This policy describes the information used by the Maxsa website and creative studio. It will be updated when the service or its data practices change.
01Information we handle
When you create or use an account, we handle your email address, account identifier and sign-in records. If you choose Google sign-in, the information returned by Google includes your account identifier, verified email and profile name.
Creative inputs include prompts, settings and any reference image you submit for generation. Generation records can include a task identifier, model, prompt, status, timestamps and output. When you contact support, we receive the information and attachments you choose to include.
Connection information, such as an IP-derived identifier, is used for sign-in abuse prevention. Do not put passwords, API keys, financial details or confidential documents into prompts or support messages.
02Why we use this information
We use information to authenticate you, run the tools you request, show generation status and results, prevent misuse, troubleshoot problems and respond to your messages. Required information is used to provide the requested feature; choosing not to provide it can make that feature unavailable.
03Services that process information
Maxsa uses external services to deliver specific features:
- AI generation services: process prompts, generation settings and reference images needed to create your images and videos.
- AI planning services: process prompts, conversation context and any reference images you attach for creative planning and prompt assistance.
- Google: handles Google sign-in when you choose that option.
- Email delivery services: processes the recipient email and message required to deliver a sign-in code.
- Vercel and Supabase: host the website, backend, account records, credit ledger and private generated media.
- Stripe: processes checkout, subscriptions and payments. Maxsa stores order references and credit records, not full card numbers.
- Google Analytics: measures website visits and interactions. Maxsa’s page-view code excludes URL queries, prompts, email addresses, sign-in codes and checkout tokens.
- Google Fonts: the current site loads fonts from Google, which receives the associated browser request.
Providers apply their own data handling terms, including retention and any model-related use. Maxsa does not promise that every provider immediately deletes inputs or never uses them for improvement. Check the relevant provider policy before submitting sensitive material.
04Cookies and browser storage
Essential cookies keep you signed in and protect authentication flows. The current sign-in session expires after seven days; temporary authentication flows have shorter lifetimes.
Your browser keeps recent generation references and prompts in local storage so you can revisit results, and temporary email verification state in session storage. Clearing browser storage removes those local references but does not by itself delete server records or media. Blocking essential cookies can prevent sign-in from working.
05Storage, retention and security
Account records, the credit ledger and generation records are stored in Supabase Postgres. Completed media is held in private Supabase Storage. Uploaded reference bytes are passed to the chosen AI provider and are not kept as part of the job record. External providers may retain their own copies under their policies.
There is currently no automatic deletion schedule for completed media or account records. Request deletion by contacting support; payment records may need to be retained for accounting or dispute handling. Access to a result is checked against your account before a download link is issued. Download links expire after five minutes; anyone you share one with may access it until then. Download a copy of work you want to keep.
We use measures such as protected session cookies and hashed authentication tokens. No storage or transmission system can be guaranteed completely secure.
06Your choices and requests
You can stop using a tool, clear local browser data, sign out, or ask us to help access, correct or delete your information. Contact support@maxsa.ai from the email associated with your account and describe your request. We may need to verify account ownership before acting.
Depending on where you live, you may have additional rights to object, restrict processing, receive a copy of your information or raise a concern with a relevant authority. Some records may need to be retained to meet legal obligations or resolve a dispute. Provider-held data is subject to the provider’s processes.
07Children and international processing
Maxsa is intended for adult creators. The Kids Story tool helps adults make stories for children; it is not a child account service. Do not submit children’s personal information. Contact us if you believe such information has been provided.
External services may process information in countries outside your location. Use of a feature can involve the international processing described in that provider’s terms.
08Invitations and creator rewards
If you use an invitation or participate in creator rewards, we keep the invitation attribution, qualifying purchase and creation references, submitted public links, review decisions and credit records. Invitation cookies last up to 7 days. A signed browser identifier lasts up to 90 days and helps flag repeated claims. We compare keyed hashes of network, email and payment-method identifiers to detect duplicate claims; we do not store full card numbers. Shared networks alone do not disqualify a participant.
Submitted public profiles and content may be checked by an authorized reviewer for ownership, originality and eligibility. Network and browser signals are removed after 90 days of inactivity or attribution age during reward maintenance. Identity, payment-association and reward records remain as needed to prevent repeat claims and handle accounting, appeals or disputes. Contact support to ask about or correct your reward records.
09Updates and contact
We will update the date on this page when this policy changes. Material changes will be explained before a newly introduced feature collects information in a different way. Questions about privacy or data requests can be sent to support@maxsa.ai.
