Skip to main content

Privacy policy

This describes what Sals Kewl Vehicle Livery AI stores, where it goes and how long it is kept. Retention windows are configurable per deployment; the values below are the defaults.

What is stored

  • Account data — email address, name, locale, time zone and preferences.
  • Content — templates, reference photographs, layers, regions, exports and project archives.
  • Operational records — sign-in events, background jobs, credit ledger entries and, on plans that include it, an audit trail.
  • Sessions — a device fingerprint made of user agent and IP address, so you can review and revoke sessions individually.

Cookies

Three cookies are set, and no others: sals_kewl_access and sals_kewl_refresh are httpOnly session cookies, and sals_kewl_csrf is readable by the page so it can be echoed back in a header to prove a request came from this application. There are no advertising or analytics cookies.

AI providers

Some providers process images inside this deployment; others send them to a third party. Which one applies is shown before any run, along with the destination. If your organization supplies its own provider key, calls go directly to your account.

Your designs are not used to improve any model unless you explicitly opt in, per user and per organization. Both switches default to off and can be turned off again at any time.

Support access

Platform administrators have no standing access to your data. Viewing it requires an audited grant that names a reason, expires automatically, gives read-only permissions, and is recorded in your organization's audit log. You can disable support access entirely in organization settings.

Retention

  • Deleted projects and organizations: 30 days, then purged.
  • AI inputs: 30 days. AI outputs: 90 days.
  • Exports: 30 days. Temporary uploads: 24 hours.
  • Job records: 30 days. Audit logs: 365 days.

Your rights

You can export any project as a complete archive containing its document, template, references and history. You can delete individual assets, projects and organizations from the interface. To delete your account and everything attached to it, contact the operator of this deployment.

Security

Object storage is private and every read is signed per request after authorisation. Provider credentials are encrypted at rest and never returned in plaintext. Uploads are validated server-side after they land, so bypassing the browser gains nothing.