Accounts, waitlist, and campaigns: we store the email address you submit, account and subscription state, campaign work orders, Brand Passport and Product Truth records, creation/update times, and the source associated with a waitlist signup.
Generation inputs and outputs: prompts, campaign instructions, and supplied images are sent to Google Gemini when you request generation. Generated outputs, session history, version metadata, jobs, and costs are stored on the Photogen host. If you connect Figma and provide a file URL, read-only design context is incorporated into the prompt sent to Gemini; Figma access and refresh tokens are encrypted on the host and deleted from Photogen when you disconnect.
API keys: a Gemini API key you enter is stored in your browser's localStorage and transmitted to the Photogen server with provider-backed requests. Photogen uses it to call Gemini and is designed not to write it to application databases, request metrics, or logs.
Operational records: we record bounded request metadata such as method, route template, status, latency, random request identifier, job state, provider/model outcome, estimated cost, and alert inputs. These records are designed not to contain prompts, image bytes, provider keys, login tokens, or raw provider errors.
We do not train an AI model on your campaign inputs or outputs. Google processes generation inputs and outputs under the terms associated with the Gemini service and API key used for the request. Google's terms distinguish paid and unpaid services: unpaid-service content may be used to improve Google products and may be reviewed by people, while paid-service prompts and responses are not used to improve Google's products but may be retained for a limited period for abuse monitoring and required disclosures. Review the current Gemini API Additional Terms before submitting confidential or personal information.
Photogen does not include an advertising network or third-party behavioral analytics script. We do not sell or rent waitlist or account email addresses.
Application records and generated files for photogen.ashbi.ca are stored on infrastructure operated for Ashbi Design. Depending on the feature used, scoped data may also be processed by Google Gemini, Figma, the configured email provider, Stripe, GitHub/container infrastructure, and hosting or backup providers for generation, design context, authentication email, billing, deployment, hosting, security, and recovery.
Uploaded source files have a configured 30-day expiry and are removed by the scheduled retention job when it runs. Account, campaign, session, output, cost, waitlist, and billing records are retained until they are no longer needed to provide and operate the service or until an applicable deletion request is completed. Encrypted backups may retain copies until their configured backup-retention period expires. Provider copies are governed by the provider terms linked above.
You can request access to, correction of, or deletion of Photogen-held account data by emailing hello@ashbi.ca. We may need to verify that you control the relevant account before acting on a request. Some information may need to be retained where required for security, billing, dispute resolution, or legal obligations.
Photogen stores the application session token, optional Gemini API key, editor session identifier, and interface state in browser local storage. Clearing site data removes those browser-held values but does not by itself delete server-held account, campaign, or output records.
Photogen is not directed at children under 13 and we do not knowingly collect data from children.
If this notice changes, the "last updated" date below will be revised. Material changes may also be described in release notes or through an appropriate account communication.
Ashbi Design (Bianca + Cameron Ashley) · hello@ashbi.ca · Toronto, Canada
Last updated: 2026-08-28