Back to home

Privacy Policy

How Imagine2 handles account data, prompts, private image assets, billing records, and service telemetry.

Last updated: 2026-08-08

Scope

This Privacy Policy explains how Imagine2 collects, uses, shares, retains, and protects personal data when you use our website, Studio, image APIs, billing, and support. Imagine2 is independent and is not affiliated with or endorsed by xAI.

Data we collect

  • Account data: name, email address, profile image, Google account identifier, session records, locale, and account creation time.
  • Creative data: prompts, generation settings, model identifier, reference images, generated outputs, asset metadata, task status, save state, and deletion time.
  • Billing data: Stripe customer and transaction identifiers, product purchased, amount, currency, subscription state, credits granted, and payment event records. Imagine2 does not store full card numbers.
  • Technical data: IP address, browser and device details, request timestamps, error logs, rate-limit events, security signals, and analytics events when analytics is enabled.
  • Support data: messages, attachments, and the information you choose to provide when requesting help.

How we use data

We use data to authenticate users; generate, edit, store, display, and delete images; calculate and refund credits; process payments; prevent fraud and abuse; enforce limits; provide support; debug failures; maintain availability; comply with law; and improve the product. We do not sell personal information.

Service providers

We disclose only data reasonably needed for a provider's role. Google supports authentication. xAI processes prompts, generation settings, and reference image data needed to produce outputs. Cloudflare may provide Workers, D1, R2, networking, security, and logs. Stripe processes payment and subscription data. Configured analytics or support services may receive technical and interaction data.

Provider processing is governed by each provider's terms and privacy practices. Avoid uploading highly sensitive personal data. Do not upload a person's image unless you have a lawful basis and any required consent.

Retention and deletion

Unsaved input and output assets normally expire after 24 hours. Saving a task extends associated output retention to 30 days. Deleting a task requests immediate object deletion. Task, credit, payment, security, audit, and deletion records may be retained longer where reasonably necessary for accounting, abuse prevention, dispute handling, legal compliance, or system integrity. Provider-side transient copies and backups follow provider and operational retention schedules.

Security

We use encrypted transport, private object storage, ownership checks, access controls, encrypted admin secrets when configured, and rate limits. No system is completely secure. You are responsible for securing your Google account and devices.

Your choices and rights

Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection. You may delete individual tasks in History and may request account deletion through support. We may verify identity before completing a request and may retain records where law or legitimate security needs require it.

International processing, children, and changes

Providers may process data in countries other than yours. Imagine2 is not directed to children under 13, and users must meet the minimum digital-consent age in their jurisdiction. We may update this Policy; the date above identifies the current version.

Contact

Privacy requests may be submitted through the support contact available in your account. Include the email associated with your Google sign-in and do not send sensitive reference images by email unless requested through a secure channel.