MAI Image

Privacy policy

Last updated: August 30, 2026

This policy explains how MAI Image (“we”, “us”) handles personal data when you use MAI Image.

Information we collect

Account data. Google sign-in provides your Google account identifier, name, email address, and profile image. We store these so you can access your account and history.

Product data. We store prompts, lyrics and other submitted text, generation settings, model choices, status, credit usage, and result links. Do not submit sensitive personal information in prompts, lyrics, or reference media.

Temporary browser drafts and request recovery. When you start sign-in with an editing or generation form open, its current text, settings, and already-uploaded media references can be kept in this browser for up to 30 minutes so they can be restored after authentication or when you return without signing in. Sign-in drafts are removed when restored, and expired drafts are removed by the open page or on a later visit. Raw files selected from your device are not copied into this sign-in storage.

Duplicate-safe image request recovery. For MAI Image requests, this browser tab stores an account-scoped request key, a cryptographic fingerprint of the submitted settings, and a task reference when available. This recovery record does not contain the raw prompt or reference-image URLs. It allows an identical retry to reuse the same logical request after an uncertain response. The record is cleared after a confirmed terminal result or after you explicitly confirm that you checked account history and want to start a separate request. It is kept in session storage rather than persistent local storage.

Billing data. Stripe processes payment details. We receive customer, subscription, invoice, payment-status, country, tax, and transaction identifiers, but not full card numbers.

Technical and analytics data. Essential logs may include IP address, browser details, timestamps, security events, and errors. If you consent, Google Analytics 4 and Microsoft Clarity may collect page use, interaction, device, and session data. Clarity may provide privacy-filtered session replay and heatmaps.

How and why we use data

We use data to provide and secure accounts, process generation and payments, maintain credit balances, prevent abuse, troubleshoot failures, support customers, measure product performance, and meet legal or tax obligations. Where applicable, our legal bases include performing our contract, legitimate interests in security and service improvement, consent for optional analytics, and compliance with law.

Processing partners and international transfers

We share only what is needed with Google for authentication and optional analytics, Stripe for billing, Microsoft for optional Clarity analytics, and the hosting, database, and generation-processing partners needed to operate the service. These partners may process data in other countries under their terms and legally recognized transfer safeguards.

Retention

Account and product records are kept while your account is active. Generation result links can expire under storage rules. Security logs are normally kept only as long as operationally needed. Billing and tax records may be retained for the period required by law. After a valid deletion request, we delete or anonymize data that is not legally required.

Cookies and controls

Essential cookies maintain your session and choices. A random first-party browser identifier counts approved public-page visits and generate-button clicks on our service without prompt text, media or generation settings. After consent, optional GA4 and Clarity load only on approved clean public pages while you are confirmed signed out and have not started using the workspace. An explicit whole-document mask applies before Clarity loads. Signing in, interacting with a form or workspace, restoring a private draft, or receiving private media stops optional providers before that content is displayed and keeps them off for the rest of that document. Private pages, URL queries/fragments and unverified sessions do not load these providers; unsafe incoming referrers also disable Clarity. Vendor events contain registered names and canonical locations, not prompts, filenames, media URLs or custom properties. Advertising features remain off. Resetting consent clears only optional analytics cookies and reloads a measured document; other open tabs receive the withdrawal. First-party attribution retains only an approved public pathname and no referrer.

Your rights

Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection, and may withdraw analytics consent. You can submit deletion from the account page or email support@mai-image.pro. We may need to verify your identity. You may also complain to your local data-protection authority.

Children

The service is not directed to children under 13, and users must be old enough to enter a binding contract in their jurisdiction.

Security and changes

We use access controls, secured session cookies, server-side credentials, signed Stripe webhooks, and encrypted transport. No system is completely secure. Material policy changes will be posted here with a new effective date.

Contact

Data controller: MAI Image. Privacy questions: support@mai-image.pro.