Your images are part of your account history. We store available originals and results so you can review and reuse your work. AI providers process the inputs needed for your selected task. You can delete completed or failed runs from History, or contact us about your account data.
1. Who we are and what this policy covers
BUAI LLC operates All Image AI at allimageai.com. This policy applies to this product, including its image generation, photo editing, image understanding, account, history and billing features. It is separate from the privacy policy for our company website.
BUAI LLC is responsible for the personal information we process to operate All Image AI. Contact us at contact@buai.dev with privacy questions or requests.
2. Information we collect
- Account information
- When you sign in with Google, we receive your Google account identifier, verified email address, display name and profile image, when available. We keep account status, sign-in records, preferences and credit balances. We do not receive your Google password.
- Images, prompts and results
- We process uploaded images and filenames, text prompts, selected tools and models, generation settings, output images, text answers, thumbnails and run status. Photos and extracted text may contain personal information about you or other people.
- Payments and credits
- Stripe processes payment details. We receive billing identifiers, purchase amounts, currency, payment and subscription status, and refund or dispute information. We keep a credit transaction history. Full card numbers and security codes are handled by Stripe and are not stored in the All Image AI application database.
- Usage and security information
- Our hosting and analytics providers may process IP addresses, browser and device information, page URLs, referral information, timestamps and interaction events. We also keep error, performance, moderation and administrative records. The application uses a salted hash of the network address for certain abuse and rate-limit checks.
- Support messages
- If you contact us, we receive your email address, message and any attachments or account details you choose to provide.
3. How we use information
- Sign you in, maintain your account and apply your preferences.
- Run the image or image-understanding task you request and deliver its output.
- Keep available inputs, results and settings together in History, including reuse and retry features.
- Process purchases, manage subscriptions, reserve and return credits, and investigate payment issues.
- Provide support, measure service performance, troubleshoot failures and prevent abuse.
- Meet legal obligations and establish or defend legal claims.
Where data protection law requires a legal basis, account, generation and payment processing support our contract with you; security, service diagnostics and support support our legitimate interests; certain records are kept for legal obligations. Where consent is required for a particular use, it must be obtained for that use and can be withdrawn.
Authorized administrators can review account and generation information, including images and prompts, for support, safety, billing and service operations. Your private History is not an end-to-end encrypted storage service.
4. AI and other service providers
We share information needed to operate the service with providers in these categories:
- AI inference: prompts, reference images and relevant settings are sent to the provider handling the selected model. Routes may use model developers or hosting services such as fal, Replicate, WaveSpeed, Microsoft Azure or Mistral. Model comparison sends the requested inputs to each participating model; a workflow can use more than one provider.
- Hosting and storage: Cloudflare provides application hosting, databases, file storage and security infrastructure.
- Account authentication: Google handles Google sign-in.
- Payments: Stripe handles Checkout, subscription management, payment processing and refunds.
- Analytics: Google Analytics and DataFast measure website visits and usage, as described below.
- Support and administration: providers involved in delivering support messages and operating the service.
Provider retention and data-use rules, including rules about model training, vary by provider and service configuration. Do not assume that every available model offers zero data retention or the same restrictions on data use. Contact us before uploading information that requires a particular processing arrangement.
We may also disclose information when legally required, to investigate fraud or protect rights and safety, or as part of a business transfer subject to applicable data protection requirements.
5. Cookies, browser storage and analytics
Essential cookies maintain your signed-in session and protect the Google sign-in flow. The session cookie has a maximum life of seven days, and sessions also expire after inactivity or revocation. Temporary browser session storage helps restore a previous run or carry an image between tools.
All Image AI loads Google Analytics and DataFast scripts to understand traffic, referral sources and product usage. These services can use cookies or similar identifiers and process technical information such as page addresses, device details and IP addresses. See how Google uses information from partner sites and DataFast’s privacy policy.
You can manage or remove cookies and site storage in your browser. Blocking essential cookies can prevent sign-in or account features from working. Google also provides an Analytics opt-out browser add-on. Clearing local browser storage does not delete information already held in your account or by a provider.
Some pages load external assets, including directory badges and model logos. The host of an external asset can receive your IP address and normal browser request information when it loads. Following an external link takes you to that service’s own policies.
6. Storage, retention and deletion
New runs receive an expiry time based on the storage entitlement active when the run is created:
- Free accounts: 7 days
- Available original uploads, previews, generated images, text answers and run details are retained for the run’s storage period. Buying a credit pack alone does not provide a monthly plan’s longer storage.
- Active paid plans: 365 days
- Eligible new runs receive the longer storage period. A later upgrade or cancellation does not automatically rewrite the expiry date already assigned to an existing run.
- Anonymous previews, when offered: 24 hours
- Temporary preview records use the shorter storage period. Live generation requires an account.
History shows the expiry for individual runs. Access ends at expiry, and expired files and run records are removed during maintenance. Some older records may not have an expiry date; contact us or use the available deletion controls to remove them. Download anything you want to keep before its expiry.
You can delete completed or failed runs from Generation history. This removes the associated stored inputs and outputs from our active storage and the run from your History. Wait for an active run to finish before deleting it. Deleting a run does not cancel a subscription or request a cash refund.
Payment records, credit transactions, support messages and security records can remain for accounting, legal, dispute-resolution or abuse-prevention purposes. Detailed prompt moderation events are scheduled for deletion after 180 days; account-level safety counts may remain longer. Generation performance and cost records can remain with the direct account identifier removed; this is not a promise that every record becomes anonymous.
Account information remains while your account is active and as needed for the purposes above. For account closure or broader deletion, email us. Provider logs and backup copies may follow separate retention schedules and are not necessarily erased at the same moment as your History.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete or receive a copy of your personal information; restrict or object to certain processing; withdraw consent; and complain to a data protection authority. We handle requests subject to applicable law and may need to verify account ownership before acting.
Send requests from your account email address to contact@buai.dev. Include the request type and, where relevant, the run or order identifier. Do not send passwords, full card numbers or unnecessary sensitive documents.
You can download available results and delete finished runs in History, adjust content preferences in Settings, and manage subscriptions through Pricing → Manage billing. Contact us for account deletion or information not available through those controls.
8. Security and international processing
We use HTTPS, authenticated access to private account content and access controls for administrative functions. No online service can guarantee complete security. Only upload content you are authorized to use, and avoid including information that is unnecessary for the task.
Our service providers operate internationally, so information may be processed outside your country. Where applicable law requires transfer safeguards, transfers must use an appropriate legal mechanism. Contact us for information about the providers and processing arrangements relevant to your use of the service.
9. Children’s privacy
All Image AI is intended for adults aged 18 or older. If you believe a child has provided personal information through an account, contact us so we can investigate and take appropriate action. Uploading another person’s photo also requires the rights and permissions needed for that use.
10. Changes to this policy
We may update this policy as the product or our data practices change. The date at the top identifies the current revision. Where required, we will provide additional notice or obtain consent before applying a material change.
Contact BUAI LLC
Email contact@buai.dev and mention All Image AI so we can identify the product and your request.