Privacy Policy
Product Ad Kit (productadkit.app)
Last updated: August 3, 2026
This Privacy Policy explains what information Product Ad Kit (“we”, “us”, “the Service”) collects, how we use it, and the choices you have. We designed the Service to collect only information needed to provide, secure, and improve the Service. Some text previews may be available without an account, while account-based features use a login session.
1. Information We Collect
Information you provide directly:
- Product and generation inputs. Product names, product descriptions, additional instructions, prompts, and other text you submit to create advertising materials.
- Images. Product images you upload and images generated by the Service. Uploaded and generated images may be persistently stored so they remain available for generation, display, and download.
- Account information. Your login email, internal user identifier, authentication session, and related account timestamps used to sign you in and associate records with your account.
- Generation records and status. Records may include generation status, prompts, provider prediction identifiers, source and generated file URLs, R2 object keys, MIME types, errors, and creation or completion timestamps.
- Payment, subscription, and webhook information. Depending on the available payment flow, we may receive provider identifiers, product and order information, amounts, currency, status, timestamps, and limited customer or account identifiers needed for payment operations and testing.
- Support communications. If you email us, we keep the correspondence to help resolve your issue.
Information collected automatically:
- IP address. Used to rate-limit requests to the free preview, so it stays fair and available and to prevent abuse. Free-tier usage counts are associated with IP addresses, which are processed on a short-term basis for this purpose.
- Basic technical data. Standard server logs (request timestamps, user agent, pages requested) generated by our hosting infrastructure for security and debugging.
Payment information: We do not collect or store your card details. Payments are processed by Creem (creem.io) as Merchant of Record. Creem collects the billing information needed to process your payment and issue a tax-compliant invoice, under its own privacy policy. We receive from Creem only the information necessary to fulfill your order (such as your email address, order ID, and payment status).
Cookies. We use only essential cookies and browser storage needed for the Service to function (such as keeping you signed in). We do not use advertising cookies or cross-site tracking.
2. How We Use Information
- To generate text-based advertising materials and product images;
- To store, display, and make uploaded or generated images available for download;
- To maintain generation records and restore account-based results;
- To process orders and manage subscriptions (via Creem);
- To send transactional emails such as receipts, kit delivery links, and important service notices;
- To enforce rate limits, prevent abuse, and secure the Service;
- To respond to support requests;
- To debug, maintain, and improve the Service.
We do not sell your personal information, and we do not use your data for third-party advertising.
3. AI Processing of Your Inputs
Product names, descriptions, and text instructions used for copy generation may be sent to OpenRouter, which routes requests to text-generation model providers. Product images and additional image instructions used for image generation are sent to Replicate for model inference. Uploaded product images and generated images are stored in Cloudflare R2. We recommend not submitting confidential material or personal information that is unnecessary for generation.
4. Service Providers
We share data with a small number of service providers who process it on our behalf, strictly to operate the Service:
| Provider | Purpose |
|---|---|
| Vercel | Website hosting and server infrastructure |
| Neon | Database hosting for accounts, generation metadata, orders, and webhook records |
| Creem | Payment processing and tax compliance (Merchant of Record) |
| OpenRouter | AI model routing for text generation |
| Replicate | AI model inference for product image generation |
| Cloudflare R2 | Storage for uploaded product images and generated images |
| Resend | Sending Magic Link and other transactional emails |
| Better Auth | Authentication and session management software |
| Waffo | Test-stage durable webhook inbox validation; not a production payment processor |
Each provider processes data under its own security and privacy commitments. We may also disclose information where required by law or otherwise described in this Policy.
Creem is the current production payment processor and Merchant of Record. Waffo is currently limited to test-stage durable webhook inbox infrastructure and is not enabled as a production payment processor or entitlement provider.
5. Data Retention
- Generation data and images may be persistently retained, including uploaded product images, generated images, prompts, URLs, object keys, prediction IDs, statuses, errors, and timestamps.
- Purchased kits and associated order records are retained for as long as needed to provide you access to your purchase and to meet legal and accounting obligations.
- IP-based rate-limit records are short-lived and rotate on a rolling basis.
- Support emails are retained as long as reasonably necessary.
- Webhook inbox records may contain the complete verified event payload, including email, user identifiers, order information, or subscription information. Complete webhook payloads and authentication information are not printed in application logs.
The Service does not currently have one automatic deletion mechanism or uniform retention period covering every category above. Retention depends on operational, account-access, security, dispute, and legal needs. Before any production Waffo enablement, we must separately establish an appropriate webhook data retention period and deletion strategy.
6. Your Rights
Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act), you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request deletion of your data;
- Object to or restrict certain processing;
- Receive a copy of your data in a portable format;
- Not be discriminated against for exercising these rights.
To exercise any of these rights, email support@productadkit.app. We will respond within the timeframe required by applicable law. Note that data held by Creem as Merchant of Record (such as invoicing records) is subject to Creem’s own retention obligations and privacy policy.
7. International Transfers
We are a globally operated service. Your data may be processed on servers located in different countries, including the United States, through the service providers listed above. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our providers.
8. Security
We take reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS), encrypted database connections, webhook signature verification for payment events, and access controls. No method of transmission or storage is 100% secure, but we work to protect your information appropriately.
9. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date reflects the latest version. Material changes will be communicated via the Service or by email where practical.
11. Contact
For any privacy questions or requests: support@productadkit.app