ockeeper

Legal

Privacy Policy

What we collect when you render, why we keep it, and how to get it back or wipe it. No dark patterns, no buried opt-outs.

Effective 4 March 2026Version 3.0ockeeper Labs, Unipessoal Lda.

The short version

Training is opt-in, always

Prompts, uploads and renders stay out of every training run unless you switch it on yourself.

Your data lives in the EU

Renders and vault history are stored in Frankfurt and Stockholm. Transfers outside the EEA are listed in section 6.

Leave with everything

One action exports your full vault and account record. One more deletes it — for good, within 35 days.

01

Who we are and what this covers

ockeeper Labs, Unipessoal Lda., Rua da Prata 80, 1100-420 Lisbon, Portugal, is the controller of the personal data described here. Our data protection officer can be reached at dpo@ockeeper.com.

This policy covers the studio, the vault, the mobile apps, the render API and our marketing site. It does not cover third-party sites we link to, or what you do with an image after you export it.

02

The data we collect

We collect four kinds of data, and each one has a reason to exist:

  • Account data — email, display name, password hash, workspace membership and the plan you are on. Given by you at sign-up.
  • Content data — prompts, uploaded references, Character Keys, generated renders, seeds and model parameters. Created when you render.
  • Technical data — IP address, device and browser type, timestamps, render durations and error traces. Collected automatically so we can keep the queue honest and debug failures.
  • Billing data — order references, amounts, the country used for tax, and the card brand and last four digits shown on your receipt. Full card numbers are handled by our payment provider and never reach our servers.
03

Why we process it

Account and content data are processed to perform our contract with you: to render images, to store them in your vault and to bill you correctly.

Billing data is processed to perform that contract and to meet our legal obligations for tax and accounting records. Technical data is processed under our legitimate interest in keeping the service stable, preventing abuse of the free allowance and investigating payment fraud. You can object to this — write to dpo@ockeeper.com and we will explain the balancing test we ran.

Marketing email is sent only with your consent, and every send carries a working one-click unsubscribe. Withdrawing consent never affects your ability to use the product.

04

Prompts, renders and model training

This is the section people actually came for. By default your prompts, uploads and outputs are not used to train, fine-tune or evaluate any model — ours or a partner’s. There is no quiet exception for “aggregated” or “anonymised” training.

A small number of renders may be reviewed by a person when they are flagged by the safety classifier, when you file a support ticket about them, or when we are legally compelled. Reviewers see the render and the prompt, nothing else about you.

If you turn on model contributions in settings, we tell you exactly what that includes and you can turn it off again at any time. Turning it off stops future use; renders already in a completed training run cannot be pulled back out, and we say so up front.

05

Who else touches your data

We use a short list of processors, each under a data processing agreement, each doing one job:

  • Waffo — payment processing, checkout and refunds. Receives the amount, currency, order reference and the billing details you enter on its checkout page.
  • Amazon Web Services — compute and object storage for renders (Frankfurt, Stockholm).
  • Supabase — authentication and application database (European Union).
  • Cloudflare — content delivery, bot mitigation and edge caching (global).
  • Postmark — transactional email such as receipts and password resets (United States).

We do not sell personal data, and we do not share it with advertising networks. If we are ever acquired, the acquirer inherits this policy until you are given notice and a chance to leave.

06

Where your data is stored

Renders, vault history and account records are stored in the European Union — primarily AWS eu-central-1 in Frankfurt, with a warm replica in eu-north-1.

Some processors operate outside the EEA. Those transfers rely on the European Commission’s standard contractual clauses, plus encryption in transit and at rest. The current list, with the country and the safeguard used, is in section 5.

If you need EU-only processing with no exceptions, enterprise workspaces can be pinned to a Frankfurt-only region — including support tooling.

07

How long we keep things

Retention is set per data type, not by one blanket rule:

  • Account record — identity, plan and workspace links. Kept until you delete it.
  • Renders and vault — images, prompts, seeds and versions. Kept for the life of the account.
  • Deleted items — removed from live systems at once; backups purge within 35 days.
  • Billing records — invoices and tax country. Kept 10 years, as Portuguese law requires.
  • Server logs — IP, device and error traces. Kept 30 days, then aggregated.
  • Support tickets — messages you send our team. Kept 24 months after closing.

Closing your account keeps the vault exportable for 90 days in case you change your mind, then removes it. You can skip the grace period and wipe everything immediately from the danger zone in settings.

08

Your rights and how to use them

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to another provider in a portable format.

  • Access and export — self-serve from settings, no ticket needed, delivered as a signed archive.
  • Correction — edit your profile directly, or write to us for anything you cannot reach.
  • Deletion — one action in the danger zone; we confirm by email once backups have caught up.
  • Objection and restriction — email dpo@ockeeper.com and we answer within 30 days, in plain language.

You can also complain to your local supervisory authority. Ours is the Comissão Nacional de Proteção de Dados in Lisbon, but you may go to the regulator where you live instead.

09

Cookies and product analytics

We use one strictly necessary cookie to keep you signed in, and one to remember your theme. Neither follows you off our domain.

Product analytics are aggregate: page views and feature usage, with no cross-site identifier and no fingerprinting. Nothing about a prompt or a render is sent to them.

We do not run advertising pixels. If we ever add a measurement tool that needs consent, it will sit behind a real banner with a reject button that works on the first click.

10

Security, minors and changes

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production is limited to a small on-call group, is logged and requires hardware keys. We run an annual penetration test and publish the summary.

The service is not intended for anyone under 16. We do not knowingly collect data from children, and we delete accounts we discover to belong to one.

When this policy changes materially, we email you at least 30 days before the new version takes effect and keep the previous version linked from the changelog. Small clarifications are noted there too, with a date.

Want your data back?

Export or delete everything from settings without asking anyone. For anything else, our data protection officer replies within 1 business day.

dpo@ockeeper.com

ockeeper Labs, Unipessoal Lda. · Rua da Prata 80, 1100-420 Lisbon, Portugal · replies within 1 business day