Privacy Policy
Last updated: 22 September 2026
Who we are
Short version
- Your dumps and the files you upload are stored on our servers under your account so they follow you across devices. A guest who is not signed in keeps work only on their device.
- Magic (AI) features send the selected layer's pixels to fal.ai, our AI inference provider. Nothing else leaves our servers unless you publish a dump or a template.
- We use privacy-friendly, self-hosted analytics (Umami) and an error reporter (Sentry) with aggregate values only. No ad networks, no cross-site tracking cookies, no selling of data.
- You can delete your account, and everything under it, from the app at any time.
What we store on our servers
- Account. When you sign in with Google we store your email, name and avatar as Google provides them, your Google account id, and session rows that keep you signed in.
- Dumps (your designs). The design is autosaved to our database as JSON while you edit. We keep up to 6 recent revisions per dump for recovery, plus a small preview thumbnail. Deleting a dump removes it and its revisions; uploads that no other dump references are removed from storage (files uploaded in the last 15 minutes are kept for that window so an edit in progress does not lose them).
- Uploads. Photos, videos, GIFs, SVGs and custom fonts you upload are stored in our bucket under your account and count against your storage quota (1 GB Free, 5 GB Creator, 15 GB Studio). For videos we derive a 1080p proxy (a transcoded copy) for playback and export. Files are served only to you, unless you publish the dump or a template: then the files that dump uses are served publicly at unguessable URLs.
- Magic (AI) results. The output of a Magic feature is stored in your storage like an upload. We also keep a ledger of the credits spent, the tool used and the model version. We do not log the prompt content of Studio Styles (those prompts are ours, not yours).
- Billing. Your Stripe customer id, subscription id, plan, status and billing period dates. Card details go to Stripe directly; we never see card numbers.
- Onboarding survey (optional). If you answer the first-run survey, the answers are stored against your account, or against an anonymous id if you are not signed in.
- Pinterest connection (optional). An OAuth refresh token, so the connection survives reloads. See the dedicated section below.
- Bug reports. Reports you send from the app include your email so we can answer, plus the description you write.
What stays on your device
- An IndexedDB draft of the dump you are editing, restored if the tab closes in the middle of a save.
- localStorage preferences: theme, first-run flags, dismissed prompts and similar settings.
- A guest who is not signed in keeps their work only on the device. It is not sent to our servers until they sign in and the dump is saved.
Magic (AI) features
One exception: the one-tap cutout on desktop runs in your browser and the image never leaves your device. The pro cutout, cutouts on the phone, and every other Magic tool run on fal.ai.
Publishing: links and templates
- Public links (/d/...). A published dump is viewable by anyone who has the link. These pages are not indexed by search engines. You can unpublish at any time, after which the link stops working.
- Templates. When you publish a template, the design and the files it uses become public and are served to other users under the licence in the Terms. Templates are reviewed before they appear in the gallery, but the files are public from the moment you publish.
Billing and affiliates
Analytics and error reporting
- Umami (self-hosted on Railway) records page views and product events. It is privacy-friendly: no cross-site tracking cookies and no ad networks. Events carry aggregate values only (plan tier, tool used, counts), never emails or design content.
- Sentry receives application errors with technical context (browser, route, plan tier). We configure it not to send personal data or document contents.
Pinterest integration
- We request read-only access to your boards and pins (
boards:read,pins:read). We never request write scopes. - We store the OAuth refresh token in our database so the connection survives reloads. The token can be revoked at any time from Pinterest's app permissions or by clicking "Sign out" in dump's Pinterest panel.
- We never post, like, follow, comment, or modify anything in your Pinterest account.
Cookies
- A session cookie that keeps you signed in (required for the service to work).
- The PromoteKit affiliate cookie, set only when you arrive through an affiliate link (60 days).
- A beta-password cookie on the preview host, which only beta testers ever see.
- Theme and other preferences live in localStorage, not in cookies.
We do not show a cookie consent banner because we set no non-essential third-party tracking cookies.
Third parties
- Google: sign-in.
- Stripe: payments.
- Railway: hosting, database and object storage (Tigris).
- fal.ai: AI processing for the Magic features.
- Sentry: error reporting.
- Umami: analytics, self-hosted by us.
- PromoteKit: affiliate attribution.
- Pinterest: the optional read-only connection.
Some of these providers are in the United States. Where data leaves the EU it is covered by standard contractual clauses or the EU-US Data Privacy Framework, as applicable to each provider.
How long we keep things
- Dumps and uploads: until you delete them or delete your account.
- Revisions: a rolling 6 per dump.
- Error reports and logs: up to 90 days.
- Stripe billing records: as long as tax law requires.
Your rights (GDPR and elsewhere)
- Access and rectification: see and correct the data we hold about you.
- Erasure:delete your account from the app (account menu, "Delete account"). That removes your account, dumps, revisions, uploads and brand kit, and cancels any subscription. You can also ask us to do it.
- Portability: download your dumps from the app as exports.
- Objection: object to processing based on our legitimate interests.
Our legal bases: performance of a contract (accounts, storing your dumps, billing), legitimate interest (security, analytics, error reporting) and consent (the Pinterest connection, the optional survey). You can also complain to your local data protection authority; in Spain that is the AEPD.