Privacy Policy
Last updated: October 2, 2026
This policy explains what personal data AIFlowCard collects, why we collect it, who we share it with, and the choices you have. We have tried to keep it short and specific rather than copy-pasted from a template.
1. Who we are
AIFlowCard ("AIFlowCard", "we", "us") operates the website at www.aiflowcard.com and the card-generation service available through it (the "Service"). The Service is independently operated.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), and comparable laws, we are the data controller of the personal data described in this policy. You can reach us at support@aiflowcard.com.
2. Information we collect
Account information
- Your email address and account creation date.
- Your password. This is stored only in hashed form by our authentication provider. We never see or store your password in plain text.
- Your credit balance and credit transaction history.
Content you submit
- The notes, articles, or other text you paste in order to generate cards.
- Any reference images you choose to upload.
- The prompts and the card images produced for you.
Usage and technical data
- Your generation history and the settings you used, such as style, aspect ratio, and card count.
- Basic technical data such as IP address, browser and operating system type, and request logs generated by our hosting and content-delivery providers.
Payment information
Payments are processed by Creem, who acts as the merchant of record. We receive only limited information from them: your email address, order and subscription identifiers, which product you purchased, and the payment status. We never receive, process, or store your full card number or other complete payment credentials.
3. How we use your information
- To provide the Service, including generating cards and managing your credits.
- To process payments, manage subscriptions, and prevent fraudulent transactions.
- To respond to your support requests.
- To keep the Service secure, diagnose faults, and prevent abuse.
- To comply with our legal and tax obligations.
We do not sell your personal data. We do not share your content with advertisers. We do not use the content you submit to train generative AI models of our own.
AI processing — please read
When you generate cards, the text you submit is sent to third-party AI model providers (listed in section 5) so that they can produce the intermediate prompts and the final card images. This means your submitted text leaves our systems and is processed by those providers under their own terms.
Please do not submit sensitive personal data (for example health, financial, or government identification data), confidential information belonging to someone else, or personal data about other people that you do not have permission to share.
4. Legal bases for processing (EEA and UK)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create your account, generate cards, and operate your credits and subscription.
- Legitimate interests — to secure the Service, prevent abuse, and diagnose technical problems, balanced against your rights.
- Legal obligation — to keep payment and tax records where the law requires it.
- Consent — where we ask for it explicitly, for example for any optional communications. You may withdraw consent at any time.
5. Third-party service providers
We rely on the following providers to run the Service. Each one only receives the data needed for its specific function.
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Authentication, database, and file storage | Singapore |
| Vercel | Website hosting and delivery | United States |
| Cloudflare | DNS, CDN, and inbound email routing | United States |
| Creem | Payment processing and merchant of record | Estonia (European Union) |
| DeepSeek | Text model used to draft card content and image prompts | China |
| Google (Gemini API) | Image generation model | United States |
| Volcengine (ByteDance) | Image generation model | China |
6. Cookies and local storage
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile you across websites. We use browser local storage strictly to make the Service work:
- Your login session token, so you stay signed in.
- Your theme (light or dark) and language preference.
Because these are essential to provide the Service you requested, they do not require consent under the ePrivacy Directive. If we ever add optional analytics, we will update this policy and ask for your consent first where the law requires it.
7. How long we keep data
- Account data — kept while your account is active, and deleted within 30 days after you ask us to close it.
- Your submitted text and generated images — kept until you delete them or close your account.
- Payment and invoice records — kept as long as tax and accounting law requires.
- Server logs — kept for a short period for security and troubleshooting, then discarded.
8. International transfers
We operate globally, so your data may be transferred to and processed in countries other than the one you live in — including Singapore, the United States, the European Union, and China. Where the law requires safeguards for such transfers, we rely on appropriate mechanisms such as contractual protections with our providers, and we limit transfers to what is necessary to run the Service.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your account and the data associated with it.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw any consent you previously gave.
- Lodge a complaint with your local data protection authority. If you are in the EU or UK, you can complain to the supervisory authority in your country of residence.
You can exercise most of these rights from your account page, or by emailing support@aiflowcard.com. We respond within the timeframe required by applicable law.
10. Security
Data is encrypted in transit, passwords are hashed, and access to production systems is restricted. That said, no method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Children
The Service is not intended for children. You must be at least 13 years old to use it, or older where your local law sets a higher minimum age for online services without parental consent. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. When we make a material change we will update the date at the top of this page and, where appropriate, notify you by email or in the app. Please check back periodically.
13. Contact
For any question about this policy or your data, email support@aiflowcard.com.