⚠ Draft — pending legal review

This is an honest working draft written for product development, not by a lawyer. It is not yet in effect and must be reviewed and approved by a qualified lawyer before it binds anyone. Nothing here is legal advice.

To be decided by Darren / a lawyer

  • Data controller legal entity and, if required, a Data Protection Officer.
  • Legal bases for processing and international-transfer mechanisms (GDPR/UK GDPR/CCPA).
  • Exact data-retention periods.
  • Confirm the live AI-provider list and data-processing agreements before launch, and keep §3 current.
Legal

Privacy Policy

What we collect, exactly which providers your prompts and uploads are sent to, how long we keep it, and how to get it deleted.

v1 · Draft 22 July 2026 · not yet in effect

1. The short version

To generate anything, your prompts and uploads leave our servers and are sent to third-party AI providers to be processed. We collect what we need to run your account and your generations, we tell you exactly who we share it with below, and we never sell your personal data.

This policy explains what we collect, where it goes, how long we keep it, and how to get it deleted. The data controller is [TODO: Legal entity name]; contact details are on our Contact page.

2. What we collect

You give us

  • Account details — name, email, and anything you add to your profile (avatar, bio, username).
  • Your prompts and the reference images or files you upload.
  • The content you generate, and anything you publish, save to boards, or submit to a challenge.
  • Messages you send — to Koko, in community and challenge chat, and to support.

We generate as you use IDALL

  • Credit balances and a transaction history of what each generation cost.
  • Generation history — which model you used, settings, and the result.
  • Membership and payment status (but not your card — see §4).
  • Basic technical logs — IP address, device/browser, and timestamps — used for security, abuse prevention, and to keep the service working. Challenge terms acceptance is logged with version, time, and IP because the rules require it.

3. Where your data goes — our providers

We use a small set of trusted companies (“processors” or “sub-processors”) to run IDALL. Each receives only what it needs for its job.

Infrastructure

  • Supabaseour database, login/authentication, and file storage. Holds your account, content, and credit records.
  • Vercelhosting and content delivery — the servers that run the site and app.
  • Bunny (Bunny Stream)video hosting and CDN — generated videos are re-hosted here so they stream reliably.
  • Resendtransactional email (login links, receipts, notifications).

Payments

  • Stripeprocesses payments. Your card is entered on Stripe and never reaches us (see §4).

AI model providers — who your prompts and uploads are sent to

When you generate, your prompt and any reference files are sent to the provider running the model you chose. These providers process your content under their own terms and privacy policies:

  • PiAPIour main generation gateway. It routes your request to the underlying image/video model — which currently includes models such as Seedance, Kling, Hailuo/MiniMax, Luma, and Midjourney.
  • fal.aiimage generation and upscaling.
  • OpenAIpowers Koko (your AI mentor) and some text and image features.
  • Anthropic (Claude)powers some AI assistance and skills features.
  • ElevenLabsaudio and voice generation, where you use it.
  • Stability AIimage generation, where used.
Be aware: we choose reputable providers, but once your content reaches a provider it is handled under that provider’s policies, which we do not control. Do not upload anything you are not comfortable sending to a third-party AI service. [TODO: confirm the live provider list and data-processing agreements before launch; keep this section current as models are added or removed]

We do not sell your personal data, and we do not share it for third-party advertising.

4. Payments — we never see your card

Payments run through Stripe’s hosted checkout. Your card details are entered on Stripe and never touch our servers or database. We store only a Stripe customer reference and your payment/subscription status, so we can grant credits and manage your membership. See the Refund & Billing terms.

5. How we use your data

  • To run generations and keep your credit balance and history accurate.
  • To provide your account, Koko, community, and challenges.
  • To prevent abuse and enforce our Acceptable Use Policy — including automated safety filtering of prompts and outputs.
  • To communicate with you about your account, and (only if you opt in where required) about products and updates.
  • To meet legal, tax, and accounting obligations.

[TODO: confirm the legal bases for processing — e.g. contract, legitimate interests, consent — with a lawyer for your target markets (GDPR/UK GDPR/CCPA).]

6. How long we keep it

  • Account and generated content: while your account is active.
  • Credit and payment records: kept as long as needed for accounting, tax, and legal reasons after that.
  • Prompts/uploads sent to providers: retained by each provider under its own schedule, which we do not control.
  • Security logs: kept for a limited period for abuse prevention.

[TODO: set exact retention periods with legal review.]

7. Your rights and deletion

Depending on where you live, you can ask us to access, correct, export, or delete your personal data, and to object to or restrict certain uses. To do any of these, email us from your account address at our contact page.

When you delete your account we remove or anonymise your personal data, except what we must keep for legal or accounting reasons. Note that content already sent to a provider is subject to that provider’s own retention, and content you published publicly (for example a shared prompt) may persist where others saved it.

8. International transfers

Our providers operate in various countries, so your data may be processed outside where you live — including the United States. Where required, transfers rely on appropriate safeguards. [TODO: confirm transfer mechanisms (e.g. SCCs) with legal review.]

9. Children

IDALL is not for children. You must be at least [TODO: Minimum account age] to hold an account, and 18+ to enter challenges. We do not knowingly collect data from anyone under the minimum age; if we learn we have, we delete it.

10. Cookies

We use essential cookies for login and sessions. Any non-essential cookies (for example analytics) are covered — with a way to control them — in our Cookie Notice.

11. Contact and complaints

Questions or requests: our contact page. Data Protection Officer (if appointed): [TODO: Data Protection Officer (if required)]. If you are in the UK/EU you also have the right to complain to your local data-protection authority.

12. Changes to this policy

We will update this policy as IDALL grows — especially the provider list in §3. Material changes are notified, and older versions stay readable in the version history below.

Version history

  • v1· 22 July 2026 · current (draft)
  • This is the first version. Earlier versions will be listed here once the document is revised.
← Back to home