Privacy Policy
Effective and last updated: September 24, 2026
This Privacy Policy explains how MachineWill, LLC (the Operator) handles information for the Erase website at erasephoto.com, its web tools and purchases, cloud processing APIs, and support pages. The Erase iOS and Android apps are covered by the separate app Privacy Policy. Contact forkable0@gmail.com for privacy questions or requests.
1. Information Erase handles
- Account and identity data: a Supabase user UUID created for anonymous use; anonymous status; authentication sessions; profile name, image, locale, and Pro entitlement state when present.
- User Media and editing input: photos, videos, image dimensions and media type; brush or lasso strokes, masks, selected regions, and requested tool settings. On-device Beautify and Add Watermark work locally. Cloud tools transmit the necessary media and editing input to the Erase API and the applicable AI processor.
- Jobs and results: job UUID, account UUID, job type, status, timestamps, provider request ID, credit cost, error or cancellation state, generated images or videos, thumbnails, and private storage references. Result links returned to the app are signed URLs that expire after one hour.
- Purchases and rewards: product and entitlement identifiers, purchase, renewal, cancellation, expiration, restore, transaction and original-transaction identifiers received through Apple and Superwall; credit ledger entries; rewarded-ad event UUID, ad unit identifier, grant source, and timestamp.
- Push and device data: Expo push token, platform, token update time, and normalized language preference; app release metadata included with diagnostics; network information such as IP address and user agent that Cloudflare may process to deliver and secure requests. For rewarded-ad fail-open abuse control, Erase stores a short-lived SHA-256 fingerprint of Cloudflare's trusted client IP in a rate-limit counter, not the raw IP.
- Local data: authentication session, language and preference values, credit/subscription cache, up to five editor history images per saved editor context, source/result copies needed to resume an edit, and temporary export or download files. These remain on your device until the app or account data is cleared, the operating system removes temporary cache, or you delete the account.
2. Why we use this information
We use it to authenticate users; run requested edits; create and privately deliver results; show Works; enforce input, rate, credit, and entitlement rules; process cancellations and exactly-once refunds; restore purchases and synchronize subscription state; deliver requested completion notifications; provide rewarded-ad grants; prevent fraud, replay, and abuse; diagnose failures; answer support and privacy requests; and comply with law.
3. Processors and destinations
- Cloudflare hosts the public site and Worker API, routes requests, and provides network and security controls.
- Supabase provides authentication, the Postgres database, and the private
uploadsstorage bucket for account-linked results and thumbnails. - PostHog receives a pseudonymous landing-page visitor ID in
seo:<uuid>form, the landing-page path,$pageviewevents, and attributed purchase count and revenue amount for product and revenue analytics. - FAL receives media and, where needed, masks or edit instructions for cloud detection, object/watermark removal, background removal, upscaling, de-AI image editing, and video processing. For Naturalize AI, Erase sends the source image directly to FAL for GPT Image 2 editing.
- OpenRouter receives text prompts and related text request data only when an optional OpenRouter-backed text-generation API is invoked. It is not used for Naturalize AI, and Erase does not send source images to OpenRouter.
- Superwall receives the Erase account UUID, paywall placement/context, and purchase or entitlement events to present paywalls, restore purchases, and synchronize Pro status.
- Apple and StoreKit process App Store purchases, subscription management, restoration, and refund requests. The Operator does not receive full payment-card details.
- Google AdMob serves rewarded ads and processes ad/device signals and ad interactions. For server-side reward verification, Erase sends a one-time opaque reward-session UUID as both
user_idandcustom_data; it does not send the stable Supabase account UUID. Google returns the ad-unit numeric suffix, reward values, callback timestamp, transaction ID, opaque session values, signature, and verifier key ID. Erase maps the session back to the account, verifies the signature and exact session binding, and records the transaction/session result to prevent duplicate grants. Erase asks AdMob for personalized ads only when both apply: Google's consent flow permits personalized ads, and on you allowed tracking in the App Tracking Transparency prompt. In every other case, including no answer yet, the request is non-personalized. On the ATT prompt appears immediately before the first rewarded ad, not at launch, and your current answer is re-read before each later ad. Where Google's consent flow applies, its form is shown before that. - Expo Push Service receives push tokens and notification payloads to deliver job-completion notifications.
