Account and usage information
Sign-in uses Supabase email verification. We maintain account identifiers, email-related trial eligibility records, credit balances and usage records to operate accounts and prevent repeated free-trial claims. A secure session cookie keeps you signed in. Requests may be rate-limited using account and network information.
Photos and conversations
Selecting a photo and locating facial landmarks happens on your device. Approving a simulation sends your photo through Netlify to OpenAI to prepare the requested edit. Image generation uses fal.ai, and OpenAI compares the original and generated photos to check the result. Some eyebrow previews are created directly by PlastyAI. Camera previews stay on your device and stop when captured or closed. When live chat is enabled, messages you send are processed by OpenAI. We also include a minimal server-verified summary of your credit balance, recorded credit purchases, simulation usage and current simulation status to answer account questions. This summary excludes your email, account identifiers, payment details and order references. Adding a portrait prepares it on your device and enables Photo included. Nothing is sent just by uploading. Selecting Send (or pressing Enter while photo inclusion is enabled) sends a resized copy of the portrait with your message through Netlify to OpenAI. Turn off Include photo for text-only messages. After a simulation, you can also choose to include the simulated result. Chat photo requests are not saved in the PlastyAI image store; provider retention policies still apply.
Temporary image storage
Photos and results are temporarily stored in encrypted form on Netlify. Ordinary image records expire one hour after creation. The Clear action requests deletion of the server image record once processing finishes. Hourly cleanup normally removes expired image records within approximately two hours. This temporary image policy does not mean account and credit records are deleted on the same schedule.
Provider processing
Third-party providers apply their own processing and retention policies. We cannot promise immediate deletion of provider-side records. See OpenAI, fal.ai, Supabase, Resend and Netlify. Resend delivers authentication emails. Processing may occur in countries other than your own.
Training and access
No model training is running. Uploading a photo, generating a result or submitting a rating does not grant permission for model training. After a result, you may separately choose to contribute the prepared original photo, AI result and approved editing description for private review and dataset preparation. This stage does not authorize training or transfer to a training provider; that requires a separate future permission. Third-party processing of ordinary simulations remains governed by provider policies.
Optional review contributions
Contribution is off by default and does not affect your credits or access. Only contribute your own adult photo with the necessary rights. Your rating can be saved without photos. Contributed photo pairs and editing descriptions are stored encrypted on Netlify, accessible to the authorized PlastyAI reviewer; they are not published or sent to a training provider. The reviewer may approve an example and download a private preparation package. Approval does not mean training has occurred or that an AI image predicts a surgical outcome.
Feedback and contributions expire 30 days after submission and are removed by the next hourly cleanup. Use My contributions to withdraw a photo pair sooner. Withdrawal removes the stored photos and editing description and blocks further export; a minimal feedback/withdrawal record remains until expiry. To delete that record too, or to delete your account and all contributions, contact support. Clearing a simulation or signing out does not withdraw a contribution.
Downloaded reviewer copies must also be deleted after withdrawal or expiry. Server withdrawal cannot remotely erase an already-downloaded file; contact support to have such copies removed. No model training is active, and separate permission will be required before any future training. Do not assume that future withdrawal could undo learning in a trained model.
Account deletion
Contact our support address to request account deletion. Temporary images follow their own cleanup schedule. Deleting an account does not instantly remove provider-side records or files downloaded to your device.
Your choices and contact
Only upload adult photos you have permission to use. Images are not displayed in a public gallery. Downloads remain on your device. For privacy questions or an account-data request, email plastyai@protonmail.com; identity verification may be needed. Do not send sensitive medical records with your initial request.
Optional private concept links
After a confirmed result you may explicitly create a temporary private link. Only the AI concept is shared, not the original photo, chat or account details. Anyone with the link can view and save it. The link expires within 30 minutes by default, capped at the result’s one-hour lifetime, and can be revoked from the result screen. Clear or creating another concept also disables access. Saved copies cannot be recalled. There is no public gallery.
Product interaction events
The interface emits local events for actions such as upload, preference selection and downloads. Only predefined topic, visual-direction and preference labels, sign-in and free/paid status, a broad credit-balance range, mobile/desktop category and a coarse trial decision/risk category may be included. No photo, message text, facial data, email or account identifier is included. No external analytics collector, tracking cookie or event storage is enabled by this update.
Your photo, explained
Your photo is not used to train AI unless you separately and explicitly consent. Uploading, saving a private history or rating a concept is not training permission.
How long is my photo kept?
Ordinary encrypted image records are normally removed within about two hours. Separately contributed review examples expire after 30 days. Use Clear to request deletion sooner once processing finishes. Providers have separate retention policies.
Is my photo used to train AI?
No model training is running. Uploading or rating a result never enrolls photos for training. After a result, you may separately contribute a photo pair for private human review for up to 30 days. Future training needs separate permission. Read about contributions.
Who processes or can access it?
Netlify hosts processing and temporary storage. OpenAI answers messages and sees the photos you include, and helps prepare and check edits; fal.ai generates image edits. Some eyebrow previews are created directly by PlastyAI. Images are not published in a gallery. Service providers process them, and authorized operators may have administrative access.
What if I delete my account?
Contact us to request account deletion. Images follow the temporary cleanup schedule independently; account deletion does not instantly erase provider records or downloads on your device.
