Privacy
Photo privacy, explained plainly.
We collect what the staging service needs, keep customer media private, and do not sell personal information.
Launch draft · August 15, 2026. The service is live for controlled QA, but customer checkout remains closed. The operator's legal name, privacy contact, and notice address must be added before public paid launch.
What we collect
- Account information such as name, email address, authentication records, and support messages.
- Property labels, source photos, staging selections, prompts derived from those selections, generated results, and generation status.
- Transaction identifiers, purchased credits, amounts, currency, and payment status. Stripe handles card details; Stage That Room does not store full card numbers.
- Security and technical information such as timestamps, request identifiers, IP-derived logs, and error diagnostics needed to operate and protect the service.
How we use it
We use this information to authenticate accounts, store private projects, process requested staging jobs, deliver and reconcile credits, prevent abuse, troubleshoot failures, respond to support, maintain financial records, and comply with law. We do not use customer listing photos to train Stage That Room models or for advertising without separate, explicit consent.
Processors and international transfers
Supabase provides authentication, database, and private media storage; Vercel hosts the application; fal.ai and its model provider process requested images; Stripe processes payments; and Cloudflare provides domain and DNS services. These providers may process information outside your province or country under their own security, legal, and retention obligations.
Production submissions ask fal.ai not to persist request input/output payloads. The provider still receives the source image and staging instructions long enough to perform the request, and limited transient files, request metadata, security logs, or legally required records may remain under provider schedules.
Retention
- Source photos and staged results remain in private account storage until you delete them or request account deletion.
- After a verified deletion request, customer media will be removed from active systems within 30 days and from routine backups within 90 days, unless a legal hold or active dispute requires longer retention.
- Account profile data is kept while the account is active and then follows the same 30/90-day deletion schedule.
- Billing, tax, fraud, and transaction records may be retained for six years after the end of the year they relate to, or longer if law, an audit, chargeback, or dispute requires it.
- De-identified aggregate operational statistics may be retained when they can no longer reasonably identify a customer or property.
Security
Customer tables use owner-scoped access controls and media is stored in private buckets. Privileged keys stay on the server, downloads use time-limited signed links, and payment webhooks are signature-verified. No online service can promise absolute security.
Your choices
You may request access, correction, export, or deletion of your account information and media. Some transaction or security records cannot be deleted immediately when retention is legally required. A monitored privacy contact and request-verification process will be published before checkout opens.
Cookies and analytics
The current service uses essential authentication and security storage. It does not currently run behavioural advertising or third-party marketing analytics. This notice will be updated before adding non-essential tracking.