Privacy Policy
Last updated: 2026-05-09
What we collect
- Account: email address (and Google profile name if you sign in with Google).
- Uploads: the photos you upload, the masks you draw, and the AI outputs.
- Consent log: for every upload, your IP address, timestamp, and the consent text you accepted.
- Payments: handled by Stripe. We never see your card number; we store only the Stripe customer ID and subscription state.
How long we keep things
- Uploaded source images: deleted from storage after 7 days.
- Processed outputs: kept in your account so you can re-download. Delete from your dashboard at any time.
- Consent logs: kept for 12 months for legal-defensibility purposes.
- Account email: kept until you delete your account.
Where we send data
Photos and masks are sent over HTTPS to Replicate, a US-based AI infrastructure provider, for inference. Replicate does not train models on your inputs and deletes them after processing. Authentication and storage are handled by Supabase. Payments go through Stripe. We do not sell your data.
Your rights
You can export, delete, or correct your data at any time. Email marshall@onepic.ai for assistance. California residents have additional rights under CCPA; EU/UK residents under GDPR. We honor all valid requests.
Cookies
We use session cookies for sign-in only. We do not use third-party advertising cookies.