Scope
This policy covers the hosted Inochi2D Web Creator atinochi2d.blendduck.com, including account, billing, project storage and Project Data Sharing. Local files that never enter a cloud project remain under your browser and operating-system controls.
Information we process
- Account identity: name, email address, profile image and provider identifiers returned by Google sign-in.
- Billing state: Stripe Customer and Subscription identifiers, plan, status and renewal boundaries. Card numbers are collected and held by Stripe, not this application.
- Project data: project name, members, revision ancestry, byte length and integrity hashes in D1; native INX revision bytes in R2.
- Operational data: bounded security, error and request metadata needed to operate and protect the service. Provider secrets and model bytes are not written to application logs.
How information is used
Information is used to authenticate accounts, enforce subscription access, save and recover native project revisions, prevent stale overwrites, fulfill owner-managed sharing, investigate abuse and keep the service reliable. It is not used to train generative models.
Service providers
Google provides account authentication, Stripe provides hosted billing, and Cloudflare provides the application runtime plus D1 and R2 storage. Each provider processes data under its own terms. Project members see project data only after an owner invitation to the exact signed-in email.
Retention and deletion
Current and historical native revisions are retained to provide Version History until the project or account deletion workflow removes them under the active retention policy. Billing records may be retained where required for accounting, fraud prevention or legal obligations. The production retention schedule remains a release gate and will be published before paid access is enabled.
Security and choices
Access is checked before storage reads and again when advancing a project head. Revision conflicts fail closed. You can export native project data, revoke members, manage billing in Stripe and revoke Google access. No system is perfectly secure; suspected account compromise should be reported through the support channel shown in the signed-in Dashboard.
Changes and contact
Material changes will update the effective date and, when appropriate, appear in the product before taking effect. Privacy questions can be submitted through the support channel in the account Dashboard. This policy will receive legal review before public paid launch.