가입하면 프리미엄 플랜 할인할인 받기

Legal

Privacy policy

Last updated: October 1, 2026

In short

Your work is yours. We are humans too, and we treat it the way we would want ours treated:

  • We never sell your data. No resale, no ad networks, no data brokers, nothing weird.
  • We never train models on your prompts, references or creations.
  • Your creations stay private until you choose to publish them.
  • We keep logs to run eroq and keep it safe, so our team can see non-private prompts and creations in our internal tools. That is all they are used for.
  • Want nothing kept at all? Turn on Private mode: no file, no library entry, no prompt.

Our commitments

We do not sell, rent or trade your personal data or your content, and we do not share them with advertisers or data brokers. We do not use your prompts, references or outputs to train models, for advertising or for marketing.

Your creations are private to you, and to your workspace if you share one, until you publish them. We keep logs of non-private prompts and creations to operate and protect the service, and use them for nothing else: operating alerts, abuse and fraud investigations, the review of what you submit for publishing, the support requests you send us, and our legal obligations. Private mode keeps a render out of our storage entirely, as described below.

What we store

  • Account and workspace data — email, hashed credentials (via our auth provider), workspace names and members, credit balances, notification and email preferences.
  • API keys — a SHA-256 hash and a display prefix. Never the key itself.
  • The usage ledger — one row per charged generation: timestamp, model id, credit amount, request size, and the prompt you typed (the image or video prompt, the text read aloud, or the last message of a chat turn — capped at 2,000 characters). A Private-mode render keeps its ledger row with the prompt replaced by stars. We keep it to resolve billing disputes, investigate abuse reports and understand how the product is used. Storage uploads and refunds carry no prompt.
  • Your library — every image, clip and voice line you generate, from the Studio or through the API, is saved to your private library with its prompt and settings so you can find it again, remix it or publish it. Delete a creation and its file and record go with it.
  • Your references — photos you attach to a character or element sit in your private Store until you remove them; removing one deletes the file.
  • What you publish — publishing is opt-in, and every submission is reviewed by our team before it goes public. A published creation, with its title, cover and your public handle, stays public until you unpublish it. Likes, views and comments on it are kept with it.
  • Top-up and subscription records — pack or plan, amount, Stripe session and subscription ids, or for a crypto payment the NOWPayments invoice and payment ids and the coin used.
  • Support messages — what you send us through the support form.
  • Emails we sent you — which email and when, so that none is sent twice and none arrives too often.
  • Where your account was created — the IP address and country of your first request after signing up, kept on the account and never updated afterwards. We use it to spot several accounts opened from one connection to farm the free credits. We do not log the IP of your other requests.

Private mode

With Private mode on in the Studio (or private: true on the API), the render is handed straight back to you and nothing of it is written to our storage: no file, no library entry, no prompt on the job. Reference pictures travel inline with the request and never join the Store. The ledger row that bills the render carries stars instead of your prompt. Models marked « Private mode ✓ » retain nothing upstream either; the others may retain the prompt under their own terms, as the model picker says.

What we do not store

The model's replies in chat are streamed to you and not written to our database, and we keep no chat history: a charged chat turn leaves only its last user message in the ledger. Audio you send for transcription is processed in memory and not retained. We never see your card number.

Processors

Generations are fulfilled by vetted infrastructure providers acting as processors on our behalf, among them OpenRouter for some chat and image models and for the third-party video engines, and our database and sign-in run on Supabase. Providers receive only what a request needs — the prompt and any reference media (for a video: your cast's look sheets and, when sound is on, a cast member's voice sample) — and our own engines keep nothing once the job returns. Models without the « Private mode ✓ » badge — two optional image models and the third-party video engines (Seedance, Veo, Sora, Kling, Hailuo, Wan, Runway, Grok Imagine) — may retain prompts and reference media under their upstream provider's terms. Payments, email delivery, file storage and product analytics are handled by dedicated processors, and our team receives operational alerts, which include non-private prompts, on internal tools.

Emails

Account emails — sign-in links, password resets, receipts — go out whenever they are needed. Balance alerts and onboarding tips each have a switch in Settings → Notifications. We also send account holders occasional offers about eroq: a discount while it is live, bonus credits when a balance runs out, a reminder of a checkout left open. They rest on our legitimate interest in promoting our own service to our customers (article L34-5 of the French Postal and Electronic Communications Code); every one carries a one-click unsubscribe link, and the same switch lives in Settings → Notifications. Stopping them changes nothing else about your account.

Cookies and analytics

Signed-in pages use first-party session cookies for authentication, plus a cookie for your theme and pinned tools. We run first-party product analytics (PostHog) to count page views, sign-ups and generations by medium — no click recording, no advertising networks, no cross-site tracking.

A visit through an affiliate link (?ref=…) sets a first-party cookie that remembers the affiliate's code for 30 days, so an account created or signed in during that time can be attributed to them. Once the account is attributed (or cannot be), the cookie is deleted. The affiliate sees that a referral joined, with a masked email (« mi•••@gmail.com »), the plans it paid for and the commission earned, never who you are. Affiliates' own application and payout details are used only to run the affiliate program and to pay them.

Your rights

You can delete any creation from your library at any time, and the account itself from Settings → Danger zone: the account row, its keys, its library, its stored files and its ledger are erased on the spot. Payment records stay with our payment provider for as long as accounting law requires, and a one-way hash of the email is kept so a new account on the same address does not receive the welcome credits twice. Database backups held by our hosting provider roll over within 7 days, after which deleted data is gone from them too. One exception: a media removed for illegal content (child sexual abuse material above all) is preserved in a restricted quarantine, with its prompt, for the authorities, as the law requires — deleting the account does not remove it. Data export: [email protected].