LEGAL
Privacy Policy
This notice explains what personal data we process when you use the Service from any country, why we process it, who receives it, and the rights you can use.
Last updated 21 September 2026. Applies worldwide.
1. Who is responsible
The Operator of this Service (presented on the site as DesignStills.com) is the controller of personal data about your account. For product photos you upload that contain personal data about other people, you are typically the controller and we are the processor acting on your instructions to store and generate images.
Contact privacy and access requests from your account Settings or through the contact method published on this website. We do not currently appoint a statutory data-protection officer. If the law later requires an EU or UK representative, we will publish those details here.
2. Personal data we collect
We collect only what the product needs:
- Account data: email address, name, a password hash when you create a password (we do not store the raw password), and the Google or Microsoft account id when you sign in with those companies. Also credit balance, generation count, subscription status, and account created time.
- Studio content: product photos you upload, prompts or style choices, generated images, and file metadata needed to show and download them.
- Session data: an httpOnly login cookie named sid that keeps you signed in. If you ask to reset a password, we email a one-time link that expires after 30 minutes.
- Technical logs that the host may create when you call the API (for example IP address, user agent, time, and error codes). We use these to run and secure the Service, not to build advertising profiles.
We do not ask for government ID, payment-card numbers, precise GPS, or special-category data. Do not upload those on purpose. If you choose Google or Microsoft sign-in, we receive the email address and name that provider confirms, and nothing else from that account.
3. Why we use it and the legal basis
Where GDPR, UK GDPR or a similar law applies, we rely on these bases:
- Contract (Art. 6(1)(b)): creating your account, authenticating you, storing your products and generations, spending credits, and delivering downloads.
- Legitimate interests (Art. 6(1)(f)): keeping the Service secure, stopping abuse, debugging failed generations, and understanding whether the product is up. You can object. We do not use this basis to override a right that the law gives you.
- Legal obligation (Art. 6(1)(c)): keeping records we must keep, and answering a lawful request from an authority.
- Consent (Art. 6(1)(a)): only if we later add optional marketing email or non-essential cookies. We do not send marketing mail today.
If you do not provide an email and password, we cannot open an account. If you do not upload a product photo, we cannot generate a photograph.
4. How we share it
We do not sell personal data and we do not share it for cross-context advertising.
We use processors that handle data only to run the Service:
- Site host and serverless functions — currently Vercel — to serve the app and API.
- File storage — currently Vercel Blob in production, or local disk during development — for uploads and generated JPEGs.
- Database — currently Turso (libSQL) in production, or a local SQLite file in development — for accounts, credits, image records, and page counts if you accept analytics.
- Image-generation provider — currently Replicate, running Flux Kontext Pro — which receives the product image and prompt so it can return Output.
- Email delivery — currently Resend — which receives the address and reset link when you ask for a new password.
We may also disclose data if the law requires it, to defend a legal claim, or to a buyer if the Service is transferred, under the same protections.
5. International transfers
You can use the Service from anywhere. Our processors are often in the United States or the European Union. When we send personal data out of the EEA, the United Kingdom or Switzerland, we rely on an adequacy decision where one exists (including the EU–US Data Privacy Framework for certified US organisations) or on Standard Contractual Clauses plus the extra steps those clauses require. You can ask us for a summary of the safeguard we rely on for a named processor.
6. How long we keep it
- Account and credit records: for as long as the account is open, then deleted or anonymised within 90 days after closure, unless a longer legal hold applies.
- Uploads and generated images: while they remain in your library, then removed from active storage when you delete them or close the account. Backup copies may last a short extra period.
- Session cookie: up to 30 days, or until you log out.
- Security and server logs: typically 30 to 90 days.
7. Security
Passwords are stored as one-way hashes. The session token lives in an httpOnly cookie, not in local JavaScript storage. Product files are served only to the signed-in owner. Generation credits are reserved and confirmed on the server. No security measure is perfect. If we become aware of a breach that the law says we must report, we will notify you and the authority within the required time.
8. Your rights
You can use the rights that apply in your country. We will honour a valid request even if we must map it onto the closest local rule. You can usually:
- access the personal data we hold about you and get a copy;
- correct inaccurate account data (name can be edited in Settings; email is the login key);
- delete your account, uploads and generations;
- restrict or object to processing that is not required for the contract;
- take your account data in a common machine-readable form (portability);
- withdraw consent later if we ever ask for it — that does not undo processing already done;
- complain to a supervisory authority. In the EEA you can contact your local authority; in the UK the ICO; in Switzerland the FDPIC.
California residents also have the right to know, delete, correct, and to not be discriminated against for using a privacy right. We do not sell or share personal information as those words are used in the CCPA / CPRA. If we ever do, we will add a “Do not sell or share” control. You may use an authorised agent. We will need to verify the request belongs to you.
Brazil (LGPD), Canada (PIPEDA and provincial laws), Australia (Privacy Act), Japan (APPI), South Korea (PIPA), South Africa (POPIA) and similar laws give comparable access, correction and deletion rights. Send the request from the email on the account. We may ask for information that proves it is you. We respond within the time the applicable law sets — often 30 days, sometimes 45 in California.
9. Cookies
The Service sets one first-party cookie: sid. It is a strictly necessary authentication cookie. It stores a signed session token, is httpOnly, and uses Secure and SameSite when the site is served over HTTPS. It is not an advertising cookie. A small bar at the bottom of the screen lets you Accept or Deny optional cookies.
The full list, durations and how to change your choice are in the Cookies Policy. Optional analytics is first-party: after Accept, a random visitor id and the page path are stored so we can count visits. Deny leaves that off. We do not set marketing cookies.
10. Children
The Service is for adults. We do not knowingly collect personal data from anyone under 18, or under 13 in the United States. If you believe a child created an account, contact us and we will delete it.
11. Automated decisions
Image generation is automated. It does not make a legal or similarly significant decision about you (for example credit, hiring or benefits). Credit reservation is an automated check that you have a credit left before a job starts. A person can review an account if you write to us about a blocked generation or a closed account.
12. Changes
We will post updates on this page with a new date. If we start collecting a new category of data, add a processor that changes the risk, or use data for a new purpose, we will update this notice before that change applies, and we will ask for a new consent where the law requires one.
13. Contact
Use Settings on a signed-in account, or the contact method published on this website. For the contract that governs use of the generator, see the Terms of Service.
Also read our Terms of Service, Privacy Policy and Cookies Policy.