Privacy Policy — Got Image 2
At Got Image 2, your privacy is a core value embedded in everything we build. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how we protect it. We've written this in plain English so it's easy to understand, while still providing the legal details you need.
Effective Date: March 16, 2026
1. Information We Collect
We collect information to provide, improve, and protect our AI image generation services. Here's a detailed breakdown of what we collect and why.
1.1 Account Information
When you create an account, we collect:
| Data Type | Purpose | Required |
|---|---|---|
| Email address | Account verification, communications, password recovery | Yes |
| Full name | Personalization, identification | Yes |
| Password | Account security (stored as secure hash) | Yes |
| Profile picture | Profile personalization | No |
1.2 Content and Usage Data
When you use Got Image 2 tools, we collect:
Image Generation Data:
- Text prompts and descriptions you enter
- Style and model preferences you select
- Resolution and format settings you choose
- Generated image files and their metadata
Interaction Data:
- Images you like, save, or download
- Features and tools you use most frequently
- Time spent on different functions
- Error reports and crash logs
1.3 Technical Information
We automatically collect technical data to ensure optimal service:
Device Information:
- Device type (desktop, mobile, tablet)
- Operating system and version
- Browser type and version
- Screen resolution
Network Information:
- IP address
- Geographic location (country/region level)
Session Information:
- Pages and features visited
- Time and duration of visits
- Referring URLs (how you found us)
1.4 Payment and Billing Information
When you make purchases, we collect:
- Payment method type (credit card, PayPal, etc.)
- Billing name and address
- Transaction amounts and dates
- Subscription plan details
Important Security Note: We never store complete credit card numbers, CVV codes, or other sensitive payment credentials. All payment processing is handled by PCI DSS Level 1 certified payment processors (Stripe).
1.5 Communications Data
We collect information from your communications with us:
- Support tickets and help requests
- Email correspondence
- Feedback and feature requests
1.6 Third-Party Data
We may receive information from third parties:
- Social media profiles (if you sign in with Google, etc.)
- Fraud prevention services
- Analytics providers
2. How We Use Your Information
We use your information for specific, legitimate purposes:
2.1 Providing Our Services
- Account Management: Create, authenticate, and manage your account
- Image Generation: Process your prompts and generate AI images
- Content Storage: Safely store your generated images and projects
- Feature Access: Enable premium features based on your subscription
- Personalization: Remember your preferences and settings
2.2 Improving Our Technology
- Quality Enhancement: Analyze generation quality to improve outputs
- Bug Fixes: Identify and resolve technical issues
- Performance Optimization: Optimize server response times and processing speed
AI Training Transparency: We may use prompts and generated content to improve our AI models. This data is processed in aggregate and anonymized form.
2.3 Communications
- Transactional emails: Order confirmations, password resets, subscription updates
- Service notifications: Feature updates, maintenance alerts, security notices
- Marketing (with consent): New features, tips, promotional offers
- Support: Respond to your questions and help requests
2.4 Safety and Security
- Fraud prevention and abuse detection
- Content moderation
- Security monitoring
- Legal compliance
3. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), we process your data based on these legal grounds:
| Legal Basis | When It Applies |
|---|---|
| Contract Performance | Providing our services, processing payments, account management |
| Legitimate Interests | Service improvement, security, fraud prevention, analytics |
| Consent | Marketing communications, optional features |
| Legal Obligation | Tax records, responding to legal requests, compliance requirements |
You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
4. Data Sharing and Disclosure
We do not sell your personal information. This is a firm commitment.
We only share data in these limited circumstances:
4.1 Service Providers
We work with carefully selected companies that help us operate:
| Provider Type | Purpose | Data Shared |
|---|---|---|
| Cloud Infrastructure | Hosting, storage, computing | All service data (encrypted) |
| Payment Processors | Transaction handling | Payment and billing info |
| Email Services | Transactional and marketing emails | Email, name |
| Analytics | Usage analysis | Anonymized usage data |
| CDN Providers | Content delivery | Generated image files |
All service providers are bound by strict data processing agreements and can only use your data to provide services to us.
4.2 Legal Requirements
We may disclose your information when required by law:
- Valid court orders or subpoenas
- Government agency requests with legal authority
- To protect someone's life or safety
- To protect Got Image 2's legal rights
We will notify you of legal requests when legally permitted to do so.
4.3 Business Transfers
If Got Image 2 is involved in a merger, acquisition, or sale:
- We will notify you before your data is transferred
- This policy will continue to apply to your data
- You will have the option to delete your data before transfer
4.4 Aggregated Data
We may share anonymized, aggregated statistics that cannot identify you.