Sentry diagnostics: Sentry is enabled for diagnostics. It receives crashes, errors, performance traces, touch breadcrumbs that identify the component and source file but not input contents, and purchase-flow breadcrumbs that may include a product ID and error message. Server-side error events may include the anonymous Supabase user UUID, request route, and Cloudflare cf-ray request ID. Mobile Sentry events are also associated with the same anonymous Supabase user UUID and an anonymous user segment. We use this information to diagnose reliability and purchase-entitlement failures, not for product analytics.
4. Sale, advertising, and tracking choices
We do not sell User Media or personal information. We do not use User Media to build advertising profiles. Rewarded ads are optional: you can use the initial allowance, watch a rewarded ad to add one credit, or purchase Pro. Denying ATT permission does not remove core editing access; Apple and AdMob may still process limited device, network, fraud-prevention, and contextual-ad information permitted without tracking authorization. You can change tracking permission in Settings.
5. Retention
- Request bodies, masks, and strokes: the Operator processes them in memory and does not persist them as separate database records after the request. Each provider may retain only the request data it actually receives under its own service terms: FAL may receive cloud-edit media, while OpenRouter receives only applicable optional text-generation request data and no Naturalize AI source image.
- Successful Works, generated media, thumbnails, and job records: retained in private Supabase storage and the account database until you delete the Erase account. Erase is not a permanent backup; keep originals and exported copies.
- Signed result URLs: expire after one hour, although the private underlying file remains until account deletion.
- Cancel-before-submit intent: purged after 10 minutes. Non-video image jobs still processing after 15 minutes are failed and refunded. Video reconciliation stops after a one-hour processing deadline.
- Rate-limit counters: hashed fail-open IP scopes and request counts are short-lived operational records and are removed by the shared stale-counter cleanup; raw IP addresses are not stored in these rows.
- Account, credits, subscriptions, rewarded-ad events, and push tokens: retained while the Erase account exists. Invalid push tokens are removed when the push service reports that they are no longer registered.
- Account-deletion recovery state: retained only while automatic cleanup is incomplete. The scheduler retries cleanup and removes the recovery row when private files are gone and the Supabase identity is confirmed deleted.
- Webhook integrity records: on deletion, account identifiers and provider payloads are cleared. A provider event ID, event type, processing status, timestamps, and error state may remain to prevent duplicate processing and document system integrity.
- Apple purchase records and processor copies: retained independently by Apple or the relevant processor under its own legal obligations and retention policy.
6. Security and private access
Cloud APIs require a Supabase bearer token. Jobs are scoped to the account UUID. Result files are stored in a private bucket and delivered through short-lived signed URLs. Service keys remain server-side. No method of storage or transmission is perfectly secure, and you should not upload media that you are not permitted to send to the processors listed above.
7. Deletion and privacy requests
When signed in on the website, open Settings and choose Delete Account to delete the account identity and profile, Works and result files, and the job, credit, order, and subscription records Erase holds for the account. Cleanup failures are retried automatically. Deletion cancels future renewal of a website subscription but does not refund an existing charge. To cancel a subscription without deleting the account, choose Manage billing with Stripe on the Billing page to open the Stripe customer portal.
You may also email forkable0@gmail.com to request access, correction, deletion, restriction, objection, or portability where applicable. Include only the account email or anonymous account UUID needed to locate the request; do not email User Media, passwords, or payment credentials. We may need to verify control of the account before acting.
8. International processing, children, and changes
The processors listed above may handle information in countries other than yours. Their contractual and legal safeguards apply to those transfers. Erase is not directed to children below the minimum age required to consent to data processing in their jurisdiction. If you believe a child submitted data without valid authorization, contact us.
We may update this Policy when the product, providers, retention, or law changes. Material changes will be posted here with a new effective date and, when appropriate, communicated in the app.
9. Contact
Operator: MachineWill, LLC
131 Continental Dr, Suite 305, Newark, DE 19713, United States
Email: forkable0@gmail.com
Support: Erase Support
Stripe web payments
Stripe processes web checkout, billing details, payment methods, taxes, fraud controls, subscription management, and refunds. Erase sends the account identifier, selected plan, price, currency, and account email when present. Stripe returns customer, checkout-session, payment-intent, charge, invoice, subscription, price, status, and billing-period data. Erase stores those identifiers and lifecycle records to grant Pro, prevent duplicate webhook processing, manage cancellation and refunds, and answer support requests. Erase does not receive or store full payment-card details. Account-linked Stripe purchase records are removed on Erase account deletion; non-identifying event IDs and processing status may remain for replay prevention and system integrity, while Stripe retains its records under its legal obligations and policy.