Privacy Policy
Last updated August 25, 2026
Short version: we collect the minimum needed to run your account, we never sell data, and you can ask for deletion anytime at [email protected].
What we collect
- Your email address and provider account ID, from Google or Discord when you log in
- Account settings: plan, quota counters, beta status, referral code
- The prompts you submit and the code the engine generates (your project history)
- Usage events (timestamps of builds) used for quotas and aggregate statistics
Cookies
Two cookies, both strictly necessary, so no consent banner blocks your screen: a signed session cookie that keeps you logged in, and a 30-day referral cookie if you arrived through an affiliate link. No analytics, advertising, or tracking cookies exist today.
Who processes your data
- Google / Discord: identity providers for login
- Stripe: payments (card data never touches our servers)
- Vercel: hosting and infrastructure
- Our AI inference provider: prompt text is sent to generate code
Children's privacy
The service is not directed at children under 13 and accounts under 13 are prohibited (COPPA). Users aged 13 to 17 should have a parent or guardian review this policy with them. Parents of anyone under 13 who somehow created an account can email us for immediate deletion.
Your rights
Wherever you live (GDPR, UK GDPR, CCPA/CPRA and similar), you can request a copy of your data, correct it, delete your account and its data, or object to processing. Email [email protected] and we respond within 30 days. We do not sell personal information, ever.
Retention and transfers
Project data persists until you delete it or close your account. Deleted accounts are anonymized within 30 days, except records we must keep for tax or fraud law. Data is hosted in the United States; by using the site you understand it moves there, and where required we rely on standard contractual clauses for transfers out of the EEA/UK.
Security
OAuth-only login (we store no passwords), encrypted transport everywhere, signed session cookies, hashed API keys, rate limiting, and least-privilege access on our side. Details in the public SECURITY overview available on request.
Changes
Material changes are announced on the site 14 days before taking effect.
Questions about this document? Email [email protected].