This policy explains what personal data SVG Mascot ("we") collects when you use SVG Mascot, why, and the choices you have. We are the controller of this data. Contact: [email protected].
Data we collect
- Account data — your name, email address and profile picture from Google or GitHub when you sign in, and a session cookie that keeps you signed in.
- Content — the prompts you write, the images and SVG files generated for you, and your projects.
- Billing data — your plan, subscription status and credit history. Card details are collected and stored by Creem, our Merchant of Record; we never see or store your full card number.
- Technical data — IP address, browser and request logs, used for security and troubleshooting.
We do not use advertising or third-party analytics trackers. The only cookies we set are strictly necessary: your sign-in session, and a short-lived (15 minute) cookie that carries a prompt you typed on our homepage into the app.
How we use it and why
- To provide the Service — generate and deliver your mascots, keep your projects and track credits (performance of our contract with you).
- To screen prompts for content that breaks our Acceptable Use Policy, prevent abuse and keep the Service secure (our legitimate interests and our payment provider's requirements).
- To process payments and meet tax and accounting obligations (legal obligation).
- To answer support requests and send essential service emails, such as receipts or changes to our terms.
We do not sell your personal data and we do not use your prompts or images to train AI models.
Who we share it with
We share data only with service providers that process it on our behalf to run the Service:
- Creem — Merchant of Record (checkout, payments, invoicing, tax) and prompt content moderation
- AI model providers — Generating mascot images from prompts and refining prompts
- Neon — Database hosting (accounts, projects, credit ledger)
- Upstash — Job queue
- Cloudflare — DNS, CDN, file storage (R2) and the billing service
- Contabo — Application servers
- Google, GitHub — Sign-in (OAuth)
Your prompts are sent to our content moderation provider (Creem) and to the AI model providers we use in order to generate your images. Some of these providers are located outside your country, including in the United States; where required we rely on appropriate safeguards such as Standard Contractual Clauses. We may also disclose data where required by law or to protect our rights and users.
Retention
We keep your account, projects and generated files for as long as your account is active. When you delete your account we delete this data within 30 days, except billing and tax records, which we keep for as long as the law requires. Server logs are kept for a limited time for security and then deleted.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to your data protection authority. To exercise these rights, email [email protected]. We respond within 30 days.
Children
The Service is not intended for anyone under 18 and we do not knowingly collect data from children.
Changes
We will post any changes to this policy here with a new "Last updated" date and notify you of material changes.