Privacy Policy
Version 1.2 · Last updated August 2, 2026 · Controller: Electric Wonder LLC, a New York limited liability company, doing business as FriedAI · Contact: support@fried.ai · Mailing address: 418 Broadway, Ste N, Albany, NY 12207
1. Scope
This policy explains how fried.ai handles personal information when you use our website and service (the “Service”). The Service is offered to and directed at residents of the United States. It is not currently offered in the European Union, the United Kingdom, or Quebec, and we do not target or market it to residents of those regions. If we make the Service available in those regions in the future, we will update this policy and put the required protections and representatives in place before serving those users. Where the law of your U.S. state gives you stronger rights than described here, you have those rights. This policy is part of our Terms of Service.
2. What we collect (and what we deliberately don’t)
What we collect
Email address
From you. For account sign-in (magic links), receipts, service messages, and your consent records.
Artist name (chosen by you)
From you. Displayed on your covers; not required to be your real name.
Uploaded photo (your face)
From you. Sole purpose: generating your covers. Deleted within 72 hours of upload (Section 5).
Temporary appearance description
Machine-generated by our pipeline during rendering. Used only to build your covers; deleted on the same schedule as the photo (Section 5).
Your Renders (finished covers)
Created for you. Stored in your account until you delete them. If you create a share link, anyone holding that link can view that cover until you archive or delete the cover, until you delete your account, or until we switch the link off after a report or a safety review.
Share links you create
Generated when you choose to share a cover. We store the link’s random token, which cover it points to, when it was created, whether it is still active, and a plain count of how many times the page has been opened. That count is a number only: it holds nothing about who opened the page.
How you found us, when you arrive through a link someone shared
Automatic. A shared link carries a short code, and if you go on to create an account we store that code with it, so we can tell which shared link brought you. It tells us nothing about you personally, and we never use it for advertising.
Age answer (18+ confirmation only)
From you. Legal eligibility. If you select an under-18 range, we block access and keep only a marker that prevents re-entry (Section 9).
Order and render history
Generated by use. Receipts, credit balance, service delivery, tax records.
Consent records
Generated at acceptance: document versions, the exact consent text you saw, timestamp, IP address, browser info. Proof of your agreement and consents.
Technical basics
Automatic: IP address, browser type, security logs, essential cookies. For security, fraud and abuse prevention, and service operation.
Reports and complaints (including takedown requests)
From you, or a third party who reports content. When someone submits a report, takedown request, or other complaint (for example at fried.ai/takedown), we collect the name and contact details they give, the content of the report, and their IP address, to review and act on it, keep a record, and meet our legal obligations.
Artist-type quiz (optional)
From you, if you take the optional quiz. The answers you tap, and the music archetype and suit we derive from them, used to show you your result and personalize your experience. Not required to use the Service, and never used for any face, identity, or advertising purpose.
What we deliberately do not collect
Your legal name (our payment processor handles any billing details at checkout; we don’t store card numbers), physical address, phone number, government ID, precise location, contacts, or any data from data brokers. We do not track you across other websites or apps, and we use no advertising trackers.
3. The face photo: our biometric-grade commitments
We treat your uploaded photo with the highest level of care the law recognizes for face data, everywhere, regardless of where you live.
Purpose (specific and only): your photo, and a temporary machine-generated description of your appearance derived from it, are collected, stored, and used solely to generate the album-cover artwork you request and to run the safety checks described in Section 4. No other use. Ever.
No facial recognition or identification: we do not use your photo to identify or verify who you are, we do not create face-recognition templates, we do not match your face against biometric databases, and we do not enable anyone else to. (Our automated safety checks flag content categories, for example whether an upload appears to show a minor or a widely recognized public figure, without creating recognition templates or establishing anyone’s identity; see Section 4.)
No training: we do not use your photos, appearance descriptions, or Renders to train AI models, and our AI provider is contractually restricted from doing so (Section 6).
No sale, no sharing, no publication: we do not sell, lease, trade, or disclose your photo or any biometric-type data to anyone except the processors in Section 6 acting under contract on our instructions, or where the law compels disclosure. We never publish it.
Consent first: we ask for your express written consent (electronic) before your photo is collected, at the moment you upload, after telling you the specific purpose and how long the data is kept. You can decline; the Service simply won’t run without a photo.
Retention and destruction (our posted schedule): see Section 5, which is our public retention and destruction schedule for biometric-type data.
4. How we use information
We use personal information to: (a) provide the Service (generate Renders, deliver them, sign you in, maintain your library and order history, and serve any share link you choose to create); (b) run safety screening on uploads and generated text (automated checks that flag content categories: child-safety violations, uploads that appear to show someone other than you or a widely recognized public figure, and content that breaks our rules; these checks do not create face-recognition templates or determine anyone’s identity); (c) process payments and keep legally required transaction records; (d) secure the Service against fraud and abuse (rate limits, CAPTCHA, suppression lists); (e) send service messages (render-ready emails, receipts, security and legal notices); and (f) comply with law.
