PRIVACY · v.4.21

EFFECTIVE 2026-04-30

What we log.

§01 — Data we collect

  • Account: email, hashed password, workspace name. That's it for sign-up.
  • Generations: prompts, engine choice, output URLs, Gemini scores, render duration.
  • Operational: IP, user agent, request timestamps. 30 days max retention.
  • Billing (Phase 4): last-4 of card via Stripe, never stored on our infra.

§02 — Data we do not collect

  • We do not run third-party analytics. No Google Analytics, no Meta Pixel.
  • We do not sell or share data with brokers. Period.
  • We do not train foundation models on your prompts or outputs.

§03 — Where data lives

US-east (Virginia) by default. EU customers can opt into Frankfurt mirroring on Agency tier. All data encrypted at rest with AES-256, in transit with TLS 1.3.

§04 — Custom personas & uploaded footage

Footage you upload to train custom LoRAs is encrypted, accessible only to the training pipeline, and deleted within 14 days of training completion. The resulting LoRA weights are yours to keep on Agency tier.

§05 — Your rights

§06 — Cookies

We use one (1) cookie: access_token for authenticated sessions, plus refresh_token. Both httpOnly + secure. No tracking cookies.

§07 — Contact

Privacy concerns: privacy@goragen.com.

▸ THIS IS A PHASE 2 PLACEHOLDER. PRODUCTION PRIVACY POLICY EXPANDS WITH PHASE 4 BILLING.