Privacy Policy
This policy explains what information PhotoQuill collects, how we use it to operate the service, and what choices you have if you want to access, correct, export, or delete your data.
Last updated:
1. Who We Are
This Privacy Policy explains how PhotoQuill ("we", "us") collects, uses and shares personal data when you use photoquill.com (the "Service"), and the choices you have. PhotoQuill is responsible (the "controller") for this data. Please read it together with our Terms of Service.
Contact for anything in this policy: support@photoquill.com.
2. Information We Collect
- Account data — your email address and sign-in records. If you sign in with Google, we receive your name, email address and profile picture from Google.
- Prompts — the text you submit, including negative prompts and editing instructions.
- Uploaded photos — photos you open or upload when you use an AI feature (for AI editing, object removal or background removal).
- Generation records — for each request: the prompt, the model and settings, the status, the credits used and a link to the result.
- Billing data — your plan, subscription status, credit balance and credit history, and the customer and order IDs from our payment partner. Your card details are collected by the payment partner, not by us.
- Moderation records — the results of the safety checks run on your prompts and outputs (see Section 4).
- Support and feedback — emails you send us, and feedback or error reports you submit through the site together with technical details such as browser, page and IP address.
- Technical data — IP address, browser and device information and pages visited, collected by our hosting provider and by Google Analytics.
- What we don't collect — PhotoQuill's standard (non-AI) editing tools run locally in your browser. A photo is sent to our servers only when you use an AI feature on it.
3. How We Use Your Information
- To provide the Service — your account, generations, credits and history (legal basis: performance of our contract with you).
- To keep the Service safe — screening prompts and outputs, investigating reports, enforcing our Acceptable Use Policy and meeting legal duties such as reporting child sexual abuse material (legitimate interests; legal obligation).
- To handle payments — plans, renewals, credits and refunds (contract; legal obligation for tax records).
- To support you — answering your emails and requests (contract; legitimate interests).
- To protect the Service — rate limits, fraud and abuse prevention and security (legitimate interests).
- To understand and improve the Service — aggregate website analytics (legitimate interests, or your consent where the law requires it).
We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not use your prompts, uploads or outputs to train AI models.
4. Content Moderation and Safety Processing
To enforce our Acceptable Use Policy, the text of every prompt is sent to the Creem Moderation API and Waffo Prompt Sift before generation. Images from models served by Runware are checked by Runware's content-safety classifier before we show them to you. Google's models apply Google's built-in safety filters. fal.ai editing models run with the provider's safety checker.
We record the result of these checks in a moderation log: the date, your account ID, the service that ran the check, its verdict and categories, and — only when a prompt was blocked or flagged — the prompt text. We use these records to review flagged content, handle reports and appeals, audit our filters and meet legal obligations. Moderation records are kept for 180 days and then deleted automatically, including when you delete your account earlier.
5. AI Processing
To fulfil a request, we send your prompt and settings — and the photo you submitted, if any — to the provider that runs the model you chose (Runware, Kie.ai, fal.ai; the models are listed in Section 6 of our Terms of Service). The provider processes it to generate the output and returns the result to us. Providers may keep inputs and outputs for a limited time under their own policies, for example to deliver the file or to prevent abuse.
Uploaded photos are used only to fulfil your request. We do not keep the photo itself in our database.
6. Who We Share Data With
We share personal data only with the service providers that help us run the Service, and only as far as they need it:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, sign-in and server functions (hosted in the United States) | Account data, generation and billing records, moderation records |
| Cloudflare | Website hosting, content delivery, security and email routing for our support address; storage of your generated files (Cloudflare R2) | Technical data such as IP address and browser; your generated files; support emails |
| Runware | Runs the AI models that generate your images (FLUX.2 [klein], FLUX.2 [dev], FLUX.2 [max], Z-Image Turbo, Seedream 4.5, Nano Banana 2 (fast), Nano Banana Pro (fast)) and checks their output for unsafe content | Your prompts, the photos you submit and the generated output |
| Kie.ai | Runs the AI models that generate your images (Nano Banana 2, Nano Banana Pro) | Your prompts, the photos you submit and the generated output |
| fal.ai | Runs the AI models that generate your images (Nano Banana 2 Edit, FLUX.2 [pro] Edit, Seedream 4.5 Edit, Finegrain Eraser, Bria RMBG background removal, BiRefNet background removal) | Your prompts, the photos you submit and the generated output |
| Creem and Waffo | Payment processing as Merchant of Record, subscription management; content moderation of prompts (Creem Moderation API, Waffo Prompt Sift) | Email, plan and order details (they collect your payment details directly); the text of your prompts for moderation |
| Sign-in with Google, if you choose it; website analytics (Google Analytics 4) | Your Google name, email and profile picture; usage data and analytics cookies |
Each provider handles data under its own privacy policy and security commitments. We may also disclose data where required by law, to protect the rights and safety of people or of the Service, to report child sexual abuse material, or as part of a sale or reorganisation of the Service (in which case this policy continues to apply).
7. Cookies, Local Storage and Analytics
- Essential — cookies and browser storage that keep you signed in and remember your preferences. The Service does not work without them.
- Analytics — we use Google Analytics 4 to measure visits and usage in aggregate. It sets cookies such as
_ga. You can block these cookies in your browser settings or install Google's opt-out add-on (tools.google.com/dlpage/gaoptout) without affecting the Service. - No advertising — we do not use advertising or cross-site tracking cookies.
8. How Long We Keep Data
| Data | How long |
|---|---|
| Account, profile and billing records, generation records, prompts | While your account is open; deleted when you delete your account |
| Generated files | We keep your 5 most recent outputs in Cloudflare R2; older files are deleted automatically, and the rest when you delete your account |
| Uploaded photos | Not stored in our database; used only to process your request |
| Moderation records | 180 days, then deleted automatically |
| Payment and tax records | Kept by our payment partner as required by law |
| Support emails and reports | As long as needed to handle them and for our records |
Deleted data may remain in backups for a limited time before they are overwritten.
9. Your Rights
Depending on where you live (for example under the GDPR in the EU/EEA, the UK GDPR, or the CCPA/CPRA in California), you have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent at any time, and to complain to your data protection authority. California residents also have the right to know what we collect and to not be discriminated against for exercising their rights; we do not sell or share personal data as those laws define it.
You can delete your account and its data at any time from your dashboard. For any other request, email support@photoquill.com from the address linked to your account with the subject "Privacy Request". We respond within 30 days and may need to verify your identity first.
10. International Data Transfers
We and our providers process data in the United States and other countries; our main database is hosted in the United States. Where data protection law requires it, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses offered by our providers.
11. Security
We protect data with encrypted connections (HTTPS/TLS), access controls that limit each account to its own data, and restricted server-side credentials. No system is completely secure, so please keep your login details safe and tell us at once if you suspect misuse of your account.
12. Children
The Service is not directed to children under 13 (16 in the EEA and the UK), and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. Material changes are announced at least 15 days in advance by email or on the website. The date at the top shows when it was last updated.
14. Contact
Privacy questions and requests: support@photoquill.com. To report content that breaks our rules, see Section 7.8 of our Terms of Service.