Privacy Policy

Last modified: August 1, 2026

1. Overview

Raphael AI ("we," "our," or "this service") is committed to protecting your privacy. This policy explains how we collect, use, store, and protect your information when using our AI image generation service. Our design philosophy is privacy-first — we minimize data collection and ensure you have full control over your information.

2. Information We Collect

Image generation requires Google sign-in. We store your Google ID, name, email, and profile picture so we can maintain your account, welcome credit, purchased credit balance, and usage history. Text prompts are processed during generation and are not permanently stored by Raphael AI. When you use an image-to-image feature such as AI ID Photo, your uploaded source photo is stored in Cloudflare R2 and made available to KIE.AI for the requested generation. We also collect anonymized technical data such as browser type and page views for service improvement.

3. Information We Do NOT Collect

We do not collect: phone numbers, physical addresses, payment card details (handled by our payment processor Creem), GPS location data, contacts or address books, or browsing history outside our site. We do not create biometric templates, perform face recognition, or use uploaded portraits to identify people. Generated images are delivered directly to your browser and are not added to your account history.

4. How We Use Your Information

Account information (Google ID, email, name) is used solely to: authenticate your identity, manage your balance, process payments, and display your usage history. Technical logs are used for: maintaining service stability, preventing abuse, and improving performance. We never sell, rent, or share your personal information with third parties for marketing purposes.

5. Payment Processing

Payments are processed by Creem (creem.io), a licensed Merchant of Record. We never see or store your credit card details. Creem handles all payment data in compliance with PCI DSS standards. We only receive confirmation of successful payments along with the transaction amount.

6. Data Storage & Retention

User account data is stored in Supabase (PostgreSQL) with encryption at rest. Uploaded reference photos are stored in Cloudflare R2 for provider access during generation. KIE.AI may temporarily retain submitted and generated media according to its own service policy. Auth tokens are stored as httpOnly cookies with 30-day expiration. Usage logs are retained for your reference in the Dashboard but do not include the uploaded photo URL or generated image. If you request account deletion, associated account data will be removed within 30 days.

7. Third-Party Services

We use the following third-party services: Google OAuth (authentication), Supabase (database), Cloudflare (CDN, DNS, bot protection and uploaded-media storage), Creem (payment processing), KIE.AI (image and video generation APIs), and Google AdSense on eligible public pages after cookie consent. Uploaded reference photos, prompts, and generation settings are shared with KIE.AI only to fulfill the generation request. Each provider has its own privacy policy. We do not sell uploaded photos or use them to train our own models.

8. Cookies

Necessary storage includes an httpOnly auth-token cookie for login and local storage for language and consent preferences. If you accept optional cookies, Raphael AI creates pseudonymous first-party analytics and session identifiers and records page and conversion events in Supabase. Google AdSense may also use cookies or similar technologies on eligible public pages to deliver and measure ads. If you choose “necessary cookies only,” optional analytics events and AdSense are not loaded. Cloudflare Turnstile may use temporary data for bot verification.

9. Your Rights

You have the right to: access your personal data (visible in Dashboard), request correction of inaccurate data, request deletion of your account and all associated data, export your usage history, and withdraw consent for data processing at any time by signing out and contacting us. For GDPR, CCPA, or other privacy regulation requests, email us at raphaelai@zohomail.cn.

10. Children's Privacy

Raphael AI is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last modified" date. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions or requests, contact us at raphaelai@zohomail.cn. We typically respond within 48 hours.

Raphael AI privacy policy explains how we handle user data for our AI image generator platform. We are committed to transparency, minimal data collection, and user control. This policy covers uploaded reference photos, cookie usage, third-party services, payment processing, GDPR and CCPA compliance, and your rights as a user. Raphael AI does not sell personal data or use prompts and uploaded photos to train its own models.