Privacy policy

Last updated: 2026-07-14.

What we collect

When you sign in we receive your email address and display name from our identity provider (signin.ounie.com). When you generate a shot we store the shot record you create — the reference photo, the scene and quality tier you chose, any custom direction you added, the credit reservation and settlement, and the finished output.

What we don't collect

We don't track you across the web. There are no third-party analytics scripts, no advertising pixels, no session replay. We don't sell, share, or resell anything you upload or generate, and neither your product photos nor your outputs are used to train any model.

Your product photos

Reference photos you upload are stored privately and used only to composite the shots you request — they are never shown to other accounts and never appear in the scene catalog. Uploading is free; only the composited shot bills credits.

Generated media

Finished shots are stored in the shared Ounie S3 bucket on a permanent public-read URL — that's what makes downloads, embeds, and agent workflows work; anyone with the exact link can view the file. Share pages (/g/…) are separate and private by default: a shot gets a public share page only when you explicitly turn one on. Deleting a shot deletes its stored output and, once no longer needed, its reference photo.

Photos sent to model providers

To render a shot, your reference photo and the composed scene prompt are sent to the frontier model provider behind our studio engine. They receive the image and prompt content only — never your name, email, or Ounie identity.

Where data lives

Application data (shot records, credit ledger entries) is stored in a Neon Postgres database hosted in the US. Output files and reference photos live in the Ounie S3 bucket, also in the US.

Payments

Credit purchases happen on ounie.com, where Stripe processes payment. This product never sees your card number; it only reads and debits your Ounie credit wallet. x402 calls are settled in USDC on-chain and are pseudonymous — we record the paying wallet address and transaction hash, nothing more. Stripe's privacy policy lives at stripe.com/privacy.

Content screening

Prompts are screened against our content standards before generation. Blocked prompts are refused without charge; we may retain minimal records of refusals to enforce our terms.

Deletion

Deleting a shot removes its record and stored output. To delete your account or download your data, open a privacy ticket. We respond within 7 days and complete the deletion within 30.

Contact

/contact · routed to ounie@ounie.com