This policy explains what personal data ImageLab collects, why, who processes it, how long we keep it, and your rights. ImageLab is run by Simplefield ("we", "us"), which is responsible for your data (the "controller"). Contact us at hello@simplefield.ai.
1. In short
- We collect only what we need to run ImageLab: your email address, your password (stored only as a hash), your OpenAI key (encrypted), your content, and some technical data for security.
- When you make an image, your prompt and images go to OpenAI on your own OpenAI account.
- We don't show ads, use analytics or tracking cookies, or sell your data. We don't use your content to train AI models.
- We store your data in the EU.
- You can export or delete all your data yourself on your Account page.
2. What we collect
| Type | What it includes |
|---|---|
| Account | Your email address; your password, stored only as a one-way hash; whether your email is verified; when you joined; the invite you used, if any |
| Consent | Which version of the Terms and this policy you accepted, and when |
| OpenAI key | Your key, stored encrypted. We show only its last 4 characters. We also record whether the last key check passed. |
| Your content | Briefs, prompts, ad copy, notes, tags, collections and presets; brand kits (names, colors, fonts, style and tone notes); uploaded images, logos and masks; generated images and ad sets |
| Usage and spend | For each generation: the model, settings, placement, status, any error, the estimated and actual cost, the usage OpenAI reports, OpenAI's request ID, and timings. Also your optional monthly limit, the storage you use, and when you were last active. |
| Security | The IP address and browser type for each sign-in session; IP addresses in rate-limit counters; error and security logs |
| Account status | Whether your account is suspended, and why |
| Messages | Anything you send us, such as an abuse report or a privacy request |
We don't collect payment details, because ImageLab has no payments. We don't ask for your name, address or phone number. Please don't put sensitive personal data, such as health information, into prompts or uploads.
3. Why we use it
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Run your account and ImageLab | Account, key, content, usage | Performing our contract with you (Art. 6(1)(b)) |
| Make and edit images with OpenAI on your key | Content, key | Performing our contract with you |
| Send account emails: verification, password reset, invites, deletion confirmation and important service notices | Email address | Performing our contract with you |
| Show your spend and apply your monthly limit | Usage and spend | Performing our contract with you |
| Keep ImageLab secure: stop bots, apply rate limits, prevent abuse, handle reports, suspend accounts | Security data, account; content only when a report or a security problem requires it | Our legitimate interest in protecting users and the service (Art. 6(1)(f)) |
| Back up data so it can be restored | All of the above | Our legitimate interest in not losing your data |
| Record which Terms you accepted, and meet legal duties | Consent, and what the law requires | Legal obligation (Art. 6(1)(c)) and legitimate interest |
We don't use your data for advertising or profiling, and we make no automated decisions about you that have legal or similar effects. We don't send marketing emails.
4. OpenAI and your key
When you save a key, we send OpenAI a small test request to check that it works. When you run a generation or an edit, we send OpenAI your prompt, any brand kit details you include, and any reference images, logos and masks, using your key. OpenAI sends back the images and usage data.
These requests are made on your own OpenAI account. OpenAI handles that data under your agreement with OpenAI and OpenAI's privacy policy, not this policy. You can review data settings, such as retention and sharing, in your OpenAI account. We don't send OpenAI your email address or other account details.
5. Who processes your data
We use these providers to run ImageLab:
| Provider | What they do for us | Data | Where |
|---|---|---|---|
| Hetzner Online GmbH | Runs the server that hosts ImageLab and its database | Everything in section 2 | EU |
| Cloudflare, Inc. | R2 stores images, uploads and encrypted database backups. Turnstile runs the bot check at sign-up. | Images and uploads; encrypted backups; for Turnstile, your IP address and browser signals | R2: EU. Turnstile: Cloudflare's global network |
| Resend | Sends account emails | Email address, email content, delivery status | EU (Ireland) sending region; Resend is based in the US |
| OpenAI | Makes and edits images on your own OpenAI account (section 4) | Prompts, brand kit details, reference images, logos, masks | US, under your agreement with OpenAI |
Hetzner, Cloudflare and Resend process data only on our instructions, under data processing agreements.
We may also share data when the law requires it, or to protect the rights and safety of users or others. If ImageLab moves to a new operator, we'll tell you before your data is transferred.
6. Transfers outside the EU
We store your data in the EU: the server at Hetzner, images and backups in Cloudflare R2's EU jurisdiction, and email sent from Resend's EU region. Cloudflare and Resend are US companies, so some data may be processed outside the EU, for example Turnstile checks and provider support access. Requests to OpenAI go to the US under your own OpenAI account. When data leaves the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified under it, or otherwise on the EU's Standard Contractual Clauses.
7. How long we keep data
| Data | How long |
|---|---|
| Account, consent record and settings | Until you delete your account |
| Your content and generation records | Until you delete them, or your account |
| OpenAI key | Until you remove or replace it, or delete your account. It's deleted immediately. |
| Sign-in sessions, with IP address and browser | A session lasts up to 7 days. We delete session records within 30 days after they end. |
| Rate-limit counters, with IP address | Deleted within 24 hours |
| Email verification, password reset and invite links | They expire after 24 hours, 60 minutes and 7 days |
| Data exports | Deleted 24 hours after they're created |
| Error and security logs | Up to 30 days |
| Database backups (encrypted) | Up to 14 days. Anything you delete leaves our backups within 14 days. |
| Abuse reports and the action we took | Up to 12 months after the case is closed |
When you delete your account, we remove your account, content, images, key, sessions and exports straight away, apart from the encrypted backups above. We then send you a confirmation email. Resend keeps its email delivery logs for a limited time under its own retention settings.
8. Your rights
Under the GDPR and similar laws, you can:
- access your data, and take it with you: on your Account page, export everything as a ZIP of your records (JSON) and your original images;
- delete your account and data: on your Account page, after re-entering your password;
- correct your data: edit your content in the app, or ask us to change your email address;
- object to processing based on our legitimate interests, and ask us to restrict processing;
- complain to the data protection authority where you live or work.
For anything you can't do in the app, email hello@simplefield.ai from the address on your account. We reply within one month.
9. Cookies
ImageLab uses only the cookies needed to keep you signed in. They're secure and HTTP-only, and they expire after 7 days. We don't use analytics, advertising or tracking cookies, and there are no third-party trackers. On the sign-up page, Cloudflare Turnstile checks technical signals from your browser to tell people from bots.
10. Security
- All traffic uses HTTPS.
- Passwords are stored only as hashes.
- OpenAI keys are encrypted (AES-256-GCM). The encryption key exists only on the server. Keys are never logged or sent back to your browser, apart from the last 4 characters.
- Each user's data is kept separate. Automated tests on every route check that no user can reach another user's data.
- Images are private. Only you can open them, after you sign in.
- Backups are encrypted and stored away from the server.
- Only the operator can use the admin tools.
No system is perfectly secure. If a breach affects your data, we'll tell you and the authorities as the law requires.
11. Children
ImageLab isn't for anyone under 18. If we learn that a child has an account, we'll delete it.
12. Changes to this policy
When we update this policy, we change its date and version. For significant changes, we'll email you or show a notice in the app at least 14 days before they take effect.
13. Contact
Simplefield. For privacy requests and abuse reports, email hello@simplefield.ai.