What we collect
When you sign in with Google we receive your basic profile — name, email address and profile picture. We store the prompts you submit and the images generated from them so you can find them again.
We also collect anonymous usage data such as page views and generation counts to keep the service running.
How we use it
Your prompts are sent to our image generation provider (fal.ai, running the Ideogram 4.5 model) solely to produce the image you asked for. We never sell your personal data.
Images you mark as public may appear in the gallery and can be indexed by search engines. Images you keep private are only visible to you.
Where your data is stored
Your account details, prompts and generated images are stored in a PostgreSQL database that we operate ourselves, on cloud servers located in Singapore. Traffic between your browser and hivepic is encrypted in transit with HTTPS/TLS.
How we protect it
- No passwords. We use Google Sign-In only. We never receive or store your Google password, and hivepic keeps no password database that could leak.
- Encrypted in transit. All requests to hivepic and its APIs are served over HTTPS.
- Restricted access. The production database listens only on the server's own loopback interface, so it cannot be reached from the public internet, and administrative access is limited to the site operator over key-based SSH.
- Isolated payments. Card and billing details are entered on Waffo's checkout and never reach our servers. We only receive a subscription reference and its status from Waffo.
No system is perfectly secure, so we cannot promise absolute security — which is exactly why we deliberately keep the amount of data we hold to a minimum.
How long we keep it
- Account, prompts and images — kept for as long as your account is active. Deleting an image removes it from your account and from the gallery. If you ask us to close your account, we erase your profile, prompts and images within 30 days.
- Operational logs — server and security logs are kept for up to 90 days to detect abuse and diagnose faults, then deleted.
- Billing records — invoices and transaction records are held by Waffo, our merchant of record, for as long as tax and accounting law requires. We store no card details at all.
- Caches and search engines — public images you later delete may linger briefly in third-party caches or search-engine snapshots that we do not control.
Sharing and international transfers
We do not sell your personal data. We share only what is needed to run the service, and only with the providers listed below. Because these providers operate globally, your data may be processed outside your country — including in Singapore, where our own servers are located.
Third parties
- fal.ai — image generation. Your prompt is transmitted to them to render the image.
- Google — sign-in and optional analytics.
- Cloudflare — content delivery.
- Waffo — payments and subscription billing. When you subscribe, Waffo processes your payment details as merchant of record.
- SeeAPI — automated content-safety screening of prompts and generated images.
Your choices and rights
You can delete your generated images at any time from your account page. You can also email us at threehai@outlook.com to:
- access a copy of the personal data we hold about you;
- correct anything that is inaccurate;
- delete your account and its associated data;
- export your prompts and images;
- object to or restrict a particular use.
We respond to these requests within 30 days. You can cancel your plan at any time from your account page.
Children
hivepic is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
Changes
We may update this policy. Material changes will be announced on this page.
Last updated: 10 October 2026.