Privacy Policy

Last updated: October 23, 2025

1. Information We Collect

Account Information: When you create an account, we collect your email address and authentication credentials (or OAuth tokens from Google).

Design Images: We store design images you upload for analysis. Images are encrypted at rest and stored securely in our database.

Usage Data: We collect information about your analyses, including analysis results, timestamps, and feedback preferences.

Payment Information: Payment details are processed and stored by Stripe. We do not store your credit card information on our servers.

2. How We Use Your Information

AI Analysis: Your design images are sent to OpenAI's API to generate feedback. OpenAI processes images according to their privacy policy and does not train models on your data.

Service Delivery: We use your information to provide, maintain, and improve our design feedback service.

Billing: We use Stripe to process payments and manage subscriptions.

Communications: We may send you service-related emails about your account, subscription, or analyses.

3. Image Storage & Retention

Storage Duration: Design images are stored indefinitely until you delete them. You have full control to delete any or all of your images at any time.

Security: Images are stored in private, encrypted storage buckets with row-level security policies.

User Control: You can delete individual analyses (including images) from your history page at any time.

4. Third-Party Services

Supabase: Database and authentication (SOC 2 Type II compliant)

Stripe: Payment processing (PCI DSS compliant)

OpenAI: AI-powered analysis generation

Vercel: Hosting and deployment

5. Your Rights (GDPR & CCPA)

Access: You can access all your data through your account dashboard.

Deletion: You can delete your analyses and images at any time. To delete your entire account, contact us.

Portability: You can export your analyses as Markdown files.

Opt-out: You can unsubscribe from marketing emails at any time.

6. Data Security

We implement industry-standard security measures including:

  • Encryption at rest and in transit (TLS/SSL)
  • Row-level security policies on database
  • Private storage buckets with access controls
  • Regular security audits and updates
  • Secure authentication via Supabase Auth

7. Cookies

We use essential cookies for:

  • Authentication and session management
  • Remembering your preferences
  • Security and fraud prevention

8. Children's Privacy

Our service is not intended for users under 13 years of age. We do not knowingly collect information from children.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or through our service.

10. Contact Us

If you have questions about this privacy policy or your data, contact us at: rams@rams.ai

Send feedback