← Back to PetIntoArt

Privacy Policy

Operator and version

PetIntoArt is an independent software project operated by an individual developer.

Last updated: September 23, 2026

Account and authentication data

We process your email address, Supabase user ID, and authentication and session information to sign you in and associate credits and portraits with your account. Login uses email one-time codes (OTP) or Google OAuth.

Brevo delivers transactional authentication emails, including one-time sign-in codes, and receives the email delivery data needed for that purpose.

When you choose Google Sign-In, Google authenticates your identity and Supabase receives the basic identity information Google supplies for sign-in, such as your Google account identifier, email and verification status, and profile information such as a name or avatar when supplied. This may remain in authentication metadata; PetIntoArt uses your account ID and email for its workspace. We do not request Google Drive or contacts access.

PetIntoArt does not send pet photos or generated portraits to Brevo or Google through these authentication and email-delivery flows.

Original pet photos — up to 30 days

Original uploaded pet photos are stored in private storage and processed to create your requested portrait. Our original photo retention period is up to 30 days from the original upload time, for guests and account holders.

An automatic scheduled cleanup job removes expired original files. Account deletion also queues uploaded photos for removal. Removal is a background process with retries, not immediate deletion on upload or on a button click. Operational outages can delay cleanup; the retention period is not restarted by generating another portrait or claiming a guest portrait.

A photo may be used for more than one generation. Deleting one portrait does not remove its shared original; the original remains subject to its own retention period. Removing an original does not remove portraits already generated from it.

Saved Pets — optional private photos

When you choose Save this pet for next time, we keep a separate private copy in your account until you remove the saved pet or delete your account. Saving is optional. Ordinary uploaded originals continue to follow the 30-day retention period above.

Removing a saved pet disables future reuse and queues its private file for background deletion with retries. It does not delete portraits already created. Account deletion includes saved photos and Saved Pets records.

Generated portraits and guest images

Account portraits are private and remain in account history until you delete the portrait or account. We do not promise indefinite file availability. Download copies you want to keep.

Unclaimed guest input and output images are retained for up to 30 days from their respective upload or creation time. If you register and claim your guest history during the claim window, the generated output becomes an account asset. Its original input still follows the 30-day period measured from the original upload.

Deleting a portrait hides it from history and prevents new download links. The private output is removed by background cleanup. Previously issued time-limited links may continue working until they expire or the underlying file is removed.

AI processing through Replicate

PetIntoArt uses Replicate to run Black Forest Labs FLUX.1 Kontext [pro] image generation. Your pet photo and the generation request are sent to Replicate as needed to provide the portrait. Black Forest Labs applies input and output safety moderation. When generation succeeds, PetIntoArt downloads the output and stores its own private copy.

Replicate currently documents default deletion of API prediction inputs, outputs, files and logs after approximately one hour. This describes its API prediction-data policy, not every internal record. Replicate may separately retain information for security, legal obligations or backups under its policies. We do not control all of its internal logs or legal duties. PetIntoArt copies follow the retention periods described above.

Pre-generation content safety

PetIntoArt sends the complete server-generated text instruction used for a portrait to Waffo for pre-generation safety classification. This text-screening request does not send the pet image bytes. Only an allow result proceeds to generation; other results fail closed.

We retain only minimal moderation metadata, such as the stage, result, reason category, provider request identifier, style identifier, a SHA-256 hash of the instruction, and provider-safety settings. The moderation audit does not store the raw final instruction, pet photo, generated portrait, signed URL, email address, raw IP address, cookie, secret, or raw provider response.

Ordinary moderation metadata is retained for no more than 30 days. A minimum necessary record may be held longer while an abuse report, security incident, intellectual-property complaint, legal dispute, or legal obligation remains unresolved.

Website hosting

Vercel hosts the website and runs server-side requests. It processes request and technical connection data needed to deliver and secure the service, including IP addresses and operational logs. Provider processing and retention are subject to its applicable terms and privacy policies.

Support email routing

Cloudflare Email Routing receives messages sent to support@petintoart.com and forwards them to an operator-controlled private mailbox. Cloudflare processes the sender, recipient, message content, attachments, and delivery metadata as needed to route and secure those messages.

