LEGAL
Privacy Policy
This policy explains what FindImagePrompt collects when you use our prompt and image tools, why we collect it, who else can see it, and how you can ask us to change or delete it.
The short version
We keep as little as we can. The images and text you send to our tools are processed to produce your result and are not saved to our database. We do not sell personal information, and we do not use your content to train our own models.
- Account data. If you sign in with Google we store your email address, display name, profile picture URL and Google account identifier, plus your plan and credit balance.
- Tool content. Images and text you submit are sent to our AI provider to generate your result and returned to your browser. We keep no copy.
- Operational data. We record request metadata — which tool ran, how many credits it cost, how long it took, whether it succeeded, and a coarse network location — so we can run, bill and protect the service.
- Advertising. Parts of the site are supported by advertising. Advertising partners, including Google, may set cookies to measure and personalise the ads you see.
- Your control. You can request access to or deletion of your account data at any time by emailing us.
Who this policy covers
FindImagePrompt ("FindImagePrompt", "we", "us") operates the website at findimageprompt.com and the four tools available on it: Image to Prompt, Text to Prompt, AI Image Describer and AI Image Generator. This policy applies to everyone who visits the site, whether or not they create an account, and to every message sent to us through the contact form.
It does not cover third-party websites you reach from our pages, or the image-generation services where you later use a prompt we helped you write. Those services have their own privacy policies, and we encourage you to read them.
If you do not agree with this policy, please do not use the service. Continuing to use FindImagePrompt after a change to this policy means you accept the updated version.
Information we collect
Information you give us
- Account details. We use Google Sign-In. When you sign in, Google shares your email address, display name, profile picture URL and a unique account identifier with us. We never receive your Google password.
- Content you submit to the tools. Reference images you upload or link to, the ideas and descriptions you type, and the options you choose, such as output format, language and target model.
- Messages. If you use the contact form or email us, we keep the name, email address and message you provide so we can reply and follow up.
Information collected automatically
- Request metadata. For each tool request we store which tool was used, the credits charged, how long the request took, whether it succeeded or was blocked, an error code if one applies, your plan, and a request identifier you can quote to support.
- Coarse network signals. We record the country and network operator (ASN) a request came from, and whether it originated from a data-centre network. Your IP address is used in transit for rate limiting and abuse checks; the only IP address we store long term is the one recorded when an account is first created.
- Anti-abuse signals. If you use a tool without signing in, we count your daily usage against a short-lived, non-identifying key so free access cannot be drained by automated traffic. We may also ask your browser to complete a Cloudflare Turnstile check.
- Session information. A signed-in session is represented by a random token in a cookie. Our database stores only a SHA-256 hash of that token, its expiry and when it was last seen.
- Analytics and advertising. Standard web measurement data such as pages viewed, referring page, approximate location, device type and browser. See Advertising and analytics.
We do not ask for and do not want special categories of data — health, biometric identifiers, political opinions, precise location or government identification numbers. Please do not submit them to our tools.
Your images, prompts and results
This is the part people ask about most, so we want to be precise.
When you run a tool, the image or text you provide is transmitted over an encrypted connection to our server, forwarded to our AI provider for processing, and the generated prompt, description or image is returned to your browser. We do not write your uploads, your inputs or your generated results into our database, and we do not place them in long-term file storage. Once the request finishes, our copy is gone.
Our AI processing is performed by the Google Gemini API. Google processes that content under its own terms as a processor for the API, and applies its own retention and abuse-monitoring practices to API traffic. If a reference image comes from a URL you paste, our server fetches that URL to read the image; the site hosting it will see that request.
We do not use your images, prompts or results to train our own models, and we do not publish, share or sell them. Anything you keep from a session is the copy you download or copy from your own screen.
How we use information
- To provide the service. Run the tool you asked for, return the result, and show your history of credits within your account.
- To manage accounts and credits. Maintain your balance, apply weekly or monthly refills, record the sign-up bonus, and refund credits automatically when a generation fails.
- To take payment. Process subscriptions, apply plan entitlements and handle billing questions and refunds.
- To keep the service available. Diagnose errors, measure latency, apply rate limits and daily spending caps, and investigate incidents using request identifiers.
- To prevent abuse and fraud. Detect automated traffic, proxy and data-centre access, quota evasion and attempts to bypass safety limits, and restrict or ban accounts that break our terms.
- To communicate. Reply to your messages, and send service notices such as billing confirmations or material changes to these policies.
- To improve the product. Understand which tools are used and where they fail, using aggregate figures rather than the content of your requests.
