⚠ Draft — pending legal review
This is an honest working draft written for product development, not by a lawyer. It is not yet in effect and must be reviewed and approved by a qualified lawyer before it binds anyone. Nothing here is legal advice.
To be decided by Darren / a lawyer
- Data controller legal entity and, if required, a Data Protection Officer.
- Legal bases for processing and international-transfer mechanisms (GDPR/UK GDPR/CCPA).
- Exact data-retention periods.
- Confirm the live AI-provider list and data-processing agreements before launch, and keep §3 current.
Privacy Policy
What we collect, exactly which providers your prompts and uploads are sent to, how long we keep it, and how to get it deleted.
v1 · Draft 22 July 2026 · not yet in effect
1. The short version
This policy explains what we collect, where it goes, how long we keep it, and how to get it deleted. The data controller is [TODO: Legal entity name]; contact details are on our Contact page.
2. What we collect
You give us
- Account details — name, email, and anything you add to your profile (avatar, bio, username).
- Your prompts and the reference images or files you upload.
- The content you generate, and anything you publish, save to boards, or submit to a challenge.
- Messages you send — to Koko, in community and challenge chat, and to support.
We generate as you use IDALL
- Credit balances and a transaction history of what each generation cost.
- Generation history — which model you used, settings, and the result.
- Membership and payment status (but not your card — see §4).
- Basic technical logs — IP address, device/browser, and timestamps — used for security, abuse prevention, and to keep the service working. Challenge terms acceptance is logged with version, time, and IP because the rules require it.
3. Where your data goes — our providers
We use a small set of trusted companies (“processors” or “sub-processors”) to run IDALL. Each receives only what it needs for its job.
Infrastructure
- Supabase — our database, login/authentication, and file storage. Holds your account, content, and credit records.
- Vercel — hosting and content delivery — the servers that run the site and app.
- Bunny (Bunny Stream) — video hosting and CDN — generated videos are re-hosted here so they stream reliably.
- Resend — transactional email (login links, receipts, notifications).
Payments
- Stripe — processes payments. Your card is entered on Stripe and never reaches us (see §4).
AI model providers — who your prompts and uploads are sent to
When you generate, your prompt and any reference files are sent to the provider running the model you chose. These providers process your content under their own terms and privacy policies:
- PiAPI — our main generation gateway. It routes your request to the underlying image/video model — which currently includes models such as Seedance, Kling, Hailuo/MiniMax, Luma, and Midjourney.
- fal.ai — image generation and upscaling.
- OpenAI — powers Koko (your AI mentor) and some text and image features.
- Anthropic (Claude) — powers some AI assistance and skills features.
- ElevenLabs — audio and voice generation, where you use it.
- Stability AI — image generation, where used.
We do not sell your personal data, and we do not share it for third-party advertising.
4. Payments — we never see your card
Payments run through Stripe’s hosted checkout. Your card details are entered on Stripe and never touch our servers or database. We store only a Stripe customer reference and your payment/subscription status, so we can grant credits and manage your membership. See the Refund & Billing terms.
5. How we use your data
- To run generations and keep your credit balance and history accurate.
- To provide your account, Koko, community, and challenges.
- To prevent abuse and enforce our Acceptable Use Policy — including automated safety filtering of prompts and outputs.
- To communicate with you about your account, and (only if you opt in where required) about products and updates.
- To meet legal, tax, and accounting obligations.
[TODO: confirm the legal bases for processing — e.g. contract, legitimate interests, consent — with a lawyer for your target markets (GDPR/UK GDPR/CCPA).]
6. How long we keep it
- Account and generated content: while your account is active.
- Credit and payment records: kept as long as needed for accounting, tax, and legal reasons after that.
- Prompts/uploads sent to providers: retained by each provider under its own schedule, which we do not control.
- Security logs: kept for a limited period for abuse prevention.
[TODO: set exact retention periods with legal review.]
7. Your rights and deletion
Depending on where you live, you can ask us to access, correct, export, or delete your personal data, and to object to or restrict certain uses. To do any of these, email us from your account address at our contact page.
When you delete your account we remove or anonymise your personal data, except what we must keep for legal or accounting reasons. Note that content already sent to a provider is subject to that provider’s own retention, and content you published publicly (for example a shared prompt) may persist where others saved it.
8. International transfers
Our providers operate in various countries, so your data may be processed outside where you live — including the United States. Where required, transfers rely on appropriate safeguards. [TODO: confirm transfer mechanisms (e.g. SCCs) with legal review.]
9. Children
IDALL is not for children. You must be at least [TODO: Minimum account age] to hold an account, and 18+ to enter challenges. We do not knowingly collect data from anyone under the minimum age; if we learn we have, we delete it.
11. Contact and complaints
Questions or requests: our contact page. Data Protection Officer (if appointed): [TODO: Data Protection Officer (if required)]. If you are in the UK/EU you also have the right to complain to your local data-protection authority.
12. Changes to this policy
We will update this policy as IDALL grows — especially the provider list in §3. Material changes are notified, and older versions stay readable in the version history below.
Version history
- v1· 22 July 2026 · current (draft)
- This is the first version. Earlier versions will be listed here once the document is revised.