Privacy Policy
This policy explains how Premsan Inc (“Premsan”, “we”, “us”) handles personal data in Krafical — this website, the web app, the API, and the Krafical apps for iPhone, iPad and Android. Premsan is the controller of that data.
1. What we collect
- Your account. Your name, your email address, and either a password — stored only as a hash — or, when you sign in with Apple or Google, your identifier there and the sign-in tokens the provider gives us. Each session records the IP address and the browser or device it was opened from, and when it expires. We also record the date on which you accepted the Terms, and which version.
- What you bring. The messages you exchange with the assistant, the part of a design you point at, your designs and every version of them, the images you upload — photos, logos and SVG files — the images the assistant generates or cuts out for you, with the description it wrote to generate each one, and the renders of your designs. Your images form one library shared by all your designs. What goes in is your choice; Krafical holds it exactly as you gave it, for the designs you want, and you can delete any design or image at any time.
- The plan. When your free use began, how many messages you have sent since, and the state of your subscription. On the web, payment is taken by Stripe: it receives your email address and your account id, and your card details go to Stripe and never reach us. We keep the subscription’s id, its customer id at Stripe, when its current period ends and whether it renews. In the app, payment is taken by the App Store or Google Play; we receive the transaction’s id, confirm it with Apple or Google, and record it against your account.
- Help. When you write to us from Help, we keep your messages, the pictures you attach, our replies, and details that help us answer: whether you wrote from the web or the app, your browser or the app’s version and operating system, your language, the screen you came from, the size of your window or screen, your time zone and your most recent failed requests to our servers. They are kept with your account until you delete it. Our team reads them in our own support tool, where, if you have allowed the assistant, Krafical’s model may draft a reply that a team member reviews before sending.
- Usage. How many times the assistant ran, how many designs were rendered and how many model tokens were used each month, kept inside your own account’s storage for our accounting. Server logs hold request metadata, including your IP address, and error reports for a short time, for security and debugging.
- The bot check. Cloudflare Turnstile runs on our sign-in and sign-up pages, and in the app’s sign-in screen, to tell a person from a script.
- Nothing else. There is no advertising, no analytics, no tracking across sites or apps, no advertising identifier, and no data broker.
2. What we do with it
We use personal data to run Krafical: to make, render and check your designs, to generate and cut out the images you ask for, to make the files you download, to sign you in, to send you the emails the account needs — a verification link and a password reset — to take payment and keep your subscription’s state, to keep the service running and prevent abuse, to answer you when you write to us, and to meet legal obligations. We do not use your messages, images or designs to train models, we do not sell personal data, and we do not share it for advertising.
3. Why we are allowed to
Where the GDPR or a similar law applies, we rely on these bases:
- Performing our contract with you — your account, your designs, your images, your conversations, and the subscription. Without them there is no service to give you.
- Our legitimate interests — keeping Krafical running, finding failures, and stopping abuse and automated sign-ups. We limit this to what running the product needs: the usage counts, the logs and the bot check, not profiling and not advertising.
- A legal obligation — payment records and anything else the law requires us to keep.
- Your consent — for anything the law treats as special that you choose to put in an image, a design or a conversation. You give it by putting it in, and you withdraw it by deleting the image, the design or the account.
4. Who else processes it
Krafical runs on Cloudflare: the servers, the storage that holds your account, designs and images, the models, the browser that renders your designs, the background removal, the email we send, and the bot check are all Cloudflare services on our own account. No prompt or image of yours goes to any other AI provider. The models are open-weight models that run on Cloudflare Workers AI: GLM-5.3 Flash writes and reviews your designs, and FLUX.2 [klein] 4B generates the images you ask for, from the assistant’s description and up to four of your images. The assistant sends them nothing until you allow that, on the web or in the app, when it asks before your first message; you can turn it off in Settings (under Account in the phone app), and the assistant then asks again before your next message. Cloudflare Images takes the background out of a photo when the assistant cuts it out, and Cloudflare’s Browser Run opens each design in a browser to check it and to make the files you download. Some email may be sent through Resend instead. Stripe takes payment on the web and stores your card details; Apple and Google take payment in the app, and each tells us when a subscription you bought there renews, is cancelled or is refunded. The typefaces your designs are set in are copied from Google Fonts into our own storage, with no personal data, and a design loads nothing from outside when it is rendered. When the app opens it asks Expo’s update service whether a newer version of our code is available; that request carries the operating system, our project id and a random identifier the app generated for itself — no account and no device identifier — and Expo sees the IP address it came from. These providers process data only on our instruction and are each bound to protect it at least as well as this policy does; we give notice here before a new one starts.
