Privacy Policy
What we collect, why we collect it, and who else sees it.
Last updated 22 August 2026
This policy covers OppressedAI at oppressedai.com. It describes what the service actually stores, rather than every category we might conceivably collect.
What we collect
- Account details — your email address, an optional display name, and a password stored only as a scrypt hash. We never store your password itself.
- What you create — your prompts, uploaded media, generated results, the model used, and the credits each generation cost.
- Billing records — which credit packs you have bought, when, and an identifier from our payment processor. Card details never reach our servers.
- Technical data — your IP address, used to rate-limit sign-in attempts, uploads and password resets, and server logs for diagnosing faults.
- Connected applications — which agents you have authorised, and when each was last used.
We do not run third-party advertising or analytics trackers, and we do not sell personal data.
Why we can use it
- To provide the service you asked for, which is the performance of our contract.
- To keep the service secure and prevent abuse — rate limiting, fraud prevention and enforcing our Acceptable Use Policy — which is our legitimate interest.
- To meet legal obligations such as tax records.
Who else processes it
We use these providers to run the service. Each acts on our instructions, and your prompts and uploaded media are sent to the model provider in order to fulfil a generation.
| Provider | What they do |
|---|---|
| Vercel | Application hosting and delivery |
| Supabase | Database (accounts, generation records, credit ledger) |
| Cloudflare R2 | Storage and delivery of generated media and uploads |
| fal.ai | Runs the AI models; receives prompts and any uploaded media |
| Resend | Transactional email, such as password resets |
Our payment processor handles card data directly and is the controller of that data. These providers operate internationally, so your data may be processed outside your country under the safeguards those providers maintain.
Publishing
Generations are private by default. If you publish one to the Community gallery it becomes publicly visible along with its prompt and the first part of your email address as a handle. You can unpublish at any time, though anything already downloaded by others cannot be recalled.
How long we keep it
- Account details and generations: until you delete them or close your account.
- Password reset links: one hour, and they are deleted once used.
- Credit ledger and billing records: retained after account closure where tax law requires it.
- Server logs: retained by our hosting provider on a short rolling window.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to processing, or to complain to your data protection authority. Email legal@oppressedai.com and we will respond within one month.
You can already do several of these yourself: change your password, sign out every device, revoke connected applications, unpublish generations, and delete characters and storyboards.
Security
Passwords are hashed with scrypt. Sessions are signed, expiring cookies that can be revoked everywhere at once. Access tokens for connected applications are stored server-side and take effect immediately when revoked. Password reset links are stored only as hashes, are single-use, and expire in an hour.
Children
The service is not intended for children. Do not use it if you are under the age at which you can form a binding contract where you live.
Changes
We will announce material changes to this policy before they take effect. The date at the top shows when it was last revised.
Contact
Questions about this document? Email legal@oppressedai.com.