Privacy
Private media, short retention, durable deletion.
Uploads and generated results are private application data. They are not a public gallery and are served only after the anonymous browser session is re-checked.
Retention
Accepted uploads and their derived jobs use a fixed retention deadline of no more than 24 hours. Creating another variant does not extend the source deadline.
Delete now
Delete-now first commits a database tombstone that revokes reads immediately. Physical object cleanup continues durably and a deletion is not reported complete until the cleanup pass succeeds.
Processing
Enabled modes can use server-side processing infrastructure operated by this service and external processing infrastructure where required. Processing credentials and object-storage credentials stay server-side and are never sent to browser JavaScript.
Training and logs
The service owner does not use customer uploads to train its own model. Application logs should contain opaque identifiers and safe error classes rather than image bytes, original filenames or credentials.
Launch disclosure
Hosting, subprocessors and support disclosures are reviewed before searchable production launch and updated here when the production configuration changes.