5. Cookies and Tracking Technologies
5.1 Types of Cookies We Use
Strictly Necessary Cookies
- Authentication and login status
- Security tokens
- Session management
- Cannot be disabled (service won't work without them)
Functional Cookies
- Language preferences
- Theme settings (light/dark mode)
Analytics Cookies
- Page view tracking
- Feature usage patterns
- Session duration
5.2 Managing Cookies
Browser Controls: Most browsers let you block or delete cookies in Settings > Privacy. Blocking all cookies may prevent some features from working.
6. Data Security
6.1 Technical Safeguards
Encryption:
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Secure key management
Infrastructure Security:
- Hosting on enterprise-grade cloud providers
- DDoS protection and mitigation
- Web Application Firewall (WAF)
- Regular vulnerability scanning
Application Security:
- Secure software development lifecycle
- Code reviews and security testing
- Input validation and sanitization
6.2 Your Role in Security
Help keep your account safe:
- Use a strong, unique password (12+ characters recommended)
- Don't share your login credentials
- Log out on shared or public computers
- Report suspicious activity immediately
6.3 Breach Notification
In the event of a data breach affecting your personal information:
- We will notify affected users within 72 hours of discovery
- We will notify relevant regulatory authorities as required
- We will provide details about what data was affected
- We will explain steps we're taking to address the breach
7. Data Retention
We retain your data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Active account + 30 days after deletion request | Service provision, account recovery |
| Generated Images | Until you delete them or close account | Your content ownership |
| Payment Records | 7 years after transaction | Legal and tax requirements |
| Support Conversations | 3 years | Quality assurance, legal protection |
| Analytics Data | 26 months | Service improvement |
| Server Logs | 90 days | Security and debugging |
After retention periods, data is permanently deleted or anonymized.
8. Your Privacy Rights
8.1 Universal Rights
All users have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete information
- Deletion: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing communications
- Object: Object to certain processing activities
8.2 How to Exercise Your Rights
Contact Us:
- Email: support@gotimage2.co
- Subject line: "Privacy Request - [Your Request Type]"
- Include your account email for verification
Response Time:
- Simple requests: Within 7 days
- Complex requests: Within 30 days (45 days maximum for CCPA)
9. International Data Transfers
9.1 Where We Process Data
Got Image 2 processes data primarily in the United States, with additional processing in the European Union for EU users and other regions as needed for service delivery.
9.2 Transfer Safeguards
For international transfers, we use:
- Standard Contractual Clauses (SCCs)
- Adequacy Decisions
- Privacy Shield Principles
10. Children's Privacy
- Got Image 2 is designed for users 13 years and older
- In the EU/EEA, users must be 16+ (or have parental consent)
- We do not knowingly collect data from children under these ages
- If you believe your child under 13 (or 16 in EU) has created an account, contact us immediately at support@gotimage2.co
11. California Residents (CCPA/CPRA)
If you're a California resident, you have specific rights:
- Right to Know: What personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Correct: Correct inaccurate personal information
- Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
- Right to Non-Discrimination: Equal service regardless of exercising rights
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
To make requests, email support@gotimage2.co with subject "California Privacy Request."
12. European Residents (GDPR)
If you're in the European Economic Area (EEA), United Kingdom, or Switzerland:
Your GDPR Rights:
- Access (Art. 15): Obtain confirmation of processing and access to your data
- Rectification (Art. 16): Correct inaccurate personal data
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Restrict processing in certain circumstances
- Portability (Art. 20): Receive data in structured, machine-readable format
- Object (Art. 21): Object to processing based on legitimate interests
Data Controller: Got Image 2 is the data controller for your personal data.
You have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can resolve your concerns.
13. AI and Machine Learning
13.1 How We Use AI
Got Image 2 uses artificial intelligence for:
- Image generation from text prompts
- Image editing and enhancement
- Style transfer and variations
13.2 AI Training Practices
What We May Use:
- Aggregated, anonymized usage patterns
- Public domain training data
- Licensed training datasets
What We Don't Do:
- Train on identifiable user data without consent
- Use your private content to create models for others
- Sell models trained on user data
14. Changes to This Policy
- We may update this policy periodically
- Material changes will be announced via email
- Non-material changes take effect upon posting
- Continuing to use Got Image 2 after policy changes means you accept the updated policy
15. Contact Us
Got Image 2 Privacy Team
- Email: support@gotimage2.co
- Website: gotimage2.co
Response Times:
- General inquiries: 5-7 business days
- Rights requests: 30 days
- Security concerns: 24-48 hours
Your privacy matters to us. If you have any questions, concerns, or feedback about this Privacy Policy or our data practices, please don't hesitate to reach out. We're committed to protecting your information and being transparent about how we use it.
Thank you for trusting Got Image 2 with your data.
