Privacy Policy
Last updated: July 26, 2026 Β· Beta
What we collect
- Account data β your email address, display name, and (if you sign in with Google) the basic profile Google shares with us.
- Content you create β prompts, uploaded reference media, and generated results. Generations are private by default; they only appear in the community feed if you explicitly publish them.
- Usage & billing records β credit ledger entries, generation history, and the technical logs needed to run and debug the service.
How we use it
- To run the product: your prompts and reference media are sent to the AI model provider that powers the model you picked (for example fal.ai) solely to produce your result.
- To account for usage: credits, plan state, and generation history.
- To keep the platform safe: prompts may pass an automated content-moderation check before reaching a paid model provider.
- We do not sell your personal data, and we do not train models on your private content.
Third parties
- Model providers (e.g. fal.ai) process the prompts and media needed to fulfil a generation you request.
- Payment processing (when paid plans are enabled) is handled by Stripe β we never see or store your card number.
- Infrastructure: our database and media storage providers host data on our behalf under their own security commitments.
Face data & character training
- If you train a character, the photos you upload contain faces β under GDPR this is special-category biometric-adjacent data, and some jurisdictions (e.g. Illinois BIPA) regulate it separately. We treat it accordingly: training photos are used only to train your LoRA, are never used to train our own models, and are never shared beyond the training provider that runs the job.
- Training source photos are automatically deleted 30 days after training completes β after that, only the trained weights and one thumbnail (shown on your character card) remain.
- When you delete your account, all character data β remaining photos, thumbnails, and our references to trained weights β is hard-deleted, not just hidden. This deletion is not reversible.
Your controls
- You can delete any generation from your gallery; deleted items are removed from your library and the public feed. You can unpublish a shared generation at any time.
- You can download a copy of your data (account, generations, characters, comments, credit ledger) as JSON from Settings.
- You can delete your account directly in Settings. Deletion is scheduled with a 7-day grace period β log back in and cancel if you change your mind β and then permanently erases your content, uploads, face-training data, and profile. Questions or manual requests: privacy@nidhogg.ai.
Data retention
- Character training photos β deleted 30 days after training completes (or immediately on account deletion).
- Training upload packages β deleted 30 days after creation.
- Uploaded reference media β kept up to 180 days, then deleted.
- Moderation decision logs β kept up to 1 year as evidence for abuse investigations and legal requests, then deleted.
- Billing, payment, and credit-ledger records β retained after account deletion as required by accounting and tax law, linked only to an anonymized account skeleton (no name, email, or content).
- Everything else tied to your account β generations, uploads, profile, comments, agent history β is deleted when your account deletion completes.
Beta notice & contact
- Nidhogg is in closed beta. Features, plans, and this policy will evolve; material changes will be announced in-product.
- Questions or requests: privacy@nidhogg.ai.
