Privacy Policy
Last updated 30 August 2026
1. What this covers
This policy explains what Frontpiece collects when you use the service, what we do with it, who else processes it on our behalf, and how to get it deleted. It applies to this website and to your account. In this policy "we", "us" and "our" mean Frontpiece LLC, a Texas limited liability company (filing number 1616516830003), which is responsible for the personal data described here and is its controller where that term applies.
We are a small team. We collect what the product needs to run and not more, and there is no advertising business here to sell anything into.
2. What we collect
We collect these things, and only these things:
- Account details. Your email address and a password, which is stored hashed by our authentication provider and is never visible to us. Email and password is the only way to sign in; there is no social login.
- Content you upload. Product photos, brand logos, and any reference images you add to an edit.
- Content you enter. Product names, brand names, descriptions, features, dimensions, categories, target buyers, brand voice notes, the marketplaces you are listing on, and the instructions and prompts you write for a generation.
- Content you import. When you import a product from a marketplace listing you supply, we fetch that public page and its images.
- Content we generate for you. The images, listing copy and A+ modules produced from the above, and the edit history attached to them.
- Payment details, handled by Stripe. Card numbers never reach our servers. We store a Stripe customer reference, your subscription state, your plan, and the billing period.
- A record of your acceptance of these documents. When you tick the box to accept our terms of service and this policy, we record the date and time, the IP address you accepted from, your browser's user agent string, the version and a content fingerprint of the exact text you were shown, and the wording of the notice itself. This record is what allows us to show, later, that the agreement was actually formed and on what terms. Section 7 explains how long we keep it and section 8 explains why it is the one thing that outlives your account.
- Technical and error data. When something breaks we receive an error report that can include the page, the request and a stack trace.
- Product usage, if you allow it. When you choose Allow on the cookie strip, we record which pages and features you use, the actions you take in the product, and a replay of your session so we can watch a failure back rather than guess at it. Replays mask the text you type. Choose Decline and none of this is collected. Separately, and with no cookie and no choice to make, our host counts page views in a form that cannot be tied back to you.
3. Who processes it
We use the service providers below to run the product. Each one receives only what its job requires, and each processes it on our instructions.
- Supabase: accounts and authentication, the database holding your products and runs, and the private storage bucket holding your uploaded photos and logos.
- OpenAI: image generation. Your uploaded product photos and your instructions are sent to its image API.
- Google: two separate roles. Gemini analyses uploaded product photos before generation and powers in-product suggestions, so those photos and prompts are sent to it. Google Drive stores the generated output images, which is where the image URLs in the product point.
- Anthropic: parses the marketplace listing pages you import, to fill in product fields.
- n8n: orchestrates the generation workflow, and passes your product details and photo links between the steps.
- Trigger.dev: runs background jobs such as adding an image, editing one, and upscaling.
- Vercel: hosts and serves the application.
- Stripe: payments, subscriptions and the billing portal.
- Resend: delivers account email such as password reset links, and receives your email address in order to send it.
- Sentry: error monitoring, which receives diagnostic data when something fails.
- PostHog Inc.: product analytics and session replay, on servers in the United States, and only for people who chose Allow on the cookie strip. It receives the usage and replay data described in section 2. A small number of events that record a transaction rather than a browsing habit, such as a completed signup or a completed purchase, are sent from our servers whatever you chose, because they are our own record of the deal and they set no cookie on your device.
4. Artificial intelligence providers and training
Your content is sent to the artificial intelligence providers named above so the service can do its job. It is processed under those providers' business and API terms rather than their consumer terms. Under the OpenAI and Anthropic API terms, content sent through the API is not used to train their models. The Gemini API is used on a paid tier, and under Google's terms for that tier your content is not used to improve or train Google's models.
We do not train any model on your content ourselves, and we do not license your content to anyone to train theirs.
Generation is not deterministic and the providers may change their models at any time, so the same input can produce different output on different days.
5. Sharing, and links that do not need a password
We do not sell your personal information and we do not share it with anyone for their own marketing.
