Privacy Policy

Last updated: May 1, 2026

Welcome to AIPhoto ("we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect information when you use our website and AI image generation services at aiphoto.io.

1. Information We Collect

1.1 Information You Provide

AIPhoto does not require account registration. However, if you voluntarily contact us by email or subscribe to our waitlist, we collect the email address you provide. We use this only to respond to your inquiry or to notify you about Pro plan availability.

1.2 Automatically Collected Information

When you use AIPhoto, we automatically collect limited technical information:

  • IP Address (hashed): We store a hashed (SHA-256) version of your IP address solely to enforce the daily rate limit of 5 free image generations. Raw IP addresses are not stored.
  • Usage Counts: We log the number of image generation requests per day, linked to the hashed IP. This data is automatically deleted after 7 days.
  • Server Access Logs: Standard web server logs (URL, timestamp, HTTP status code, user agent) are retained for up to 14 days for security and debugging purposes.

1.3 What We Do NOT Collect

  • We do not store your text prompts.
  • We do not store generated images on our servers.
  • We do not use cookies for advertising or tracking.
  • We do not collect names, addresses, payment information, or any personal identifiers.

2. How We Use Information

The limited information we collect is used exclusively for:

  • Enforcing the free daily generation limit (hashed IP + count).
  • Diagnosing technical issues (server logs).
  • Responding to direct support requests.
  • Notifying Pro waitlist subscribers when the plan launches.

3. Third-Party Services

AIPhoto uses third-party AI model APIs to generate images. When you submit a prompt, it is transmitted to these services:

  • OpenRouter (openrouter.ai): Our API gateway for routing requests to AI models. OpenRouter's Privacy Policy applies to data processed through their platform.
  • AI Model Providers: Depending on the model you select (Flux Pro, DALL·E 3, SDXL), your prompt may be processed by Black Forest Labs, OpenAI, or Stability AI. Each has their own privacy policies.

We do not share your data with advertisers, analytics services, or data brokers.

4. Cookies

AIPhoto uses only a single essential session cookie to maintain your browsing session. This cookie does not track your activity across sites and is deleted when you close your browser. We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.

5. Data Retention

  • Hashed IP rate-limit records: 7 days.
  • Server access logs: 14 days.
  • Waitlist email addresses: Until you unsubscribe or Pro plan launches, whichever comes first.

6. Your Rights

Depending on your location, you may have rights under applicable law, including GDPR (EU) or CCPA (California):

  • Access: You may request information about data we hold about you.
  • Deletion: You may request deletion of any data associated with you.
  • Opt-out: You may unsubscribe from our waitlist at any time by emailing us.

To exercise any of these rights, contact us at hello@aiphoto.io.

7. Children's Privacy

AIPhoto is not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it immediately.

8. Security

We implement reasonable technical and organizational measures to protect the limited data we collect, including HTTPS encryption, IP hashing before storage, and automatic data expiration.

9. Changes to This Policy

We may update this Privacy Policy periodically. The "Last updated" date at the top will reflect any changes. Continued use of AIPhoto after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this Privacy Policy? Contact us at: hello@aiphoto.io