Cutout Studio

Legal

Privacy policy

This is a template for a demonstration deployment. Adapt it to the jurisdictions you operate in before going live.

What we store

  • Account details: your email address, an optional display name, a password hash, and the identifier of your Google account if you sign in that way.
  • Images: the file you upload and the cutout we produce, kept in an object storage bucket so you can download them again later.
  • Usage records: the credit movements on your account, the size and format of each job, and a keyed hash of the IP address behind each free preview.
  • Billing records: a Stripe customer id, the plans you bought and the state of your subscription. Card details are held by Stripe and never reach our servers.

Why we store it

  • To run the service you asked for: producing cutouts, keeping your balance accurate and letting you download files again.
  • To keep the free tier usable: the hashed IP address lets us count free previews per day without keeping a readable log of who visited.
  • To meet accounting obligations for payments we receive.

Who else sees your images

  • Cutouts are produced by a specialist AI processing provider acting on our behalf. Their storage of your files is switched off in our integration, so your images are not retained there.
  • Payments go through Stripe, which receives your email address and the plan you chose, never your images.
  • We do not sell personal data and we do not use your images to train models.

How long we keep it

  • Images stay until you delete them or close your account.
  • Credit and billing records are kept for as long as accounting rules require, even after an account is closed.
  • Hashed IP counters are per day and are only useful for the day they cover.

Your choices

  • You can delete individual images from your account page at any time.
  • You can ask for your account and its files to be deleted; we act on that within a few working days.
  • You can ask for a copy of the data we hold about you.

Cookies

  • We set two cookies: a short-lived session token and a refresh token. Both are httpOnly, so page scripts cannot read them. There are no advertising or tracking cookies.