Privacy Policy
Last updated: March 16, 2025
1. Information We Collect
Account information
When you sign in with Google OAuth, we collect your email address. We do not collect passwords.
Card content
Text, photos, and other content you provide when creating intro cards. This data is used to generate your cards and is not shared with third parties except as needed to process your request (e.g., AI generation APIs).
Payment information
Payments are processed by Stripe. We do not store your credit card number. Stripe may collect information as described in their privacy policy.
Usage data
We may collect basic usage data such as pages visited, features used, and error logs to improve the Service.
2. How We Use Your Information
- To provide and maintain the Service
- To process payments and manage credits
- To generate intro cards using AI
- To communicate with you about your account
- To improve the Service
3. Data Sharing
We do not sell your personal data. We may share data with:
- AI providers (e.g., Google Gemini) to generate card content. Only the text and images you submit for card generation are sent.
- Stripe to process payments.
- Hosting providers (e.g., Vercel, Supabase) to operate the Service.
4. Shared Cards
When you share a card via a public link, the card content (name, role, bio details) becomes publicly accessible at that URL. You control what information appears on your card.
5. Data Retention
We retain data according to the following schedule:
- Account data (email, credits): retained for as long as your account is active.
- Session tokens: expire after 30 days of inactivity.
- Shared card history: retained while your account is active so you can reload recent shared cards.
- Payment records: retained for 7 years to comply with financial regulations.
- Feedback submissions: retained indefinitely unless you request deletion.
You can request deletion of your account and all associated data by emailing us. We will process deletion requests within 30 days.
6. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise these rights, please contact us at the email address listed on our website.
7. Cookies
We use essential cookies to maintain your login session (a signed JWT token stored in an httpOnly cookie). We do not use third-party tracking cookies.
8. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), signed session tokens, and secure payment processing through Stripe.
9. Children
The Service is not intended for users under 13 years of age. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes through the Service or by email.
11. Contact
If you have questions about this privacy policy, please contact us at support@aicardgenerator.app.