Privacy Policy
Last updated: July 7, 2026
This policy explains what Unstill collects, why, and who touches it. Short version: we collect the minimum needed to run accounts, credits, and generation — and we don't sell any of it.
1. What we collect
- Account data — email address, optional name, phone number (phone sign-in only). Passwords are stored as scrypt hashes; SMS codes and email tokens as SHA-256 hashes. We never store plaintext secrets.
- Your content — prompts, briefs, uploaded reference images (processed for generation, not retained as originals), saved projects, and pieces you explicitly share.
- Usage records — an append-only log of credit-consuming actions (action type, credit amount, timestamp) for billing integrity and abuse prevention.
- Payment data — handled entirely by Stripe. We receive only your email, the plan purchased, and payment status — never card numbers.
- Cookies — a single signed session cookie for login. No advertising or cross-site tracking cookies.
2. How we use it
- Operating the Service: authentication, credit metering, saving and sharing your work.
- Generation: your prompts and reference images are sent to the AI providers below to produce your output.
- Transactional messages only — verification links, password resets, OTP codes, receipts. No marketing without separate opt-in.
- Safety: rate limiting and abuse detection using IPs and usage patterns.
3. Processors we rely on
- Supabase — database (accounts, credits, projects, shares).
- Stripe — payments and subscriptions.
- Google AI — text/vision generation of briefs and
.unstillfiles. - ElevenLabs — narration text-to-speech.
- MSG91 — SMS delivery of sign-in codes (phone number + code only).
- Resend — transactional email delivery.
- Hosting infrastructure (e.g. Vercel) — request logs including IP addresses.
Each processes data only to provide its function, under its own privacy terms. If you bring your own API keys, your prompts go to those providers under your agreements with them.
4. Sharing & publicity
Pieces you publish via share links or the community gallery are public — title, view count, and the playable file. Everything else is private to your account. We disclose data only if legally compelled, and we'll tell you unless prohibited.
5. Retention & deletion
- Account data and projects: kept while your account exists.
- OTP codes and email tokens: minutes to hours (single-use, short expiry).
- Usage logs: up to 24 months, for billing disputes and abuse prevention.
- Email varundev1007@gmail.com to export or delete your data — we complete deletion within 30 days (Stripe records are retained as required by financial law).
6. Security
Transport is TLS everywhere. Database access is server-side only with row-level security enabled. Passwords are scrypt-hashed, API keys and one-time codes SHA-256-hashed, protected downloads AES-256-GCM encrypted. No system is perfect; report vulnerabilities to the email below.
7. Children
The Service is not directed at children under 13, and we don't knowingly collect their data.
8. Changes & contact
We'll announce material changes on the site or by email. Data controller and contact for all privacy matters: varundev1007@gmail.com.