We do not use your information for third-party advertising, cross-context behavioral advertising, profiling with legal effects, or automated decisions about you other than the content-safety checks described above (which you can contest via support@fried.ai).
Marketing email, if we ever send any, will be opt-in and will have a working unsubscribe link. We do not send marketing email today.
5. Retention and destruction schedule (public)
This section is our public Biometric Data Retention and Destruction Schedule (the document referenced in our footer and the Terms) and also covers every other category of data we hold. It applies regardless of where you live.
Uploaded photo
Retained at most 72 hours from upload, whether or not a render completes, then permanently deleted from our systems. To make your covers we send your photo to our AI provider; it is not used to train models and is kept by them only briefly for abuse monitoring before deletion (see Section 6). The photo file is kept separately from our database, so it is never written to our database backups.
Temporary appearance description
Same as the photo. Permanently deleted on the same schedule. It is brief text, never an image; if a database backup taken before deletion still holds a copy, that copy contains no photo and ages out of our backup window on its own.
Renders (your covers)
Until you delete them or your account. Deleted within 30 days of your deletion request.
Share links (token, the cover it points to, timestamps, anonymous view count)
Kept while the link is active. Once a link stops working, we keep the switched-off record for up to 12 months, so that address stays dead and so we can answer questions about a link that was reported, then we delete it. Archiving a cover switches its links off; deleting the cover or your account switches them off immediately and their records are deleted with the cover, within 30 days of your deletion request. The narrow exception is a link tied to a safety or legal matter, which follows the safety-screening entry below.
How you found us (the code carried by a shared link)
Life of account. Deleted within 30 days of account deletion.
Account data (email, artist name, render history, age answer)
Life of account. Deleted within 30 days of account deletion.
Artist-type quiz answers and derived result (archetype and suit)
Life of account. Deleted within 30 days of account deletion.
Order and transaction records
As required by tax and accounting law (typically 7 years). Retained in minimized form after account deletion, then deleted.
Consent records
Life of account plus 6 years. Then deleted.
Suppression markers
Blocked under-18 attempts; hashed email of deleted accounts to prevent re-use abuse; bounced or complained addresses; opt-outs. Kept as long as needed for the protective purpose, then deleted.
Safety-screening and abuse-report evidence
A copy of a specific upload or cover that our screening blocked or that was reported for a safety violation, plus the screening verdict. Kept as long as the law requires or a review or legal need exists. This is the narrow, legally required exception to the 72-hour rule; it never applies to ordinary uploads. Apparent CSAM is preserved and reported to NCMEC when we become aware of it, as the law requires.
Security logs
Up to 12 months, then deleted or de-identified. After that we strip the IP address and device information from older records. Logs we must keep as evidence of a safety or legal matter are retained separately for as long as the law requires.
The 72-hour outer bound is a hard ceiling that runs from upload; it applies whether your render completes, fails, or is abandoned. If you change your photo, the prior photo and its derived description are deleted on the same schedule. Your uploaded photo is kept as a file separate from our database, so it is never part of a database backup. The appearance description is brief text held in our database; a backup taken before its deletion may retain that copy until the backup ages out of our retention window, and it is never restored into the live Service. Backups of other data purge on a rolling basis within 30 days. The only exception to the 72-hour rule is the safety-evidence entry above: if a specific upload is blocked by safety screening or reported for a safety violation, the law requires us to preserve that copy. Ordinary uploads are never affected.
For Illinois residents: this section is the written policy and retention and destruction schedule referenced by 740 ILCS 14/15(a). Destruction occurs when the initial purpose is satisfied, always well within the statute’s outer limits.
6. Who processes data for us (processors)
We share personal information only with service providers acting under contract on our instructions:
OpenAI (AI image generation and safety screening)
Processes your photo and appearance description to generate Renders and run automated safety checks. OpenAI does not use your content to train its models, and retains it only transiently to process the request and for a limited period for abuse monitoring, after which it is deleted.
Trigger.dev (render-pipeline compute)
Runs the background worker that orchestrates rendering; your photo and appearance description pass through it during a render only.
Payment processor (payment processing)
When you buy credits, our payment processor receives your payment details directly, so we never see or store full card numbers.
Supabase (database and storage)
Hosts account data, Renders, and (temporarily) uploads.
Vercel (web hosting)
Serves the website.
Resend (transactional email)
Delivers magic links, receipts, and render notifications; bounce and complaint signals feed our suppression list.
Cloudflare Turnstile (abuse prevention)
Bot detection on the create flow.
We may also disclose information if required by law (we review demands and narrow them where we can), to protect people’s safety (Section 4(b), including legally required CSAM reporting to NCMEC), or in a merger or acquisition (with notice and the same protections). We have never sold personal information and we never will.
7. Where we operate and where data is processed
We are a U.S. company and we process data in the United States. The Service is intended for users in the United States, and our data practices are built around U.S. federal and state law.
