Privacy Policy
This policy describes how Stilllight (“we”, “us”) handles information when you use the image creation service. Please review it before creating an account or uploading images.
Information we handle
- Account: your email address, a salted password hash, account and session timestamps.
- Creation: prompts, selected generation settings, generated images, and credit activity. Generated images and prompts are saved to your account library until you delete them or delete your account.
- Reference images: image-to-image uploads are sent to the image provider to fulfil your request. Stilllight does not save the uploaded reference image in your library.
- Payments: Stripe processes checkout and payment details. Stilllight receives payment identifiers, plan, amount, currency, and subscription status to fulfil your purchase. We do not receive or store your full card number.
- Technical data: essential session cookies and limited server logs needed to operate and protect the service. The service does not currently use advertising trackers.
How we use information
We use account and session data to sign you in; prompts and reference images to generate or edit images; generated images to provide your private library and downloads; and payment events to add, spend, expire, or refund credits and manage subscriptions. We also use limited technical information to prevent abuse and troubleshoot failures.
Image and payment providers
Prompts and reference images are sent to OpenAI’s API for image generation or editing. OpenAI states that API data is not used to train its models by default, and that image-generation and image-editing requests may be retained for up to 30 days for abuse monitoring under its standard controls. OpenAI’s own terms and data controls apply to that processing; we do not control its systems. OpenAI API data controls.
Payments are processed by Stripe. Stripe handles card entry and provides payment, refund, and subscription events to Stilllight. Hosting providers may process data needed to run the service. These providers may process information in countries other than yours under their own terms and safeguards.
Storage and deletion
Your generated images, prompts, account, credit ledger, and payment records are stored by the service until you delete the relevant images or request account deletion. Deleting an image removes it from your library and active image storage. Account deletion cancels active subscriptions where possible, removes images and login access, and replaces account identifiers with a deleted-account marker. A minimal credit and payment audit trail may remain in pseudonymised form to prevent duplicate fulfillment and meet accounting or legal obligations. Stripe and other providers may retain transaction records under their own terms or law. Copies already downloaded by you or other people cannot be recalled.
Cookies and security
Stilllight uses a necessary, HTTP-only session cookie to keep you signed in. It is not used for advertising. We use password hashing, account-scoped access checks, and signed payment events, but no online service can guarantee absolute security. Use a unique password and do not upload confidential or sensitive material unless you are comfortable sending it to the image provider.
Your choices
You can review and delete images from your library, sign out, and request account deletion from account settings. For access, correction, privacy, or billing questions, contact cshu763@gmail.com. Applicable privacy rights depend on your location; we will respond to requests as required by applicable law.
Children and prohibited content
Stilllight is not intended for children under 13, or the higher minimum age required where you live. Do not upload or create content that violates our Terms, another person’s rights, or applicable law.
Policy updates
We may update this policy as the service changes. The effective date above will change when we publish a revision. Material changes will be communicated through the service or to the account email where reasonably practicable.
This policy reflects the current MVP implementation. We will update it if data handling, storage providers, or features change.