Privacy Policy
This page explains what Mascotline collects, why we collect it, and who else receives it. It is written in plain language. It is a starting draft — have a human review it before you rely on it for a store listing.
Who we are
Mascotline is a web product that helps you lock a mascot identity and generate on-brand scene images. Contact: [email protected].
Account data
When you create an account we process your email address and the name you choose to show on your profile. We use that data to authenticate you, operate your account, send necessary service messages, and respond to support requests.
Content you submit
You may submit text descriptions of characters and scenes, edits to character traits, and related product inputs. We process that content to generate candidates, lock character identity, run drift checks, store your mascots and renders for you, and provide exports and API access you request. Generated images and related records stay in your account until you delete them or delete the account (payment ledger rows may be retained for financial audit).
Third-party processors we actually use
These external parties receive user data to provide specific services:
- OpenRouter — routes model calls used to generate and evaluate images and related text from the prompts and references you provide.
- Google Gemini Flash — processes prompts and related inputs for faster generation and evaluation passes when that model path is used.
- Gemini image — processes prompts and references to produce mascot and scene images when that image path is used.
- Polar.sh — processes checkout and payment events when you buy credits (email and purchase details as needed to complete payment and reconcile your credit balance).
- Cloudflare Email Service — processes email addresses and message content for transactional mail the product needs to send.
- Supabase Storage — stores the image files and related assets produced for your account.
Everything else runs on infrastructure we operate; no third party receives your data through it.
International transfers
Where the data physically sits: United States (Northern Virginia). If you use Mascotline from outside the United States, your data is transferred to the United States. Where a recipient is covered by an adequacy decision, that is the basis for the transfer; otherwise we rely on Standard Contractual Clauses. The exact basis for each processor is available on request so this page does not go stale as certifications change.
Cookies
This marketing site sets no cookies. Analytics events are counted without a device-persisted identifier, so there is no consent banner on these pages. Inside the signed-in product, session authentication may use a strictly necessary httpOnly cookie set by our servers; that cookie is required to keep you logged in and is disclosed here even though consent is not required for strictly necessary storage.
Analytics on this site
Optional product analytics may send anonymous event names (for example, that a visitor clicked Create your mascot) with a random identifier created in memory for that page load only. We do not write that identifier to cookies, localStorage, or sessionStorage on this landing.
How long we keep data
Account and content data are kept while your account is active. If you delete your account, we delete associated mascot content as described in our product rules. Records needed for payment reconciliation may be retained longer where the law or financial audit requires it.
Your choices
You can update your display name in the product, export or download assets the product provides, and request account deletion. For privacy questions or requests, email [email protected].
Changes
If this policy changes in a material way, we will update the effective date on this page.