Privacy Policy
Last updated: 20 April 2026
This Privacy Policy explains how Inpaintly ("we", "us"), operated by Ascend Global Data, collects, uses and protects your information when you use our service at inpaintly.app (the "Service").
1. Information We Collect
Account data: your email address, provided when you sign up via magic link.
User content: photos you upload, masks you draw, prompts you enter, and AI-generated output images.
Billing data: purchase records (order ID, credits bought, amount, date). We do not store your card details — those are handled entirely by LemonSqueezy.
Usage data: basic logs such as IP address, browser user-agent, pages viewed and generation timestamps, used for security and fraud prevention.
2. How We Use Your Information
- To authenticate you and run the AI generation you requested;
- To track your credit balance and purchase history;
- To prevent abuse, fraud and violations of our Terms of Service;
- To reply when you contact support;
- To send transactional email (receipts, magic-link logins). We do not send marketing email unless you opt in.
3. We Do NOT Train Models on Your Data
Your uploads, masks and output images are never used to train any AI model — ours or a third party's. They exist only to serve your generation request and your personal gallery.
4. Subprocessors
We rely on the following vetted third-party services to run Inpaintly:
- Supabase — authentication, Postgres database, object storage. Hosted in the EU/US.
- Replicate — hosts the AI inpainting model. Your photo + mask are sent to Replicate to run the generation and the result is returned to us. Replicate's privacy policy applies to that leg of the pipeline.
- LemonSqueezy — merchant of record for payments. Receives your billing details directly.
- Vercel / Cloudflare — hosting and CDN for the website.
Each subprocessor has a published Data Processing Agreement and GDPR-compliant privacy policy.
5. Data Retention
- Uploaded input photos + masks: deleted automatically 30 days after generation, or immediately on request.
- Generated output images: kept in your personal gallery until you delete them or delete your account.
- Account record: kept while your account is active. Deleted within 30 days of account deletion request, except where retention is required by law (e.g. tax records for 5 years).
- Purchase records: retained for 5 years for tax/accounting compliance.
6. Your Rights
Regardless of where you live, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your account and associated data;
- Export your data in a portable format;
- Object to specific processing;
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email hello@inpaintly.app. We respond within 30 days.
7. Cookies
We use a single first-party session cookie required to keep you logged in. We do not use advertising cookies or third-party trackers on our main app flow. The marketing site may include a privacy-respecting analytics script (Plausible or Cloudflare Web Analytics) that does not identify individuals.
8. Children's Privacy
The Service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a minor has signed up, contact us and we will delete the account.
9. Security
Data is encrypted in transit (HTTPS/TLS) and at rest. Access to production systems is restricted to the operator and protected by 2FA. We will notify affected users within 72 hours of discovering a qualifying data breach.
10. International Transfers
Inpaintly is operated from Sri Lanka and uses service providers in the EU and US. By using the Service you consent to your data being processed in these jurisdictions.
11. Changes
We'll post material changes here with a new "last updated" date and, if significant, email registered users.
12. Contact
Privacy questions: hello@inpaintly.app.