Privacy Policy
This policy explains what data Image Gen API (operated by Sikasio) collects, why, and what happens to it. The short version: we collect the minimum needed to run an image-generation API, we don't sell your data, and your generated images are deleted automatically.
1. What we collect
- Account data — your name, your email address, and a salted hash of your password. We never store the password itself.
- API usage logs — per-request metadata (API key, IP address, endpoint, response status, timing, request size) kept for up to 30 days for abuse prevention, credit accounting, and debugging.
- Prompts and generated images — prompts are processed to generate your images. Generated images are stored as hosted result URLs and automatically deleted after 7 days.
- Billing data — payments for paid plans are handled entirely by Polar (polar.sh) as merchant of record. We never see or store your card details; we receive only your subscription status and plan.
2. What we use it for
To provide the service (authenticate keys, enforce credits and rate limits), to send transactional email (verification codes, password resets, account notices), to prevent abuse, and to comply with legal obligations. We do not send marketing email without your consent, and we do not sell or rent your personal data to anyone.
3. Cookies
The customer portal sets a single session cookie so you stay signed in. There are no advertising, analytics, or third-party tracking cookies.
4. Sharing
We share data only with the processors needed to run the service: our hosting provider, the AI model provider that renders your prompts into images, our transactional-email provider (to deliver account emails), and Polar for payments. Each receives only what it needs. We may disclose data if legally required.
5. Retention
- Account data — kept while your account exists.
- API usage logs — deleted after at most 30 days.
- Hosted generated images — deleted after 7 days.
6. Your rights
You can ask us to export or delete the personal data we hold about you, or delete your account entirely, by emailing support@sikasio.com from your account address. We answer within 30 days. Depending on where you live you may have additional statutory rights (such as under the GDPR), which we honor.
7. Security
All traffic is encrypted in transit (TLS). Passwords are hashed with a memory-hard algorithm, API keys are stored only as hashes, and access to production systems is restricted. No system is perfectly secure — if a breach affects your data we will notify you.
8. Changes
We may update this policy as the service evolves. Material changes will be announced by email or on the site, with the "Last updated" date above revised.
9. Contact
Privacy questions and data requests: support@sikasio.com.