Privacy Policy
Effective July 18, 2026 · Contact: support@robotcamouflage.com
The short version
Your emoji, your projects, and your prompt history live in your own browser — not on our servers. We keep the minimum needed to run accounts and credits: who you are (name + email from Google), what your credit balance is, and bare-bones records of each generation without the prompt text. We don’t sell data. We don’t run ad trackers.
What we store (on our servers)
- Account: your name and email from Google sign-in, plus session records (which include your IP address and browser user-agent — standard for login security).
- Credits: your balance and an append-only ledger of every grant, purchase, spend, and refund. This is a financial record.
- Generation records: for each generation, an ID, which tier, the credit cost, and whether it succeeded, failed, or was blocked. No prompt text and no images are stored in our database.
- Payment records: Stripe event IDs and checkout-session references. We never see or store your card number — payment details go directly to Stripe.
- Error logs:when something breaks, error reports go to Sentry and our hosting logs. These contain technical details and may incidentally include fragments of request data, but we don’t log prompt text on purpose.
What stays in your browser
Your projects, generated images, edits, and prompt history are stored in your browser’s local database (IndexedDB) on your device. We can’t read them, back them up, or recover them — clearing your browser data deletes them. We also never connect to your Slack workspace; you download a PNG and upload it yourself.
What passes through, transiently
When you generate, your prompt is sent through our server to OpenAI to create the image (and a snippet of it to suggest an emoji name). We don’t keep it after the request finishes. OpenAI processes API data under its API terms — API inputs aren’t used to train their models by default, and they may retain data briefly (typically up to ~30 days) for abuse monitoring.
Who touches data on our behalf
| Who | What for | What they see |
|---|---|---|
| Sign-in | Your Google account handles auth; we receive name + email | |
| Cloudflare | Hosting, database, network, cookieless analytics | All traffic and our database |
| OpenAI | Image generation, name suggestion | Your prompts, transiently |
| Stripe | Payments | Payment and card details (we never do) |
| Sentry | Error monitoring | Technical error reports |
Cookies and analytics
Only strictly-necessary session cookies to keep you signed in. No advertising or tracking cookies. For traffic measurement we use Cloudflare Web Analytics, which is cookieless: it counts page views and load performance without storing anything on your device or profiling you across sites. If we ever add more detailed analytics, we’ll update this policy first and note it here.
Retention and deletion
- Account and session data: kept while your account exists.
- Credit ledger and payment records: kept even after account deletion (de-identified in our database; payment-processor records at Stripe are retained per their policy) — we need them for payment disputes, refunds, and bookkeeping.
- Error logs: expire per Sentry/Cloudflare retention (typically ≤90 days).
- To delete your account: email support@robotcamouflage.com from your sign-up address. We delete your account and sessions; the de-identified ledger remains as described. Remember your images were never on our servers to begin with.
We do not sell your data
Not to anyone. Not “share for advertising purposes” either.
Children
This service isn’t directed at children under 13, and we don’t knowingly collect their data. If you believe a child under 13 has an account, email us.
Changes
We’ll post changes here with a new effective date.