Signing in with Apple or Google sends us your identifier and email from that provider. Each acts on its own behalf there, not as our processor, and its handling of your account with it is governed by its own privacy policy; if you hide your email from us with Apple, mail reaches you through Apple’s relay. The App Store and Google Play are the sellers of what you buy inside the app, and their handling of your payment is governed by theirs.
5. Where it is
Your data is processed on Cloudflare’s network, which spans the world, and stored on it under Cloudflare’s own commitments for international transfers. Premsan is in Japan, a country the European Commission recognises as protecting personal data adequately.
6. On the phone
The app keeps on your device a sign-in token, the language and appearance you chose, the random identifier it uses for update checks, and, when you share a design, a copy of that file in the app’s own cache for the share sheet. It uses the camera only when you choose to take a photo, and the operating system asks your permission the first time; it reads your photos and files only when you pick them, through the system’s own picker, which needs no permission. Nothing is read in the background. Purchases go through the store’s own sheet. The app contains no advertising or analytics library. The only review prompt it shows is the operating system’s own, requested once after you share your first design.
7. Cookies
On the web we set the cookies the product cannot work without: the one that keeps you signed in, and the ones Cloudflare Turnstile sets to tell a person from a bot on the sign-in and sign-up pages. This website and the web app keep your theme and language in your browser’s own storage. There are no other cookies: no advertising cookies, no cross-site trackers, and no analytics that follows you between sites, so the site does not ask you to accept cookies. Clearing them signs you out.
8. How long we keep it, and deleting it
We keep your account and everything in it for as long as the account exists. Deleting a design removes it, its conversation, its versions, its render and its checks; the images it used stay in your library until you delete them. Deleting an image removes it from your library and from our storage. Verification and reset links expire on their own.
You can delete your account at any time: on the web under Account in Settings, or in the app under Account. Deleting it erases everything we hold for you — designs, versions, conversations, images, renders, Help messages, usage and the subscription’s state — and then the account itself, except for the records listed below. You cannot undo it.
These records remain after the account is deleted:
- Purchases in the app. A subscription bought in the app leaves a record of the store’s transaction id, the date and the id of the account it was bought for, so that the same receipt cannot be applied to another account, and because the law requires payment records to be kept. The account it names no longer exists.
- Payment records. Stripe, Apple and Google keep their own records of a payment under their own legal obligations.
- Backups. Cloudflare keeps restorable copies of our databases for up to 30 days, so that they can be restored after a failure; they then expire.
- Server logs. These are deleted automatically after a short time.
9. Your rights
You can read and delete every design and image yourself, download any design, and delete your account, without asking us. Depending on where you live, you may also have the right to a copy of the rest of what we hold about you, to restrict how we process it, to object to processing we base on legitimate interests, to withdraw consent where we relied on it, and to move your data elsewhere. Write to support@krafical.com and we will answer within one month.
If you live in California or another U.S. state with a similar law, you have the right to know what personal data we hold about you, to delete it, and to correct it; the controls above do that. We do not sell or share personal data as those laws define the words, so there is no opt-out to offer, and exercising a right gets you the same service on the same terms.
If you think we have handled your personal data wrongly, you can complain to a data protection authority — in the EEA or the United Kingdom, the one where you live or work or where the problem happened; in Japan, the Personal Information Protection Commission. You are welcome to contact us first, but you do not need to.
10. Security
Every connection is encrypted in transit. Passwords are stored as hashes. Each user’s data is kept in its own isolated storage and is deleted with the account, apart from the records listed in section 8. The app keeps its sign-in token in the operating system’s secure store, never in a cookie. Credentials never enter our logs. If you find a security weakness, write to security@krafical.com and allow us time to fix it before you disclose it to anyone else.
11. Children
Krafical is not for anyone under 16, and we do not knowingly hold a child’s data. If you think a child has an account, tell us and we will delete it.
12. Changes
We may update this policy. When a change matters we will say so in the web app or the phone app, or by email. The date at the top is the version that stands.
13. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. support@krafical.com.