assets.baby

Last updated 1 September 2026

Privacy

What we hold about you, who else sees it, and how to get rid of it. Written to be read, not to be survived.

Not ready to publish — 4 details missing

Fill these in src/lib/legal.ts, then have a lawyer in your jurisdiction read both documents before you take money. This block disappears on its own once nothing says TODO.

  • legalNameregistered legal or trading name
  • countrycountry of establishment
  • jurisdictiongoverning law and courts
  • contactEmailsupport@your-domain

01Who we are

assets.baby is operated by TODO — registered legal or trading name, established in TODO — country of establishment. For anything in this document, write to TODO — support@your-domain.

02What we keep

WhatWhyHow long
Your email addressIt is your account. Sign-in is a link sent to it, so there is no password to storeUntil you delete your account
Projects, game descriptions and promptsThey are the input the service works fromUntil you delete the project or the account
Generated images and screensThey are what you paid forUntil you delete the project or the account
Credit historySo both of us can see what was bought and what it was spent onUntil you delete your account
IP address and browser user-agent, at the moment you buy credits, start a generation, approve a screen or download a packTo answer payment disputes and support claims. Nothing else is logged — not page views, not general browsing12 months, then deleted automatically
A Stripe customer referenceSo the billing portal can show you your own invoices and nobody else'sUntil you delete your account

We do not store a password, because there is none — signing in sends a one-time link to your email. We run no advertising and no cross-site tracking. The only cookie we set is the one that keeps you signed in.

We do measure page views, using Vercel Analytics. It is cookieless: it sets nothing on your device and builds no profile of you. It records which page was viewed, where you arrived from, and a coarse country, browser and device type — and it identifies a visit with a value derived from your request that is rotated daily, so the same person cannot be followed from one day to the next, let alone across other sites. We use it to see which pages people read, nothing more.

03Who else sees it

Running this service means sending parts of your data to other companies. These are all of them:

  • Supabase (self-hosted)

    Database, file storage, authentication and background jobs

    Receives: Your email address, projects, prompts and every generated image

  • OpenAI

    Image generation

    Receives: The text prompts built from your game description, and your approved screen when it is used as a style reference

  • Google (Gemini)

    Text and vision models — game design, asset planning, reading your approved screen

    Receives: Your game description and the screens you approve or upload

  • Alibaba Cloud (DashScope / Qwen)

    Image generation, when selected as the image provider

    Receives: The same prompts and reference screens as the other image providers

  • Vercel

    Hosting and cookieless page-view analytics

    Receives: Which pages are viewed, the referring site, and a coarse country, browser and device type. No cookie, and the visit identifier is rotated daily

  • Stripe

    Payments

    Receives: Your email address and purchase amounts. Card details go to Stripe directly and never reach our servers

Some of these process data outside your country. We do not sell your data, and we do not share it with anyone not on this list.

04Your prompts go to AI providers

This is the part worth understanding before you type anything sensitive. Your game description, the wording you give us, and the screens you approve or upload are sent to the AI providers listed above so they can generate your assets. That is not incidental — it is how the product works.

We use those providers' standard API tiers, which at the time of writing do not train their models on data sent through them. We cannot guarantee their terms will never change, so treat anything you send as leaving our control. Do not paste confidential material, personal data about other people, or anything you are not free to share.

05Your generated files are served from unguessable public links

Say this plainly rather than bury it: the images we generate for you are stored at web addresses that contain long random identifiers. Anyone who has the exact address can open the file without signing in. The addresses are not listed anywhere, are not guessable, and are not indexed — but they are not access-controlled either.

This is what lets your browser build the export ZIP directly. If that trade does not work for you, do not upload artwork you consider confidential.

06IP addresses, and the narrow reason we log them

We record your IP address and browser user-agent at four moments only: when you buy credits, when you start a generation, when you approve a screen and when you download a pack. Not page views, not general browsing.

The reason is disputes. If a payment is charged back or someone reports that they paid and received nothing, this is the evidence that answers it. It is deleted automatically after twelve months.

07Getting your data out, or deleting it

Deleting a project deletes its files. Ask us to delete your account and we remove your email, your projects, your files and your credit history.

Two things survive deletion, and you should know which. Records of purchases are kept where tax and accounting law requires it. Dispute records in the log described above keep their timestamps but have your account identifier removed, so they can no longer be linked back to you.

Depending on where you live you may have the right to access, correct, export, restrict or object to our use of your data, and to complain to your data protection regulator. Write to TODO — support@your-domain and we will answer within 30 days.

08Security

Card details never reach our servers — Stripe handles payment entirely. Sign-in has no password to steal. Each account can only read its own rows, enforced by the database rather than by application code alone.

No service is perfectly secure. If you find a vulnerability, please tell us at TODO — support@your-domain before telling anyone else.

09Changes

If we change this in a way that materially affects you, we will email the address on your account before it takes effect.

Questions about this document: TODO — support@your-domain