Privacy

Studio is a private photo editor. Files stay on our servers for a short time. We do not sell your photos.

What we keep, and for how long

Uploads land in a private inbox that is not on the public website. Work files used while an edit runs are deleted after about 24 hours. Finished outputs are kept about 7 days, then deleted. After that, the download path on the job is cleared. Quarantined policy files are deleted after a review decision or 14 days. We keep job metadata (prompt, timestamps, token counts, file hashes when a policy check ran) so billing and safety review still work after the pixels are gone.

How files are accessed

Inbox, outputs, and quarantine directories are not web-accessible. There is no public URL into /opt/photo-ai. You download through Studio after signing in: /studio/jobs/{id}/download. That route checks your session and that you own the job (administrators may also access a file for support or safety review). Optional download links can carry a 10-minute signed token. Unique filenames are used so “Save as” does not keep offering final.png.

Processing

Edits run on our servers. Open-source tools (not Grok) change pixels. Grok only plans a JSON recipe. For that plan it receives a JPEG preview with a long edge of at most 1024 pixels, never upscaled. The engine still edits the original file. We do not use client-only or zero-knowledge encryption: the engine must read plaintext while tools run. Finished output images are encrypted at rest with a server master key (not your password). Login still verifies Argon2id password hashes only.

AI and policy

Grok sees the 1024px preview and your prompt in order to plan the recipe and to run a safety check. Sexual content, nudity, and anything involving minors is not allowed. Adult policy uses strikes; a separate path handles suspected minor sexual content for administrator review only.

Start free · Sign in · Pricing · Terms

Home · Pricing · Privacy · Terms

Please confirm

Continue?