Privacy Policy
This policy explains how GOREST INC, 745 S Bernardo Ave, Sunnyvale, CA 94087, USA ("Gorest", "we") handles your information when you use Gorest Sprite.
1. Information we collect
- Account data: your email address and authentication data, managed through Supabase Auth. We never see or store your password in plain text.
- Content: the prompts you write, images you upload, and the assets generated for you.
- Billing data: payments are processed by Stripe. We store only Stripe references (such as customer and session IDs) and your credit history — never card numbers.
- Technical data: IP address, request logs, and rate-limit counters used to operate and protect the Service.
2. How we use it
To provide the Service (including sending your prompts and reference images to our AI model providers, currently Google, to generate your assets, and storing your uploaded reference images in your private library so you can reuse them); to process payments and maintain your credit balance; to prevent abuse and secure the Service; and to communicate with you about your account. We may analyze content in aggregate (for example, which art styles are most popular) to improve the Service. We do not sell your personal information, and we do not use your content to train our own models.
3. Service providers
We share data only with the processors needed to run the Service: Supabase (authentication, database, file storage), Railway (hosting), Stripe (payments), and Google (image-generation API). We may also disclose information if required by law.
4. Storage and retention
Data is processed and stored in the United States. Your generated assets and account data are kept while your account is active. You can request deletion of your account and data at any time (see Section 5).
5. Your rights
Depending on where you live (including the EU/EEA under GDPR and California under CCPA/CPRA), you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. We honor these requests for all users: email official@gorest.ai and we will respond within 30 days. We do not sell personal information, so there is nothing to opt out of under CCPA "Do Not Sell".
6. Security
Traffic is encrypted with TLS. Stored assets live in private buckets accessed through short-lived signed URLs, and database access is isolated per user. No system is perfectly secure; please use a strong, unique password.
7. Cookies and local storage
We use only what is necessary to keep you signed in (authentication tokens in your browser's local storage). We do not use advertising or cross-site tracking cookies.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information.
9. Changes
We may update this policy from time to time; material changes will be announced in the app. The "Last updated" date above always reflects the current version.
10. Contact
GOREST INC · 745 S Bernardo Ave, Sunnyvale, CA 94087, USA · official@gorest.ai