Skip to content
NEWLIMITED TIME OFFERGet started with our premium plan today!

Privacy Policy

Last updated: March 26, 2026

This Privacy Policy describes how LimeAILab ("we", "us", or "our") collects, uses, and protects your information when you use our AI image generation platform at limeailab.com (the "Service").

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Display name
  • Password (hashed and salted, never stored in plain text)
  • OAuth profile data if you sign in via GitHub or Google (name, email, avatar URL)
  • Passkey/WebAuthn credentials if you choose this authentication method

AI Generation Data

When you use our image generation features, we collect:

  • Text prompts you submit
  • Reference images you upload (for image-to-image generation)
  • Generation parameters (model selection, aspect ratio, resolution, seed values)
  • Generated output images

Payment Information

When you purchase credits or subscribe to a plan, payment is processed by Creem. We store:

  • Transaction records (amount, date, plan type)
  • Subscription status and billing cycle

We do not store your full credit card number or payment credentials. These are handled entirely by Creem.

Usage Data

We automatically collect:

  • Pages visited and features used
  • Generation history and credit usage
  • Device type, browser type, and operating system
  • IP address
  • Timestamps of account activity

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service — process your image generation requests, manage your account, and deliver generated images
  • Process payments — handle credit purchases, subscriptions, and billing via Creem
  • Maintain generation history — store your prompts and outputs so you can access them later
  • Improve the Service — analyze usage patterns to optimize performance and develop new features
  • Communicate with you — send transactional emails (account verification, password resets, payment receipts) via Resend
  • Ensure security — detect and prevent fraud, abuse, and unauthorized access

We do not sell your personal information to third parties. We do not use your prompts or generated images to train AI models.

3. AI-Generated Content Data Handling

  • Prompts are stored in our database (Cloudflare D1) and linked to your account for generation history purposes.
  • Generated images are stored on Cloudflare R2 object storage.
  • Reference images you upload for image-to-image generation are stored on Cloudflare R2.
  • Generation parameters (model, resolution, aspect ratio) are logged alongside each generation record.
  • If you choose to make images public or they are selected for the Gallery, the images and associated metadata may be publicly visible. Prompts are not displayed publicly unless you explicitly choose to share them.

4. Third-Party Services

We rely on the following third-party services to operate:

ServicePurposeData Shared
Cloudflare (Workers, D1, R2, KV)Hosting, database, image storage, cachingAll service data is processed within Cloudflare infrastructure
CreemPayment processingPayment details, email, transaction amounts
ResendTransactional email deliveryEmail address, email content
GitHub (OAuth)Optional account authenticationOAuth token exchange; we receive your public profile
Google (OAuth)Optional account authenticationOAuth token exchange; we receive your basic profile

Each third-party service operates under its own privacy policy. We encourage you to review their policies.

5. Data Storage and Security

  • User data is stored in Cloudflare D1 databases.
  • Images are stored in Cloudflare R2 object storage.
  • Session and cache data is stored in Cloudflare KV.
  • All data is encrypted in transit (TLS) and at rest within Cloudflare's infrastructure.
  • Passwords are hashed using industry-standard algorithms and are never stored in plain text.
  • We implement access controls and security best practices, but no system is 100% secure. We cannot guarantee absolute security.

6. Cookies and Tracking

We use essential cookies only:

  • Authentication session cookies — required to keep you signed in
  • Security tokens — CSRF protection and related security measures

We do not use:

  • Third-party tracking cookies
  • Advertising cookies
  • Social media tracking pixels

We may use Cloudflare Analytics or similar privacy-respecting analytics to understand aggregate usage patterns. These do not track individual users across websites.

7. Data Retention

  • Account data is retained as long as your account is active.
  • Generated images are retained until you delete them or delete your account.
  • Generation history (prompts, parameters) is retained until you delete your account.
  • Credits expire 30 days after being granted, as described in our Terms of Service.
  • Payment records are retained as required by applicable tax and financial regulations.
  • If you delete your account, we will remove your personal data and generated images within 30 days, except where retention is required by law.

8. Your Rights

You have the right to:

  • Access your personal data and generation history through your account dashboard
  • Download your generated images at any time
  • Delete individual images or your entire account
  • Update your account information
  • Opt out of non-essential communications
  • Request a copy of the personal data we hold about you by contacting us

To exercise any of these rights, you can use the relevant features in your account settings or contact us at contact@limeailab.com.

9. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will promptly delete such information.

10. International Data Transfers

Our Service is hosted on Cloudflare's global network. By using the Service, you consent to your data being processed in the jurisdictions where Cloudflare operates its infrastructure.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: