Owner review draft
Privacy
This draft explains the intended privacy posture for AI Print Ready Files before final legal review. It is not legal advice and should be reviewed before public launch.
What we collect
We collect account information such as your name, email address, authentication records, plan, credit balance, and billing status. We also collect product-use records that let the service run: uploaded file metadata, preflight reports, prep jobs, export history, download records, and support messages.
When you upload artwork, we process the file so we can check print readiness, generate reports, prepare exports, and let you download the result. We do not use customer artwork to train our own public model. Any external AI operation and its processor terms must be disclosed and approved before public launch.
Uploaded files
Uploaded files are used to provide the service you requested: preflight, quoting, file preparation, vector suitability checks, export generation, storage, and download. Files may include images, PDFs, vector artwork, source dimensions, file names, generated reports, and related job status.
The current product windows are 7 days for Free, 30 days for one-off packs and Starter, 90 days for Pro, and 365 days for Print Shop. When a file expires or is deleted, we remove access through the product and purge stored bytes on the retention schedule, subject to limited backups and records required for billing, security, or dispute handling.
Payments and billing
Payments are processed through Stripe. We do not store full payment card numbers on our servers. We store records needed to connect your account to purchases, subscriptions, invoices, credit grants, plan changes, refunds, and billing support.
If you use a paid plan, Stripe and our systems may record checkout events, invoice status, plan tier, renewal dates, failed-payment status, and credit-ledger entries. Those records are used to provide access, prevent duplicate credit grants, and resolve billing questions.
How we use information
We use information to operate the product, prepare files, show reports, process downloads, manage credits, prevent abuse, troubleshoot errors, improve reliability, respond to support requests, and understand high-level product performance.
We may use aggregated or de-identified operational data to improve preflight quality and understand common file problems. We should not publish a customer file, customer artwork, or identifiable report as a case study without permission.
Service providers
The intended production stack uses Google Cloud for hosting, database, private storage, secrets, and operational monitoring; Stripe for payments; Postmark for transactional email; and optional Google sign-in and Google Analytics. A private malware scanner receives each upload before storage. These providers should receive only the information needed for their role.
Standard preflight and PDF preparation do not require sending artwork to an external AI processor. Artwork pixels are sent to one only when you choose an AI operation such as upscale, vectorize, or generative bleed. The final processor terms, retention, training, and regional handling must be reviewed before launch.
We may share information if required to comply with law, protect the service, investigate abuse, enforce terms, or respond to a valid legal request. We do not sell uploaded artwork.
Security
We use practical security controls such as authenticated accounts, rate limits, malware scanning before storage, protected downloads, tenant-scoped access, and separation between billing records and file processing. No online service can promise perfect security, so users should avoid uploading files they are not comfortable processing through an online tool.
If we learn about a security issue that affects user data, the owner-review version of this policy should define the notification process and timing before public launch.
Your choices
You can choose not to upload a file, delete available files where the product allows, stop using paid features, or contact support about account and billing records. Some records may need to be retained for security, compliance, accounting, dispute resolution, or service integrity.
If privacy rights apply in your location, the final legal policy should explain how to request access, correction, deletion, portability, or opt-out rights. This draft flags that requirement for owner and counsel review.
Contact
Privacy requests should route through the contact address published on the site. Before launch, the owner should add the final legal entity, mailing address, and privacy contact.
