CCPA's applicability thresholds, and we honor its spirit anyway.
- No ad trackers. The site uses session storage for sign-in state; no third-party advertising cookies.
3. Uploaded photos, faces, and avatars
Turning a photo into an avatar involves transient, automated processing of the image — which may include face geometry — solely to produce your 3D asset. We do not use it to identify people, do not build biometric databases or templates, do not sell or trade any of it, and do not retain source photos beyond the operational processing of your request and short-lived service logs. Generated assets remain in your library until you delete them. Only upload photos of yourself or of people who gave you written consent (see Terms §6).
4. Who processes data for us
We use a small set of service providers, bound to process data only on our instructions: cloud hosting (US), GPU/AI inference providers that execute generation requests, our payment processor (they handle card data; we receive only payment events), and an email/SMS delivery provider. We do not disclose personal data to third parties for their own purposes; we will disclose data if the law genuinely requires it and will tell you unless legally barred.
5. International transfers
The Service is operated and hosted in the United States. Where GDPR/UK-GDPR applies to your data, transfers to the US are protected by Standard Contractual Clauses with our processors, plus the safeguards above.
6. Retention
- Account and library data: for the life of the account; deleted (or irreversibly anonymized) within 30 days of account deletion, except billing records we must keep for tax/audit law.
- Source reference photos: not retained beyond processing your generation and transient operational storage.
- Billing ledger and purchase-consent records: retained at least 3 years (legal requirement).
- Security logs: short-term, rotating.
7. Your rights
Wherever you live, you can ask us to: access your data, correct it, delete it, export it (portability), restrict or object to processing based on legitimate interests, and withdraw consent at any time (e.g., unsubscribe). EU/UK users may also complain to their supervisory authority. To exercise any right, email foundry@jonathanarvay.com from your account email — we respond within 30 days.
8. Security
TLS everywhere; passwords stored as salted hashes only; optional two-factor authentication; bearer-token sessions; strict security headers and content-security policies; payment card data handled exclusively by the payment processor. No system is perfectly secure — if a breach puts you at risk, we will notify you and the relevant authorities as required by law (including the GDPR's 72-hour authority notification and Indiana's 45-day resident notification).
Responsible disclosure: found a security issue? Email security@jonathanarvay.com with details and, if possible, steps to reproduce — we ask that you not publicly disclose until we've had a chance to respond. See /.well-known/security.txt (RFC 9116).
9. Children
The Service is for users 16 and older and is not directed to children. We do not knowingly collect children's data; discovered under-16 accounts are deleted.
10. Changes
We will post any changes here and, for material changes, notify you on the site or by email before they take effect.
11. Contact
X AXIS LLC · Indiana, USA · foundry@jonathanarvay.com