Privacy Policy

Last updated: June 17, 2025

1. What We Collect

We collect the following information when you use CutelyAI:

  • Account information: Your name, email address, and password (hashed).
  • Uploaded photos: Photos you upload to create AI portraits. These are stored privately on Cloudflare R2.
  • Generated images: AI portrait images generated from your photos.
  • Payment information: Billing details processed by Stripe. We do not store your card number — Stripe handles all payment data.
  • Usage data: Pages visited, features used, and device/browser information collected via Google Analytics.
  • Communications: Emails you send to our support team.

2. How We Use Your Data

We use your data solely to provide and improve the Service:

  • Processing your uploaded photos to train a personalized AI model (LoRA) unique to your account.
  • Generating portrait images using your trained AI model.
  • Sending transactional emails (account verification, password reset, generation complete notifications).
  • Processing payments and managing your subscription.
  • Improving the Service through aggregated, anonymised analytics.

We do not use your photos or your child's AI model to train any shared or public AI model. Your data is used exclusively for your own portrait generation.

3. Storage & Security

All uploaded photos and generated images are stored on Cloudflare R2, encrypted at rest using AES-256. All data is transmitted over TLS 1.3 (HTTPS). Access to your files is private by default — only you can access your photos and generated portraits through the Service.

AI model training is performed on isolated, ephemeral GPU instances via fal.ai under a strict data processing agreement. Training data is not retained by fal.ai beyond the training job.

4. Third Parties

We share data with the following third parties only as necessary to provide the Service:

  • fal.ai — GPU cloud for AI model training and image generation. Subject to fal.ai's data processing terms.
  • Cloudflare R2 — Private cloud storage for photos and generated images.
  • Stripe — Payment processing. Stripe is PCI DSS compliant.
  • Resend — Transactional email delivery.
  • Google Analytics — Anonymised usage analytics. You can opt out via Google's opt-out tool.
  • Sentry — Error monitoring for application reliability. No personal photo data is sent to Sentry.

We do not sell, rent, or share your personal data or your child's photos with any other third parties.

5. Photos of Children

We take the privacy of children's photos extremely seriously:

  • Your child's photos are stored privately and are never shared with other users.
  • Photos are not used to train any shared, public, or foundational AI model.
  • Your child's trained AI model (LoRA weights) is stored privately and never shared or sold.
  • We do not display your child's photos or generated images publicly.
  • Photos and models are deleted permanently when you delete your account.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • All uploaded photos are permanently deleted within 24 hours.
  • All trained AI models (LoRA weights) are permanently deleted within 24 hours.
  • All generated images are permanently deleted within 24 hours.
  • Account information is removed from our active database immediately.

We do not retain backups of deleted user content beyond 24 hours.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your data (GDPR Article 17, CCPA). You can delete your account at any time from Settings.
  • Portability: Request an export of your data in a portable format (GDPR Article 20).
  • Opt-out: Opt out of analytics tracking at any time.

To exercise these rights, email us at [email protected].

8. Cookies

We use the following cookies:

  • Session cookies: Required to keep you logged in. These are encrypted and expire when you close your browser or after 7 days.
  • Google Analytics cookies: Anonymised usage tracking. These are third-party cookies set by Google.

We do not use advertising cookies or cross-site tracking cookies.

9. Children's Privacy

CutelyAI is a service for parents and guardians — not for direct use by children. We do not knowingly collect personal information directly from children under the age of 13. The photos of minors uploaded by parents are processed solely to provide the portrait generation service requested by the account holder.

If you believe we have inadvertently collected personal information from a child, please contact us immediately at [email protected].

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. The date at the top of this page indicates when the policy was last updated.

11. Contact

For privacy questions, data requests, or to report a concern, contact us at [email protected].