Two parts of the product make content reachable by a link rather than by a login, and both are worth understanding before you use them:
- Reviewer links. When you share a run for review, we mint a long, unguessable link that grants whoever holds it access to that run's images and copy, and the ability to approve or request changes. It needs no account and no password. It does not expire, and we cannot revoke a single link on its own: revoking means invalidating every outstanding reviewer link at once. Treat one like a password, and only send it to people you mean to give access to.
- Image links. Generated images are served from storage links that work for anyone holding the URL. That is what lets a reviewer link, an export and a shared preview display them without a login.
6. What we use it for
To run the service: to generate images and copy for you, to show you your work, to let you edit and export it, and to share it with the reviewers you choose.
To bill you, to prevent abuse, to diagnose failures, and to answer you when you contact us.
To comply with the law, and to enforce our terms. This is also why we keep the acceptance record described in section 2: it is the evidence that our agreement with you exists, and it is kept on that basis rather than to profile you.
We do not use your content to advertise to you, we run no advertising trackers, and we sell nothing about you to anybody. We do run product analytics, and section 2 says what that means: our host counts page views without a cookie, and PostHog records what you do in the product and replays your session if you chose Allow. We use it to find what breaks and what nobody can work out how to use, and for nothing else.
7. How long we keep it
Your account content, meaning your products, photos, runs, generated images and listing copy, is kept for as long as your account is open, because it is the working history the product is built around.
When you delete your account we delete that content, other than anything we must keep to meet a legal, tax or accounting obligation. Billing records are kept for as long as the law requires, usually several years.
The acceptance record described in section 2 is kept for six years after it is superseded by a later acceptance or after your account closes, whichever is later. That is a little longer than the period in which a claim about the agreement can still be brought where these terms place disputes. It is stored so that it cannot be edited or deleted by the application, which is the property that makes it worth anything as evidence.
Error reports are kept on a short rolling window by our monitoring provider, and are not linked to your content.
Content held by the providers in section 3 is retained under their own terms, which we do not control.
8. Your choices
You can see and change your account details in the product, and you can delete individual products, runs and images at any time. To request a copy of your data, a correction, or the deletion of your account and everything in it, email legal@frontpiece.ai from the address on your account. We action deletion requests within 30 days and will tell you when it is done.
One thing survives that deletion, and we would rather say so than have you find out: the acceptance record described in section 2. It is deliberately stored in a way that account deletion cannot reach, because its only purpose is to show that you and we had an agreement, and a record that disappears when one side asks cannot do that job. It holds the time, the IP address, the version of the documents and the wording you were shown, and nothing about what you made with the product. If you want it removed as well, ask us, and we will tell you honestly whether we are able to and on what basis.
Depending on where you live you may have further rights, including the right to object to processing, to restrict it, to receive your data in a portable form, or to complain to a supervisory authority. Ask us and we will help rather than make you cite the statute.
Your answer to the cookie strip is stored in a cookie on your own device and lasts twelve months. Clearing your cookies for this site clears it, and we will ask again on your next visit, so changing your mind takes no email to us.
Deleting content does not retract a reviewer link you have already sent to someone, and it does not reach copies other people have downloaded.
9. Security
Uploads live in a private storage bucket, database access is scoped so an account can only reach its own rows, and traffic runs over TLS. Payment card data never touches our servers.
No service is perfectly secure, and section 5 describes two places where the product deliberately trades a login for a link. If you become aware of a vulnerability, tell us at the address below before you tell anyone else.
10. International transfers
We are based in the United States and the providers in section 3 operate there and elsewhere. Using the service means your content is processed in the United States and in other countries where those providers run, which may have different data protection rules than your own.
11. Children
The service is for businesses and is not directed at children. You must be at least 18 to use it, and we do not knowingly collect anything from a child. If you believe a child has given us information, tell us and we will delete it.
12. Changes to this policy
We may update this policy. When we do we will change the date at the top of this page. Where a change is material we will ask you to accept it before you continue to use the service, in the same way as a change to the terms, and we will keep a record of that acceptance.
13. How to reach us
Privacy questions, data requests and deletion requests all go to the same place: legal@frontpiece.ai. The terms of service set out the agreement this policy sits under.