- To meet legal obligations. Keep financial records, respond to lawful requests and enforce our terms.
We do not sell personal information, and we do not share it for cross-context behavioural advertising in the sense given to those terms by California law.
Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — providing the tools, running your account, and taking payment for a plan you chose.
- Legitimate interests — keeping the service secure and available, preventing abuse and fraud, measuring aggregate usage, and improving the product, balanced against your rights.
- Consent — analytics and advertising cookies where consent is required, which you may withdraw at any time.
- Legal obligation — retaining transaction records and responding to lawful requests.
Advertising and analytics
FindImagePrompt is supported in part by advertising so that a free tier can stay free. We work with third-party advertising partners, including Google, and use Google Analytics 4 to measure how the site is used.
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and other sites on the internet.
- You can opt out of personalised advertising from Google in Google Ads Settings, and from many other vendors at optout.aboutads.info or optout.networkadvertising.org.
- You can prevent Google Analytics from measuring your visits with the Google Analytics opt-out add-on.
- More detail about how Google handles data from sites that use its services is available at policies.google.com/technologies/partner-sites.
Advertising is never placed inside your generated results, and advertising partners do not receive the images or text you submit to our tools.
Service providers and disclosures
We keep our supplier list deliberately short. Each provider may process information only to perform its function for us:
- Cloudflare — hosting, content delivery, database storage, and the Turnstile anti-abuse check.
- Google — Gemini API for AI processing, Google Sign-In for authentication, Google Analytics for measurement, and Google advertising services.
- Creem — our payment provider, acting as merchant of record for subscriptions. Creem collects and processes your payment details directly; we never see or store your full card number.
We may also disclose information when we believe in good faith that it is necessary to comply with a law, regulation or valid legal process; to enforce our terms; to investigate fraud or a security incident; or to protect the rights, property or safety of our users or the public. If the service is ever transferred to another owner, account information may transfer with it, and we will say so on this page before that happens.
International transfers
Our infrastructure and providers operate globally, so your information may be processed in countries other than your own, including the United States. Where information is transferred out of the European Economic Area or the United Kingdom, we rely on our providers' approved transfer mechanisms, such as the European Commission's Standard Contractual Clauses, together with the technical protections described in this policy.
How long we keep information
- Images, prompts and results — not retained. They exist only for the duration of the request.
- Request metadata — 90 days by default, then deleted automatically.
- Anonymous usage counters — three days, which is all a daily quota needs.
- Sessions — until the session expires or you sign out, after which the record is deleted.
- Account records — for as long as your account exists, and for a short period afterwards to complete deletion and settle any outstanding billing.
- Credit and transaction records — retained as a financial audit trail for as long as accounting and tax obligations require, even after an account closes.
- Contact messages — until the conversation is resolved and no longer needed for support history.
How we protect information
All traffic is served over HTTPS. Session tokens are random values stored only as hashes, so a copy of our database does not let anyone impersonate you. Administrative pages are restricted to a fixed list of addresses. Payment card details never reach our servers. Automated abuse controls, rate limits and daily spending caps reduce the damage any single compromised account can do.
No online service can promise perfect security. If we ever become aware of a breach affecting your personal information, we will notify you and any required regulator as the law directs.
Your privacy rights
Whoever and wherever you are, you can email us to ask what personal information we hold about your account, to correct it, or to have it deleted. We will respond within 30 days, and we may need to verify that you control the email address on the account before we act.
If you are in the EEA or the UK
You have the right to access your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to receive your data in a portable format; and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your local supervisory authority.
If you are in California
You have the right to know what personal information we collect, use and disclose; to request deletion; to request correction; to opt out of the sale or sharing of personal information; and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA and CPRA, so there is nothing for you to opt out of.
Other choices
You can sign out to end a session, use the tools without an account within the free anonymous limits, adjust cookies in your browser, and use the advertising opt-outs listed above. We honour Global Privacy Control signals where the law requires it.
Children's privacy
FindImagePrompt is not directed to children. You must be at least 13 years old to use the service, and at least 16 if you are in a country where that is the minimum age for consenting to online services. We do not knowingly collect personal information from children below those ages. If you believe a child has provided us with personal information, email us and we will delete the account and its data.
Changes to this policy
We update this policy when the service changes or the law requires it. The effective date at the top always reflects the current version. If a change materially affects how we handle your personal information, we will give notice on the site, and by email where we hold your address, before it takes effect.
How to contact us
Questions, access requests and deletion requests all go to the same place, and a person reads every one.
Email: support@findimageprompt.com
Or use the contact form. Please write "Privacy" in your message so we can route it quickly.