Privacy Policy
Last updated · August 2, 2026
ANTEI is a bring-your-own-key AI gallery. This policy explains what we store, what leaves our servers, who processes it on our behalf, and the control you have over it.
What we store
We keep as little as the product allows and no advertising profile of any kind.
- Account details from Clerk when you sign in: an identifier, your email address, and any name or avatar you chose there.
- Generation records: prompts, model and provider chosen, parameters such as seed and resolution, timing, and success or failure.
- The files you generate or upload, and the collections, canvases and LoRA recipes you build from them.
- Credit balance and deduction history where a model runs on platform credits.
- Support messages you send us, and error reports (see «Error monitoring»).
Your API keys
Keys you connect are stored encrypted and used only to reach the provider you connected them for. We do not read them, resell capacity through them, or use them for our own generation. You can remove a key at any time, which stops it being used immediately.
What we send to AI providers
When you generate, the prompt and any reference material for that job are sent to the provider you selected, for example OpenAI, Google, fal.ai, ByteDance, ElevenLabs or Fish Audio. What they do with it is governed by their own policies, and some providers retain inputs for a period for abuse monitoring. We do not send them your account email or your archive.
Service providers we use
We rely on a small set of companies to run ANTEI. They process data on our instructions and only for these purposes:
- Clerk: authentication and account records.
- Neon: the application database.
- Cloudflare R2: storage and delivery of your generated and uploaded files.
- Vercel: hosting and request serving.
- Sentry: error and performance monitoring.
- The AI providers you connect or select, for the jobs you run.
Where your data is processed
These providers operate in several countries, so your data may be processed outside where you live, including outside the EEA and the UK. Where that happens we rely on the transfer safeguards those providers offer, such as standard contractual clauses.
How long we keep it
Files and generation records stay until you delete them or close your account. When you close an account we delete your files and records; backups holding copies roll off within 30 days. Credit and payment records are kept as long as accounting rules require. Error reports are kept for up to 90 days.
Cookies and local storage
We use cookies that keep you signed in and hold your language choice. We use no advertising or cross-site tracking cookies. The browser also stores some workspace state locally, such as canvas layout, panel sizes and drafts, which never leaves your device and clears when you clear site data.
Error monitoring
Sentry receives a report when something breaks: the error, the page, browser and version, and an account identifier so we can tell whether one person hit a problem or everyone did. Reports can include the URL you were on. We do not send prompts or generated files into error reports.
Session replay
Session replay (Sentry Session Replay) reconstructs what happened in the interface before a problem: clicks, navigation, console and network activity. It is off until you accept it in the privacy banner, and you can withdraw consent by clearing this site's data. All text is masked and all media blocked before anything is sent, so prompts, generated images and file names are never captured. We sample 1% of sessions and keep a replay for up to 90 days, alongside the matching error report.
Your rights
Wherever you live, you can ask us to do the following, and we answer within 30 days:
- Get a copy of the data we hold about you.
- Correct anything inaccurate.
- Delete an individual result, a whole collection, or your entire account.
- Export your files and generation records.
- Object to or restrict a particular use of your data.
- Complain to your local data protection authority if you think we got it wrong.
Children
ANTEI is not intended for children under 13, or under 16 in the European Economic Area and the United Kingdom, and we do not knowingly collect their data. If you believe a child has created an account, write to privacy@antei.app and we will remove it.
Security
Traffic is encrypted in transit, files are stored in access-controlled buckets, API keys are encrypted at rest, and access to production data is limited to what operating the service requires. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.
Changes to this policy
We update this policy as the product and its processors change. The date at the top reflects the current version, and we give notice in the product before a material change takes effect.
Contact
Data questions, access requests and deletion requests: privacy@antei.app.