Privacy Policy
Last updated: September 8, 2026
This policy describes the information processed when you use Thumbrix.
Information the service handles
- Account information such as name, email address, verification state, profile image, authentication accounts, and active sessions.
- Billing records such as orders, subscriptions, payment status, invoices, and credit balances. Complete card details are handled by the payment provider and are not stored in the application database.
- Product data created through enabled features, including API keys, chats, AI tasks, feedback, and uploaded asset metadata.
- Basic security and acquisition data, which may include IP address, user agent, locale, and campaign source.
API keys created in the account area are stored only as SHA-256 digests after the raw key is shown once.
How information is used
Information is used to authenticate users, provide requested features, process payments, maintain credit balances, prevent abuse, operate the service, and answer support requests.
Service providers
Thumbrix runs on Cloudflare infrastructure, sends thumbnail descriptions and optional reference photos to KIE for image generation, and uses the payment provider shown at checkout (Stripe, PayPal or Creem). It may also use Google or GitHub for optional sign-in, and Resend for transactional email when those integrations are configured. Each provider processes data under its own terms and privacy policy.
Thumbnail storage
Generated images and their task records are saved so you can return to a result. Free previews have a watermark baked into the file. Original files are served only after an account and purchase check. The image provider also processes your inputs under its own policies. Do not upload a reference photo unless you have permission to use it.
Cookies and local storage
Essential cookies maintain authenticated sessions and a guest trial identifier. A short-lived, salted hash of the connection IP is used to limit automated trial requests. The homepage stores text drafts in session storage and an optional reference photo in IndexedDB so they can survive checkout or login. You can remove a photo in the form or clear site data in your browser. Local storage may retain a theme choice and your analytics consent choice.
We use Google Analytics 4 to understand page views and interactions such as button clicks. Analytics cookies are denied by default and enabled when you choose Accept in the cookie banner. You can decline or change your choice at any time using Cookies in the footer. When analytics cookies are declined, Google may receive cookieless measurement signals. Advertising storage, advertising user data and advertising personalization remain denied by this consent setting. Google processes analytics data under its privacy policy.
Retention and security
Account and business records are retained while needed to operate the service, satisfy legal obligations, or resolve disputes. Reasonable technical safeguards are used, but no internet service can guarantee absolute security.
Your choices
You may update profile and security information from account settings. Contact the deployment operator to request access, correction, or deletion when those actions are not available in the product.
Contact
For billing questions, use the merchant contact details on your payment receipt.