Legal

Privacy Policy

Last updated: March 2026

This policy describes how Identity Market collects, uses, and stores personal data when you use our platform. It applies to all users, including subscribers and creators.

This Privacy Policy describes how Identity Market (“we”, “us”, “our”) collects, uses, and stores personal data when you use our Platform. By using the Platform, you agree to the practices described in this policy. This policy is supplemental to our Terms of Service.

1. What We Collect

We collect the following categories of data:

  • Account information: Name, email address, password (hashed), account role, and registration date when you create an account.
  • Payment data: Payment is processed by Stripe. We do not store card numbers or full payment details. We receive and store subscription status, billing period data, Stripe customer IDs, and transaction records for our own accounting.
  • Usage data: API request logs including timestamps, identity accessed, generation parameters, output metadata, and usage counts. This data is used for billing, enforcement, and audit purposes.
  • Creator submissions: Identity configurations, workflows, prompt templates, preview images, and associated metadata submitted by creators to the Platform.
  • Technical data: IP addresses, user agent strings, session tokens (stored as httpOnly cookies), and access logs collected automatically when you use the Platform.

2. How We Use It

  • Provide the Platform: Authenticate your account, issue and validate API keys, meter API usage against subscription limits, and deliver generated outputs.
  • Process payments: Manage subscriptions, handle billing lifecycle events via Stripe webhooks, and process creator payouts.
  • Enforce our Terms: Detect and investigate policy violations, rate limit abuse, and fraudulent activity. Respond to valid legal requests.
  • Communicate updates: Send service notices, billing confirmations, and material policy change notifications. We do not send marketing emails without your consent.

3. How We Store It

  • Account, access, and subscription data is stored in a PostgreSQL database hosted on secure cloud infrastructure.
  • Identity configurations and generated outputs are stored in S3-compatible object storage (AWS S3, Cloudflare R2, or equivalent) with private access controls. No assets are publicly accessible.
  • Generated images are retained for 90 days following creation, after which they are deleted from storage.
  • We do not sell, rent, or share your personal data with third parties for their own marketing or commercial purposes.

4. Third-Party Services

We use the following third-party services to operate the Platform. Each has its own privacy policy.

  • Stripe — Payment processing and subscription management. Stripe may collect and process your payment card data and billing address directly. See stripe.com/privacy.
  • Replicate / hosted inference provider — Generation requests are routed through our inference infrastructure. Prompts and generation parameters may be transmitted to the inference provider for processing.
  • Cloudflare / AWS — Infrastructure, CDN, and object storage. These providers process traffic and store assets on our behalf under data processing agreements.
  • Sentry — Error monitoring. Application errors and stack traces (which may include request metadata) are sent to Sentry for debugging. We configure Sentry to scrub sensitive data before transmission.

5. Your Rights

Depending on your jurisdiction, you may have the right to request access to the personal data we hold about you, request correction of inaccurate data, request deletion of data that we no longer need to retain, or request a portable export of your account data. To exercise these rights, contact us at legal@identity-market.com.

We will respond to verifiable requests within the timeframe required by applicable law, usually within 30 days. We may ask you to verify your identity before we process a request, and we may retain limited records where retention is required for tax, accounting, fraud prevention, or legal compliance purposes.

6. Cookies

We use a limited set of essential cookies to operate the Platform. We do not use advertising or tracking cookies. For details, see our Cookie Policy.

7. Data Retention

  • Account data: Retained while your account is active and for 30 days following account deletion, after which it is permanently removed from our systems (except as required by law).
  • Generation history: API usage records and generation metadata are retained for 90 days.
  • Payment records: Transaction records are retained for 7 years in accordance with financial record-keeping obligations.
  • Creator assets: Identity configurations are deleted within 30 days of a creator terminating their participation in the creator programme, unless retention is required by applicable law or ongoing legal proceedings.

8. Contact

For privacy-related enquiries, data subject requests, or questions about this policy, contact us at privacy@identity-market.com.