If you are located outside the United States: the Service is not directed to you, and the personal information you provide will be processed in the United States, where privacy laws may differ from those in your country. We do not currently offer the Service in the European Union, the United Kingdom, or Quebec. If we make it available in those regions in the future, we will provide the additional disclosures those laws require and appoint any required local representative before serving those users.
Whatever your location, we apply the biometric-grade protections in Sections 3 and 5 to your uploaded photo, and the rights and controls in Section 8 are available to everyone.
8. Your rights and controls
Available to everyone, everywhere, in Settings → History and Data:
Download my data: a self-service export of your covers plus a machine-readable file of your account data, artist name, order history, and render history.
Delete my account: we permanently delete your account data from our systems, on the schedule in Section 5. Any copies held by our processors or in routine backups age out on their standard retention cycles. We confirm completion by email. A hashed suppression marker may be kept to honor the deletion and prevent abuse.
Delete individual covers, change your photo (the prior photo is deleted per Section 5), and correct your email or artist name, all self-service.
Withdraw consent: deleting your photo or account, or simply not uploading, withdraws consent for future processing; withdrawal is one click, the same way consent was given.
By email (support@fried.ai): access, correction, deletion, portability, restriction, or objection requests; consent withdrawal; questions; complaints; or an appeal if we decline a request (we explain why and how to appeal; you may also contact your state Attorney General). We verify requests against your account email, respond within the time your state law requires (typically 45 days), and never discriminate against you for exercising rights.
What the export includes and what it doesn’t: the export covers data you provided and your account records. Internal system data that is not personal to you (our prompt engineering, model configurations, aggregate analytics) is not included; the temporary appearance description is deleted on the Section 5 schedule and therefore may no longer exist to export in the ordinary course.
State-specific notes (US). California (CCPA/CPRA): we do not “sell” or “share” personal information as defined by the CCPA and have not in the preceding 12 months; we honor the Global Privacy Control browser signal (since we don’t sell or share, there is nothing further to opt out of); categories collected are listed in Section 2 (identifiers; audio/visual, your photo; commercial information, orders; internet activity, security logs); you have the rights to know, delete, correct, and port, without discrimination. We do not use or disclose sensitive personal information except to provide the Service you request. Washington residents: see also our Washington Consumer Health Data Privacy Notice regarding biometric-type data, which for the purposes of Washington’s My Health My Data Act is consumer health data; our practices are as stated in Sections 3 and 5, and we collect face data only with your consent and only as necessary to provide the Service you request. Illinois residents: see Sections 3 and 5 (BIPA notice, consent, retention and destruction schedule; no sale, no profit from biometric data).
9. Children
The Service is for adults 18+. We do not knowingly collect personal information from anyone under 18 (and certainly not under 13). Our age screen blocks under-18 answers before any email or photo is collected; the only thing kept is a marker in your browser that prevents re-entry, used solely to keep the Service adults-only. If you believe a minor has used the Service, contact support@fried.ai; we will delete the account and data promptly on verification.
10. Security
We use encryption in transit and at rest, access controls, secrets management, and least-privilege infrastructure. Uploads live in non-public storage and are purged on the Section 5 schedule; the best protection for face data is not keeping it. No system is perfectly secure; if a breach affects your personal information, we will notify you and regulators as the law requires, promptly and without games.
11. Cookies
We use only cookies and similar technologies that are strictly necessary: session and sign-in, security and anti-fraud (including CAPTCHA), the age-gate marker, and remembering settings. No advertising or cross-site tracking cookies. Because we use only strictly necessary cookies, no cookie-consent banner is required; if we ever add non-essential cookies, we will ask first. Share pages set no cookies at all (Section 12).
12. If you open a link someone shared with you
You do not need an account to look at a cover someone shared with you, and we do not treat you as a user of the Service for opening one. On a share page we set no cookies, run no analytics, and build no profile of you. We do not know who you are, we do not try to find out, and nothing you do there follows you anywhere else. There are no advertising or tracking technologies on those pages, and nothing about a visit is sold or shared for anyone else’s purposes.
The only thing we count is how many times a link has been opened, as a plain number that carries nothing about the person opening it. The ordinary exception every website has still applies: our hosting and security infrastructure keeps short-lived technical logs of requests so the site stays up and protected from abuse, held as described under “Security logs” in Section 5. We add nothing of our own on top of them. If something on a share page concerns you, you can report it at fried.ai/takedown without an account, and we will review it promptly.
13. Changes to this policy
We will post changes here with a new version number and effective date, and for material changes we will notify you by email and/or in-Service notice at least 30 days in advance. We will never apply a material change to previously collected photos or biometric-type data without asking for your fresh consent. Prior versions are available on request.
14. Contact
Electric Wonder LLC d/b/a FriedAI · support@fried.ai · 418 Broadway, Ste N, Albany, NY 12207