The short version: we collect as little as we can, we keep your post history only when you're signed in, we never sell your data, and you can delete everything from your dashboard.
1. Who we are
Beastify operates beastify.xyz and is the controller of the personal data described here. Contact: [email protected].
2. What we collect
- Account data: your email address and a salted, hashed password (we never store your password in plain text).
- Billing data: your Stripe customer ID, subscription status and renewal dates. Card details are collected and stored by Stripe, not by us.
- Content: posts, drafts and captions you submit, and the rewrites and memes generated for you. If you are signed in, we save them to your history ("post wall") so you can see them again. If you are not signed in, we process your text to answer the request and do not keep it in our database.
- Generated media: memes are stored as files at long, unguessable URLs so you can view, download and share them. Anyone with a link can open that file.
- Usage and abuse-prevention data: a random identifier stored in your browser, a hashed (non-reversible) form of your IP address, daily usage counters, and operational logs of AI requests (model, tokens, latency, success, and a hashed identifier, but not your post text).
- Technical data: like most websites, our servers and our CDN (Cloudflare) process your IP address, browser user agent and request details to deliver and secure the site.
- API data: API key names, hashed keys and last-used dates.
- Communications: messages you send us.
We don't use advertising trackers or sell your data, and we don't currently use third-party analytics.
3. How and why we use it
- To provide the Service (analysis, rewrites, memes, history, API), to manage accounts and subscriptions, and to support you. Legal basis: performance of our contract with you.
- To keep the Service safe and fair: enforcing usage limits, preventing abuse and fraud, debugging and security. Legal basis: our legitimate interests.
- To improve the Service using aggregated, non-content metrics such as latency, error rates and costs. Legal basis: our legitimate interests.
- To comply with law, such as tax and accounting obligations. Legal basis: legal obligation.
- To email you about your account (for example password resets and important changes). We won't send marketing emails without your consent.
4. Who processes your data
We share data only with service providers that process it on our behalf under contracts, and only as needed:
- AI model provider (currently OpenAI): receives the text and captions you submit to generate results. Under its API terms, API data is not used to train its models and may be retained for a limited period (typically up to 30 days) for abuse monitoring.
- MongoDB Atlas: database hosting (accounts, history, usage counters, logs).
- Cloudflare: DNS, CDN, security, and storage of generated media (R2).
- Stripe: payments, subscriptions and invoices.
- Email provider (for example Resend), if enabled: transactional emails.
- Our hosting provider: servers that run the application.
We may also disclose data if required by law, to protect rights and safety, or as part of a merger or acquisition (with notice to you). These providers may process data outside your country, including in the United States; where required, transfers rely on safeguards such as the European Commission's Standard Contractual Clauses.
5. How long we keep it
- Account and history: until you delete items or your account.
- Daily usage counters: about 3 days.
- Operational AI request logs: up to 24 months.
- Sessions: up to 30 days of inactivity; password-reset links: 1 hour.
- Generated media files: they may stay available at their URLs after you delete a history item. Email us to have specific files removed.
- Billing records: as long as required for tax and accounting law.
7. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or California law), you may have the right to access, correct, delete, or export your data, to object to or restrict certain processing, and to withdraw consent. You can delete history items and your whole account yourself from the dashboard. For anything else, email [email protected]. We'll respond within the time the law requires and may need to verify your identity.
We do not sell or "share" personal information for cross-context behavioral advertising. You also have the right to complain to your local data-protection authority.
8. Security
We use encryption in transit (HTTPS), hashed passwords and API keys, httpOnly session cookies, access controls and reputable infrastructure providers. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
9. Children
The Service is not intended for anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We may update this policy. If changes are material, we'll notify you on the site or by email before they take effect.