Learn what personal data SandArtAI collects, why we process it, how uploads and generated artwork are stored, and how to request access or deletion.
2026/07/24
This Privacy Policy explains how SandArtAI ("we", "our", "us") collects and uses personal data when you use our website and services. For privacy questions or requests, contact support@sandartai.com.
We use data to provide, maintain, and improve the service; run account, billing, and subscription workflows; detect abuse, fraud, and security issues; respond to support requests; and comply with legal obligations and enforce our Terms.
Sand art generation requires third-party AI processing. Google Gemini receives the uploaded source image and fixed, bounded analysis instructions that produce structured visual analysis. Those instructions are not used for identity, demographic, or open-ended free-text inference.
Replicate receives the source image, selected controls, compiled generation instructions, and any optional user instructions needed to generate the output. We use the resulting analysis and output to provide the requested feature.
Google and Replicate process data under their own terms and privacy practices. For Google Gemini paid services, Google states that prompts, files, and responses are not used to improve products, but limited abuse-monitoring retention may apply and Zero Data Retention has conditions. See Google's Gemini data retention documentation and Gemini API Additional Terms. Replicate states that API inputs, outputs, files, and logs are removed after one hour by default; see Replicate data retention and Replicate Privacy. Provider practices may change, and we do not make an absolute retention guarantee for provider copies.
Payments are processed by Creem, our Merchant of Record. Creem handles checkout, invoicing, tax collection, and payment processing. We do not store full card numbers and receive only the transaction metadata needed to provide the service and support your account.
We share data only with processors needed to operate the service, such as hosting, authentication, email delivery, analytics, payment processing, Google Gemini, and Replicate. We do not sell personal data.
SandArtAI stores source images, generated results, and thumbnails in private storage. We do not automatically publish your images or generated works.
Normal successfully completed works and their related source, result, and thumbnail assets are scheduled to expire 30 days after completion. Favorited normal works, and the assets needed to display them, remain available until you unfavorite or delete the work, a verified deletion request is completed, or retention is required for a legal or security need.
Unsubmitted standalone source uploads are scheduled to expire within 24 hours. Replacing or removing an unattached upload requests earlier cleanup; if that storage request fails, the retained metadata allows the scheduled cleanup process to retry. Source assets attached to failed or canceled work may remain for retry, security, and operations until you delete the associated work where that option is available or submit a verified deletion request to support. Migrated legacy works have no automatic expiry and are not eligible for Favorite. Deleting one through Legacy archive removes its registered legacy public source and result objects, removes its history record, and schedules its migrated private copies for cleanup. Account deletion handles these objects through the durable account-deletion cleanup request described below.
Account deletion first records a durable cleanup request and a bounded snapshot of the registered legacy public source and result object keys stored in sand_art_history, before credentials and generation metadata are removed. New generation uploads, legacy history saves, and generation job creation are frozen while account deletion is pending, so a failed self-delete can be retried without widening the cleanup set.
After the user row is removed and a conservative one-hour grace period has passed, scheduled cleanup deletes and verifies the account's canonical private generation prefix, exact legacy private prefixes, and the snapshotted registered legacy public objects. Any listing, validation, or storage deletion failure is retried from the durable cleanup request. Account deletion therefore schedules recoverable physical cleanup; it does not promise that every stored object is deleted synchronously with the account request. Verified deletion requests are processed subject to legal, security, fraud-prevention, and other permitted retention needs.
We retain account, usage, payment, and analytics data only as long as needed for the purposes in this policy, including legal, accounting, security, and abuse-prevention needs. Provider copies follow the provider retention practices described above.
Your data may be processed in countries other than your own. We use reasonable technical and organizational safeguards for data transfers and storage, but no internet service can guarantee absolute security.
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data. To exercise applicable rights, email support@sandartai.com. We may need to verify your request and may retain information where required or permitted by law.
We may update this policy from time to time. The latest version is published on this page with its updated date.