PhosphenePhosphene View plans

Privacy Policy

Effective date: July 29, 2026

1. Who this policy covers

This Privacy Policy explains how Phosphene Inc. ("Phosphene", "we", "us", or "our") collects, uses, shares, and protects information when you use phosphene.cc, our image-generation tools, subscriptions, galleries, and related services.

2. Information we collect

  • Account details such as email, name, profile image, authentication provider, and preferences.
  • Content data such as prompts, reference images, generated images, tags, dream sessions, and gallery posts.
  • Billing records such as plan, credit balance, Creem or App Store transaction and subscription references, status, and receipts.
  • Usage data such as pages viewed, actions taken, generation history, support requests, and feature interactions.
  • Technical data such as IP address, device, browser, locale, cookies, logs, and security events.

3. How we use information

  • Provide, personalize, secure, and improve the Service.
  • Generate images, manage credits, process subscriptions, and provide support.
  • Detect abuse, enforce our Terms, prevent fraud, and protect users and providers.
  • Send transactional messages about your account, payments, credits, security, and service updates.
  • Analyze product performance, diagnose errors, and understand aggregate usage trends.

4. AI processing

Prompts, reference images, generated images, and related metadata may be sent to AI model providers and infrastructure vendors to generate, transform, upscale, moderate, or store outputs. Do not upload sensitive personal data or content you do not have rights to use.

5. Photos, avatars, and face data

Profile avatars

A profile avatar is optional and is uploaded separately in Profile settings. We resize it to a 512-pixel WebP image and display it in your profile and account interface. A photo received from an authentication provider is account information and is not automatically copied to your profile avatar. On Phosphene web, the profile avatar may also appear only with content you explicitly choose to publish. We do not send a profile avatar to an AI provider unless you separately select that image as a reference image.

Reference photos that may contain faces

When you choose reference photos, we collect the image files, basic file information, and private resized copies. We use the photos only to perform the image creation, edit, or animation request you initiate. The selected AI model may analyze visible facial features in the image to produce the requested result.

Phosphene does not use TrueDepth, Face ID, or ARKit face data. We do not create or store face geometry, landmarks, embeddings, biometric identifiers, or a biometric template separate from the image file. We do not use reference photos or facial features for authentication, identification, advertising, marketing, analytics, user profiling, or training our own models.

Processing and sharing

This Privacy Policy explains this processing. When you generate or edit, the full reference image is sent only to the AI processor needed for the model you selected. Depending on that model, processors may include OpenAI, Google, OpenRouter and its selected model provider, fal.ai and its selected model provider, or Alibaba Cloud. Our private object-storage provider stores the reference library for us. These processors may use the image only to provide the requested service and related security or abuse prevention; we do not authorize them to use it for advertising, marketing, user profiling, or training their general models.

We disable fal.ai request input/output storage and require zero-data-retention, no-data-collection routing for OpenRouter image requests. OpenAI may keep API inputs and outputs in abuse-monitoring logs for up to 30 days unless law or security needs require longer. Google's paid API terms prohibit using prompts to improve its products, and Alibaba Cloud states that Model Studio inputs are not used for model training; temporary Alibaba task and result links expire after 24 hours. Other processor-side security records follow the processor's business API terms.

Storage, retention, and deletion

Reference photos are private and owner-restricted. We retain each reference photo and its resized copies until you delete that individual photo from your reference library or delete your account. Deleting a reference photo removes its active object-storage files and database record. Deleting your public avatar removes its active object-storage file and clears it from your public profile. Deleting your account removes your stored reference photos, public avatar, and related account records, subject only to records we must keep for legal, security, fraud-prevention, or financial obligations.

AI processors receive a reference image for a generation request rather than as your persistent Phosphene reference library. Processor-side transient logs or safety records are retained only for the limited period stated in the applicable processor's business API terms or as legally required. You can stop future processing by deleting the photo and not uploading it again. To request deletion of any required residual record, contact us using the details below.

6. Payments

Web orders are processed by Creem, our merchant of record. Purchases in the iOS app are processed by Apple through the App Store. Creem or Apple may collect payment details, tax information, billing address, and fraud-prevention signals under their own privacy terms. We do not store full card numbers. We receive transaction, subscription, and receipt information needed to activate plans, manage credits, provide support, prevent fraud, and keep accounting records.

7. Service providers and sharing

We share information with vendors only as needed to operate the Service, including:

  • Payment processing and merchant-of-record services.
  • AI model, image-generation, moderation, and infrastructure providers.
  • Hosting, database, object storage, CDN, logging, and error-monitoring services.
  • Email, customer support, analytics, security, and fraud-prevention tools.

We may also disclose information to comply with law, enforce our Terms, protect rights and safety, or complete a merger, acquisition, financing, or sale of assets. We do not sell personal data.

8. Cookies and analytics

We use cookies, local storage, and similar technologies for authentication, security, checkout continuity, preferences, analytics, and product diagnostics. You can control cookies through your browser settings, but some features may stop working.

9. Data retention

We retain information for as long as needed to provide the Service, maintain security, resolve disputes, comply with legal and tax obligations, and enforce agreements. Generated content and account data may be deleted on request unless retention is required for legitimate business, safety, or legal reasons.

10. Security

We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. International transfers

We and our providers may process information in countries other than your country of residence. Where required, we use appropriate safeguards for international transfers.

12. Your rights

Depending on your location, you may have rights to access, correct, export, delete, or restrict use of your personal data, and to object to certain processing. Contact us to submit a request. We may verify your identity before fulfilling requests.

13. Children

The Service is not intended for children or for users below the age of majority in their jurisdiction. We do not knowingly collect personal data from children.

14. Contact

Privacy questions and data requests: [email protected].