Optional private result history
Saving history is a separate choice after a confirmed concept. With your explicit storage permission, up to six original/concept pairs and their approved descriptions are encrypted in your account history for up to 30 days. They are accessible through your signed-in account, not a public gallery, and are not enrolled for model training. Delete saved concepts from Saved concepts. Clearing the ordinary studio record does not delete saved history; expired history is inaccessible and its photo data is cleared by scheduled cleanup. Downloaded files remain on your device. Provider retention policies are separate.
Fair access to free concepts
To reduce repeated free trials, we process limited technical signals: verified email status, an essential random device cookie, short-lived network rate-limit information and a portrait-similarity signal. These signals are used only for service security and trial eligibility, not advertising, profiling or model training. We do not use hidden browser fingerprinting or face recognition.
The device cookie is HttpOnly, Secure and SameSite, lasts up to 30 days and is separate from your sign-in cookie. Logging out does not reset it. We store a keyed hash, not the raw token. Network information comes from our hosting platform; our trial records contain a keyed identifier rather than a raw IP address. Network limits are temporary and do not label a person as abusive.
When you agree to create your first free concept, we check the JPEG in memory. We keep a keyed exact-file digest and encrypted, low-detail whole-image similarity hashes, not an additional copy of the photo. These can help identify a reused, resized or lightly cropped image; they do not identify a person. A shared device, network or similar photo may be legitimate. A single device or photo match does not permanently block an account. Contact support if a trial check seems wrong.
Retention and deletion
- Network request information: up to 1 hour for preparation/generation attempts and up to 24 hours for trial activations. It becomes inactive at expiry. Dated records are removed by hourly cleanup, normally within approximately two further hours.
- Device and portrait associations, similarity hashes and detailed decision signals: up to 30 days, then removed by scheduled cleanup. A hash-bucket can remain while other unexpired entries use it; expired entries are removed.
- A keyed verified-email trial claim: up to 180 days. It prevents recreating a recently used email from renewing the trial. Account-linked entitlement and credit transaction records remain with the account so signing in again cannot grant duplicate credits.
Clearing a studio photo does not reset trial entitlement. For an account deletion request, contact support; limited abuse-prevention associations may remain until the periods above expire, while the account-linked data is handled through that request. Older email-only trial-suppression records may still exist from the previous system and are included in account-deletion review. Provider retention and downloaded files are separate. A trial limitation never deletes purchased credits.
No model training permission is granted by a trial check, upload, photo-similarity check or saved history. Any future training contribution requires a separate, explicit permission.
Consultation Prep PDFs
When you request a PDF, your signed-in account and PDF entitlement are checked on our server. For a current concept, the prepared original portrait is sent back to Netlify and matched against its recorded digest. Saved-history PDFs use the already stored original and concept. The document is prepared in server memory from these images, the recorded visual preference and any optional user notes. No new OpenAI or fal.ai request is made. The generated PDF is returned to your browser; we do not save an additional PDF file or your PDF notes for this feature.
We retain an account-linked receipt containing the concept identifier, creation time and entitlement version so the same concept does not consume a second PDF right. Receipts and paid credit accounting remain with the account. Redownload requires the source concept to remain available. Downloads remain on your device.
Account sign-in
Email and password sign-in is handled by Supabase Auth through our Netlify server. Passwords are forwarded securely for authentication and are not stored in our credit records, browser storage or analytics. New accounts must verify their email before using the studio. Password recovery uses an email link or code; optional email-code sign-in remains available. Your encrypted session is kept in a secure, HttpOnly cookie for up to one hour, and the server checks that session with Supabase. Setting a password on an existing account does not create new credits or change its trial history.
Payments
When you choose a paid package, our server sends Dodo Payments your sign-in email, the selected product and a random checkout reference. You enter payment and billing details directly on the Dodo-hosted checkout. PlastyAI does not receive or store your full card details. Our payment integration does not send portraits, visual concepts, chat prompts or health information to Dodo.
We store encrypted account-linked checkout references and payment records to deliver credits, prevent duplicate grants and reconcile refunds. Checkout-attempt rate-limit records are removed after 24 hours, test payment records after 7 days and live checkout preparation records after 30 days, by the next hourly cleanup. Live payment bindings and credit/PDF accounting records remain available for reconciliation and are reviewed when an account-deletion request is received. They are not automatically erased by Clear; contact support to request deletion and learn which payment records need to be retained.
Dodo Payments processes payment data under its own privacy policy and retention rules. Payment records are not used by PlastyAI for model training or advertising.
Chat access and retry handling
We record reply usage and purchased chat rights with your signed-in account. A reply is counted only after it is successfully prepared. For safe retries, the encrypted account record temporarily holds a request identifier, a digest of the request and the completed text reply. These retry records expire after 10 minutes (unfinished requests after 2 minutes) and are removed on the next chat request or hourly cleanup. They are not used for model training, advertising or profiling; no extra portrait or full input prompt is saved in these records.
Short account and shared-service rate-limit counters are removed after 24 hours by the next hourly cleanup. Aggregate reply usage and purchase entitlement records remain with the account for service delivery and payment reconciliation. Clear removes the conversation from your browser; temporary reply records expire as described above. For account deletion, contact support. These records are not sent to analytics.