Policy
Privacy Policy
This policy explains how AI Image Combiner handles personal information wherever the website and service are available.
Last updated: August 4, 2026
Who we are and scope
AI Image Combiner is a brand operated by one independent individual. It provides image generation, combination, editing, account, Chat, and billing features. The operator disclosure explains the public identity used for the service. This Privacy Policy applies worldwide to personal information handled through the AI Image Combiner website and service. It does not apply to third-party websites or services that publish and control their own privacy practices.
Information collected and sources
We collect information that you provide, information created when you use the service, and information received from the providers involved in the requested feature. The categories, sources, and purposes are summarized below.
| Category | What we collect | Source | Purpose |
|---|---|---|---|
| Account and authentication | Name, email address, email verification status, profile image, account and provider identifiers, and sign-in or session information. | You, Google when you choose Google sign-in, and our authentication service. | Create and secure your account, authenticate you, associate activity with your account, and provide support. |
| Images, prompts, and outputs | Uploaded and added images, prompts, analysis suggestions, and generated or edited outputs. | You and your use of the workspace or Chat. | Upload, analyze, combine, generate, edit, display, and deliver images when you request those actions. |
| Generation and Chat records | Selected model and transport, output quality and aspect ratio, task and session status, Chat history, provider request references, errors, and Credit usage. | Your choices, active AI services, and our service operations. | Complete requests, maintain history, provide support, enforce limits, and preserve billing integrity. |
| Billing and Credits | Plan, Credit balance and transactions, subscription period, invoice and payment references, amounts, currency, refunds, and disputes. | You, Waffo Pancake, legacy Stripe records, and our billing records. | Process payments and subscriptions, issue Credits and receipts, reconcile transactions, and meet legal obligations. |
| Request, device, and security data | IP address and user-agent supplied with requests; keyed hashes derived from them for application risk checks; request identifiers, timestamps, headers, Turnstile outcomes, errors, and abuse-prevention decisions. | Your browser and network requests, and Cloudflare security services. | Operate the service, protect accounts, enforce rate limits, detect abuse, and investigate security events. |
| Cookies and local data | Authentication cookies, the aic_guest cookie, and a temporary IndexedDB workspace draft containing images, a prompt, analysis suggestions, and output settings. | Your browser and our service. | Keep you signed in, support guest use, restore recent work, and operate requested features. |
| Product events | Actions, route, selected model and output tier, source, download events, error category, subject identifier, and timestamps. | Your use of the service. | Understand feature use, improve reliability, troubleshoot problems, enforce event limits, and plan product improvements. |
| Advertising data, if enabled | Consent choices, cookies or local-storage values, web beacons, IP address, browser or device identifiers, ad interactions, and measurement data used by Google and advertising partners. | Your browser, consent choices, Google AdSense, and advertising partners. | Serve, limit, secure, personalize where permitted, and measure advertising after advertising is activated. |
How information is used
We use personal information to:
- Provide image generation, editing, Chat, account, and billing features.
- Authenticate users, maintain sessions, and deliver account communications.
- Route requested AI processing and return the resulting images or suggestions.
- Apply Credits, process purchases, and maintain transaction records.
- Detect abuse, protect the service, and investigate security incidents.
- Measure product use, troubleshoot errors, and improve reliability.
- Serve and measure advertising only after AdSense and required consent controls are configured.
- Comply with law, enforce our terms, and resolve disputes.
Cookies, local storage, and product events
First-party authentication cookies keep signed-in users authenticated. For guest use, the aic_guest cookie stores a random guest identifier for 24 hours. The application database stores a hash of that value rather than the cookie value itself. A browser workspace draft may store selected images, a prompt, analysis suggestions, and output settings in IndexedDB for up to 24 hours so the workspace can recover recent work.
Product events record limited actions and operational context such as the route, selected model or tier, downloads, and error categories. We use these events for internal analytics, reliability, and product improvement. Cloudflare Turnstile and other security services may process request and device signals to distinguish legitimate use from abuse.
AI image processing and model providers
Uploaded and generated images controlled by AI Image Combiner are stored in private Cloudflare R2 storage. Uploading an image by itself does not start AI analysis. When you expressly request analysis, generation, or editing, the necessary images, prompt, selected model, and output settings are sent through the active analysis or generation transport.
Depending on deployment configuration, a request may use our configured DMX/New API gateway, KIE, or Cloudflare REST AI services used with Cloudflare AI Gateway. Those relays may process the request directly or route it to the selected upstream model provider, including OpenAI or Google. Analysis and generation transports may be configured independently. The active relay and upstream provider may receive submitted images, prompts, output settings, request identifiers, and related technical metadata needed to complete and troubleshoot the request.
Relays and upstream model providers control their own service logs, temporary copies, retention periods, and any permitted model-improvement use under their agreements, configurations, and privacy policies. We do not promise that third-party systems delete data on our 24-hour schedule or that every provider contract prohibits all model-improvement use. Review the active provider information before submitting confidential or sensitive material.
