— Legal
Privacy Policy.
This policy explains what data StudioPic collects when you use our service, how we use it, who we share it with, and the choices you have. Questions? Email hello@studiopic.co.
What we collect
- Account info: your email address (used for sign-in via magic link).
- Photos you upload: the selfies, garment images, and scene references you provide as inputs to generate output photos.
- Generated outputs: photos produced by our AI pipeline based on your inputs.
- Usage data: generation count, timestamps, error logs, IP address (hashed daily for rate-limit purposes).
- Payment info: handled entirely by Dodo Payments (our merchant of record). We never see or store your card details.
How we use it
- To generate the photos you ask for.
- To send you sign-in links and important account notices.
- To enforce daily limits and prevent abuse (rate limiting, bot defense).
- To process subscription payments and send receipts.
- To improve the product (anonymized, aggregated metrics only).
Who we share it with
StudioPic uses third-party processors to operate. Each receives only what they need to do their job:
- OpenAI— your input images are sent to OpenAI to run the image generation model. OpenAI's policy applies to that processing.
- Cloudflare R2 — stores your input and output images.
- Supabase — stores account, session, and job metadata (in Postgres).
- Resend — sends magic-link sign-in emails to your inbox.
- Dodo Payments — handles subscription billing, taxes, and currency conversion. Their privacy policy applies to payment data.
- Cloudflare Turnstile — verifies that requests come from real humans, not bots.
- Upstash Redis — stores rate-limit counters (hashed user/IP IDs only).
- Vercel — hosts and serves the StudioPic web application.
We do not sell your personal data to anyone. We do not share your photos with anyone other than the processors listed above.
How long we keep it
- Free tier output photos: retained for 7 days, then deleted automatically.
- Pro tier output photos: retained as long as your subscription is active, plus 30 days after cancellation.
- Input images (selfies, garments): deleted after the generation completes. We never train on your photos.
- Account data: retained while your account is open. Deleted within 30 days of account deletion.
Cookies
StudioPic uses a single session cookie (set by NextAuth) to keep you signed in. Cloudflare Turnstile may set a temporary cookie during bot-check verification. We do not use marketing or tracking cookies.
Your rights
- Access: request a copy of the data we hold about you.
- Deletion: request that we delete your account and associated data.
- Correction: ask us to fix inaccurate information.
- Portability: receive a copy of your data in a machine-readable format.
Email hello@studiopic.co for any of the above. We respond within 30 days.
Children
StudioPic is for users 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has used the service, contact us and we will remove their data.
Changes
We may update this policy. When we do, we'll change the “last updated” date at the top and, for material changes, notify users via email.
Contact
Questions about this policy or a request about your data? hello@studiopic.co.