Do not email passwords, one-time codes, full payment-card numbers, or illegal material. Support messages may be retained as needed to answer the request, investigate safety or legal reports, resolve disputes, protect the service, and meet applicable obligations.

Supabase infrastructure

Supabase provides authentication, our database and private image storage, and processes the corresponding account, session, image and transaction records as our infrastructure service provider. Its data-processing terms describe its processor/service-provider role for customer data. Its own service administration and usage-data processing may have separate purposes under its policies.

Payments through Waffo Pancake

PetIntoArt uses Waffo Pancake as Merchant of Record for paid credits. We provide transaction-related information such as your account identifier, email and selected purchase, and receive order and refund references and statuses to manage credits.

Waffo acts as an independent controller for payment, billing, tax, fraud, compliance, refund, chargeback and Merchant-of-Record transaction data under its applicable obligations. Card details are entered in its payment flow; PetIntoArt does not store full card numbers. Waffo’s own privacy policy governs its processing and retention. Deleting a PetIntoArt account does not delete records Waffo must retain.

Guest trial protection and anti-abuse data

We use an essential guest session cookie and request/rate-limit information to enforce free-trial limits and protect the service. The guest cookie lasts up to 30 days; the server stores a hash of its random identity, trial usage and any account claim.

For short-term network abuse checks, the server derives a keyed hash from the network address. Raw IP addresses are not stored as long-term product identifiers in our trial database. Rate-limit records expire after their minute or 24-hour windows and are removed during rate checks and scheduled cleanup. These identifiers are pseudonymous, not a promise of anonymity. Infrastructure and provider access logs may have separate retention.

Cookies and browser storage

Necessary cookies and browser storage support authentication, guest identity, security, temporary portrait selections, and short-lived workspace recovery state. A pet photo selected in the current creator remains local to that page until you start generation; PetIntoArt does not currently place the selected pet-photo file into browser session storage for a cross-page handoff. When generation starts, the photo enters the private upload flow described above.

PetIntoArt currently has no advertising cookies, marketing tracking pixels or newsletter tracking integration. External login and payment services have their own cookie policies. Disabling necessary storage may prevent login or the guest trial from working.

Deleting portraits or your account

Use Delete portrait in Create → Recent Portraits, or Delete account in Account → account controls. A confirmed account deletion closes further product use, then removes photos, portraits and application account data through a retryable workflow. The authentication user is deleted last, after storage and application cleanup.

Remaining credits become unusable. Account deletion does not automatically request or issue a cash refund. Request any eligible unused-pack refund before deletion. A refund still being processed blocks deletion until resolved; an unresolved incoming purchase must also finish processing first.

Financial records and other retention limits

After account deletion, we retain minimal transaction and accounting records needed for payment reconciliation, tax, legal claims or disputes. These can include internal identifiers, credit entries, amounts and terminal payment/refund references; they cannot be used as a product account and do not include pet photos or portraits.

The financial audit currently has no automatic deletion deadline. Applicable retention requirements and disputes determine how long records need to be kept. Account deletion does not promise instantaneous physical erasure of provider copies or backups.

Purposes, sharing and privacy requests

We use this information to provide the requested service, secure accounts, prevent abuse, manage purchases and address support or legal obligations. Where applicable, processing relies on providing the service you request, legitimate security and operational interests, legal obligations, or consent where required.

Our infrastructure and processing providers receive data needed for these purposes. Processing may take place outside your country and is subject to provider terms and applicable safeguards. We do not guarantee absolute security.

Depending on applicable law, you may request access, correction, deletion or a copy of your personal data, object to or restrict certain processing, withdraw consent where relied upon, or complain to a competent privacy authority. Contact support to make a request; we may need proportionate identity verification. Mandatory rights are not limited by the self-service controls.

Policy updates

We may update this policy to reflect changes in the service or applicable requirements. The date above identifies this version. Material changes will be communicated as required by applicable law.

Contact

For policy questions, support or requests, email support@petintoart.com.