Privacy Policy
Last updated June 5, 2026
This Privacy Policy explains how The Refinery (“we,” “us,” or “our”) collects, uses, shares, and protects information about you when you use our website and services (the “Service”). By using the Service you agree to this Policy. It should be read alongside our Terms & Conditions.
1.Information We Collect
- Account information. Your email address (which is your login) and a securely hashed version of your password. We never store your password in plain text.
- Content you create. The prompts you write, any reference images you upload, your boards and their layout, and the images generated for you. These are stored on our servers so they persist across sessions and devices.
- Payment information. When you buy credits, payment is processed by Stripe. We receive confirmation of the transaction, the amount, and the credits purchased; we do not receive or store your full card number.
- Usage and technical data. Basic log and device information (such as IP address, browser type, and actions taken) generated automatically when you use the Service, used for security, debugging, and to operate the Service.
2.How We Use Information
We use the information we collect to:
- provide, operate, and maintain the Service and your account;
- process your generation requests through our third-party AI model providers;
- process purchases and maintain your credit balance and history;
- secure the Service, prevent fraud and abuse, and enforce our Terms and content rules (including automated and human review of content);
- respond to your requests and provide support; and
- comply with legal obligations.
We do not sell your personal information, and we do not use the content of your private boards for advertising.
3.How We Share Information
We share information only as needed to run the Service:
- AI model providers. Your prompts and reference images are sent to the third-party model providers that fulfil your generations (which may include Google, OpenAI, ByteDance / Seedream, Topaz Labs, and the kie.ai routing platform). Their handling of that data is governed by their own policies.
- Payment processor. Stripe processes payments and is responsible for your payment details under its own privacy policy.
- Infrastructure providers. Our hosting provider stores the Service’s data on our behalf.
- Legal and safety. We may disclose information if required by law, to respond to legal process, or to protect the rights, safety, and security of our users, the public, or the Service — including reporting child sexual abuse material to the authorities.
- Business transfers. Information may be transferred as part of a merger, acquisition, or sale of assets.
4.Cookies
We use a single essential cookie to keep you securely signed in (an authentication session cookie). It is required for the Service to function and cannot be disabled while you are logged in. We do not currently use advertising or third-party tracking cookies. If we add optional analytics in the future, we will ask for your consent first; you can review or change your choice from the cookie notice on our home page.
5.Data Retention
We keep your account information and content for as long as your account is active. If you delete your account, we delete your boards, images, and associated content, except where we are required to retain certain records (for example, transaction records for tax, accounting, or legal compliance). Backups and logs are retained for a limited period and then deleted or overwritten in the ordinary course.
6.Security
We take reasonable technical and organizational measures to protect your information, including password hashing and signed session tokens. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for keeping your password confidential.
7.Your Rights & Choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update your email, display name, and password in your account settings, and you can request account and data deletion by contacting us. We will respond to verified requests as required by applicable law. You will not be discriminated against for exercising these rights.
8.Children
The Service is intended for users 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, please contact us and we will delete it.
9.International Users
We and our providers may process and store information in countries other than your own, which may have different data-protection laws. By using the Service, you consent to such processing and transfer.
10.Changes to This Policy
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you. Your continued use of the Service after changes take effect means you accept the updated Policy.
11.Contact
For privacy questions or to make a data request, contact us at support@therefinery.com.