Legal
Privacy Policy
Last updated 31.07.2026
1. Controller
The controller responsible for processing your personal data under the General Data Protection Regulation (GDPR) is Rods & Cones. You can reach us at support@rodsandcones.ai.
2. What we process and why
We only process the data needed to run the service:
- Account data: your email address and the identifier from your chosen sign-in provider, used to create and secure your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Uploaded images: the images you submit and the upscaled results, stored so we can process and return them to you. Legal basis: Art. 6(1)(b) GDPR.
- Usage & job data: job status, latent balance, and timestamps, used to operate your account and prevent abuse. Legal basis: Art. 6(1)(b) and our legitimate interest in a secure service (Art. 6(1)(f) GDPR).
- Payment data: handled by our payment provider (see below). We receive your subscription status, not your card details. Legal basis: Art. 6(1)(b) GDPR.
- Server logs: including IP address and request metadata, retained briefly for security and debugging. Legal basis: Art. 6(1)(f) GDPR.
- Product analytics: which pages you visit, where you arrived from, and which elements you interact with, used in aggregate to understand and improve the service. This is measured without cookies or any storage on your device, and we do not build a cross-session profile of you. Legal basis: our legitimate interest in improving the service (Art. 6(1)(f) GDPR).
3. Processors and third parties
We use the following processors, each under a data processing agreement. Several are based in the United States; transfers rely on EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
- Supabase: authentication and database (account, job, and balance data). This data is hosted in the EU-West region.
- Cloudflare R2: private object storage for your uploaded and upscaled images.
- Modal: GPU inference; your image is processed here to produce the upscaled result.
- Polar: our payment provider and merchant of record; handles checkout, billing, invoices, and tax.
- Vercel: application hosting and delivery.
- PostHog: cookieless product analytics, hosted in the EU. Receives page visits, referrer, and interaction events — never your images or their contents.
- Google / GitHub: only if you choose them to sign in (OAuth).
- Microsoft / Outlook: delivery of sign-in and account emails.
4. Cookies and local storage
We use only strictly necessary cookies, namely the session cookie that keeps you signed in and protects against cross-site request forgery. These are exempt from consent under § 25(2) TDDDG, so we do not show a consent banner. We do not use advertising or third-party tracking cookies.
Our product analytics (see above) is deliberately cookieless: it stores nothing on your device — no cookies, no local storage — so it too falls outside the § 25 TDDDG consent requirement. Because we set nothing on your device for any non-essential purpose, there is no consent banner to show. Should we ever introduce cookies or device storage that are not strictly necessary, we would ask for your consent first.
5. Retention
We keep account data for as long as your account exists. Uploaded images and their upscaled results stay in private storage until you delete the job from your dashboard, which removes both the original and the result. There is no automatic expiry beyond that today. We delete or anonymize data once it is no longer needed for the purposes above or to meet a legal retention duty.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate data (Art. 16);
- erasure (Art. 17) and restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21); and
- lodge a complaint with a supervisory authority, which in our case is Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany.
To exercise any of these, email support@rodsandcones.ai.
7. Security
Data is encrypted in transit, image storage is private and not publicly listable, and access to the database is restricted by row-level security so you can only reach your own records.
8. Changes
We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above and, where required, communicated to you directly.