Infrastructure and service providers
- Cloudflare provides application hosting, D1 database, private R2 object storage, Queues, Turnstile, Images, security, and optional REST AI and AI Gateway services. It processes requests, stored objects, task data, usage, cost, latency, errors, and delivery information as needed for those services. See the Cloudflare Privacy Policy.
- DMX/New API may act as the configured relay for analysis or generation and receive the request content and technical metadata necessary to call an upstream model.
- KIE may accept reference images and prompts, create and track model jobs, return result locations, and send authenticated job callbacks.
- OpenAI and Google provide upstream models when their models are selected through the active transport. See the OpenAI Privacy Policy and Google Privacy Policy.
Payments, sign-in, and email providers
- Waffo Pancake acts as merchant of record for new subscription checkouts and receives payment, tax, subscription, invoice, refund, dispute, email, and billing-address information needed for that role. See the Waffo Privacy Policy. Stripe may continue to process legacy subscriptions and their invoices, refunds, and disputes. See the Stripe Privacy Policy. AI Image Combiner does not store complete payment card numbers.
- Google sign-in is available when configured and chosen. We receive the Google account ID, name, email address, verification status, and an available profile image to sign you in and link your account. See the Google Privacy Policy.
- Resend may receive your email address and the contents of account security emails when email delivery is enabled. See the Resend Privacy Policy.
Google AdSense and consent choices
Google AdSense advertising is not activated until the required publisher, site-verification, and consent configuration is complete. If AdSense is enabled, Google and its advertising partners may place or read cookies, use local storage, web beacons, IP addresses, browser or device identifiers, and ad interaction data to serve, secure, limit, personalize where permitted, and measure ads.
Before AdSense advertising is served in the European Economic Area, the United Kingdom, Switzerland, or another region requiring consent, the site will use a Google-certified consent management platform. Required consent choices are collected before eligible ad requests, and a Privacy and cookie settings control is provided when that consent system is enabled so choices can be revisited. Choosing non-personalized ads may still allow limited cookies or identifiers for functions such as security, fraud prevention, frequency capping, and measurement.
Learn more in How Google uses information from sites or apps that use its services. Google advertising personalization can also be reviewed in Google Ads Settings.
Retention
Access through AI Image Combiner to uploaded and generated image files ends 24 hours after creation. A scheduled service task removes the corresponding objects from the Cloudflare R2 storage controlled by AI Image Combiner after expiration. The aic_guest cookie and browser workspace drafts also expire after 24 hours. These 24-hour periods do not describe or control copies and logs held by AI relays, upstream model providers, or other third-party services.
Account, generation, Chat, product event, and security records are retained according to the life of the account and as reasonably needed to provide support, investigate security or abuse, resolve disputes, and meet legal obligations. Billing records are retained as needed for tax, accounting, refund, chargeback, and other legal obligations. We do not promise a fixed retention period where no automated deletion schedule exists. A deletion request may be limited by legal exceptions or records we must keep for these purposes.
Sale, disclosure, and targeted advertising
AI Image Combiner does not sell personal information for money. We disclose information to the service providers described above so they can perform hosting, authentication, AI processing, billing, email, security, support, and—if activated—advertising functions. We do not intentionally include uploaded images or prompts in Google ad requests.
Depending on applicable law, disclosures to Google and advertising partners for personalized advertising may be described as sharing, cross-context behavioral advertising, or targeted advertising. Where a consent or opt-out right applies, the relevant advertising choice is presented before or when that processing is enabled. Advertising choices do not prevent disclosures required to provide requested non-advertising features or meet legal and security obligations.
Your privacy rights
Depending on where you live and subject to applicable law, you may have the right to know or access personal information, correct inaccurate information, request deletion, obtain a portable copy, restrict or object to certain processing, withdraw consent, opt out of certain advertising processing, receive equal service without unlawful discrimination, or appeal a decision about your request.
Submit a request to support@imagecombiner.app with Privacy Request in the subject line. We may ask for information needed to verify your identity and match the request to our records. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct identity confirmation. Legal exceptions may apply, and response and appeal periods depend on the law applicable to the request.
International processing
The operator and service providers may process information in countries other than the country where you live. Privacy protections and government access rules may differ by location. Where applicable law requires a transfer safeguard, the responsible provider or operator uses the safeguard applicable to its processing role.
Security
We use technical and organizational safeguards designed to protect personal information, including private object storage, access controls, encrypted connections, authentication protections, keyed risk hashes, and abuse monitoring. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Children
The service is intended for a general audience and is not directed to children under 13. A parent or guardian who believes a child has provided personal information may email support@imagecombiner.app with Privacy Request in the subject line to request deletion.
Changes to this policy
We may update this policy as the service, providers, advertising setup, or legal requirements change. We will revise the Last updated date and policy version when changes take effect and provide additional notice when required by law.
Contact
Questions or privacy requests can be sent to support@imagecombiner.app. Use Privacy Request in the subject line for requests to exercise privacy rights. Current policy version: 2026-08-04.