Skip to content
Undress Design
HomeGenerateUndressClipAbout
18+ only
...credits
Checking account
HomeGenerateUndressClipAbout
Privacy

Privacy Policy.

Effective August 22, 2026 · Version privacy-2026-08-22

Privacy at a glance
  • The Service is for adults and original fictional characters only.
  • Prompts and media are processed to generate, moderate, secure, and preserve requested history.
  • Customer content is not sold, used for targeted advertising, or used to train AI models.
  • Encrypted generation content currently has no automatic time-based expiry.
  • You may request access, correction, deletion, or other rights through Contact support.

This summary does not replace the complete Policy below.

Development operator notice

The verified legal name, registration details, physical address, governing jurisdiction, and dedicated privacy contact for the person or entity controlling this development deployment have not been supplied in the repository. “Operator” below means that person or entity. These verified details and any required local representative or data protection officer must be added before public launch.

1. Scope and role

This Policy describes how the Operator processes personal data when you visit or use Undress Design, including its generation, editing, clip, account, payment, history, analytics, moderation, support, and reporting features (the “Service”). It applies to registered users, guests, support requesters, and people who make a privacy or safety report.

The Operator generally decides why and how Service data is processed and acts as its controller or equivalent. Service providers process data under their own terms and the Operator’s instructions where applicable. External payment and identity providers may also act as independent controllers for data you give them directly.

2. Data we process

  • Account data: email address, internal user ID, password hash, Google account ID when used, verification status, account dates, country code at registration, accepted Terms version, credits, and account status.
  • Authentication and security data: session and verification records, IP address, user agent, login activity, rate-limit data, pseudonymous guest identifiers, and security or administration events.
  • Generation data: prompts, negative prompts, settings, uploaded images, generated images or clips, private previews, file type and size, hashes, model, job identifiers, status, and credit use.
  • Moderation data: automated decisions, reason codes, policy and model identifiers, scores, timing, detected-person and face information, and apparent-age estimates or ranges.
  • Transaction data: selected package, price, currency, payment provider, order and payment identifiers, status, settlement callbacks, gift-card fingerprints, and credit ledger entries. The Service does not receive full card or wallet credentials entered on a provider’s checkout page.
  • Support data: email address, case ID, category, subject, messages, reference IDs, status, and access-token or assignment records.
  • Technical and analytics data: page path, coarse events, referrer and allowed campaign parameters, browser, device, operating system, language, screen data, performance measurements, IP-derived location, and request logs.

Data comes from you, your browser or device, the Service’s automated systems, and authentication, generation, moderation, email, payment, analytics, and security providers. Do not submit confidential information or personal data about another person.

3. Why we use data

The Operator processes data only as reasonably necessary to:

  • create and secure accounts, authenticate users, and provide requested features;
  • generate, edit, deliver, store, restore, and delete requested content;
  • moderate content, protect adults and minors, enforce the Terms, prevent fraud or abuse, and investigate reports;
  • administer credits, payments, refunds, support, and Service communications;
  • measure reliability and coarse product use, diagnose errors, and improve performance;
  • comply with law, lawful process, accounting duties, and legal claims; and
  • protect the rights, safety, and security of users, the Operator, providers, and others.

Where the GDPR, UK GDPR, or similar law applies, the usual legal bases are performance of a contract, compliance with law, and the Operator’s legitimate interests in operating and securing the Service. Consent is used where required, including for optional sensitive analytics or particular sensitive-data processing, and may be withdrawn without affecting earlier lawful processing. If data is required to provide a requested feature, that feature cannot work without it.

4. Sensitive content and AI processing

Prompts and media may be highly sensitive and may reveal or allow an inference about a person’s body, age, health, race or ethnicity, sex life, or sexual orientation. The Service does not request personal data in order to identify a real person and permits only original fictional adults. Real-person likenesses, minors, and non-consensual intimate imagery are prohibited even if an uploader claims consent.

Content is transmitted to generation and moderation infrastructure as needed to perform the request. The Service does not use customer prompts, uploads, or outputs to train AI models, and its infrastructure providers are engaged to process that content to provide the requested operation, maintain security, or comply with law. Authorized staff may access retained sensitive content only through restricted, purpose-bound and audited administration workflows.

5. Automated moderation

Automated systems may inspect prompt text and images, detect people and faces, estimate apparent age, apply safety classifiers, and allow or block a request. A blocked request may be preserved as a zero-credit safety record and may remain available to authorized reviewers while the customer sees only a limited reason. These systems reduce risk but may be inaccurate and do not guarantee detection of every violation.

A moderation block affects access to that generation operation; it is not used for employment, credit, housing, insurance, health care, or another legally significant third-party decision. You may contest a decision through Contact support.

6. Service providers and disclosures

The Operator may disclose limited data to:

  • Modal and RunPod for AI generation, moderation, job execution, and related infrastructure;
  • Google for optional OAuth account access;
  • Resend or a configured SMTP provider for authentication, deletion, support, and transactional email;
  • Stripe, MotionArt, NOWPayments, Platega, RuKassa, and Rewarble for available hosted card checkout, settlement brokering, payment, legacy-order, and gift-card features;
  • ipwho.is for a one-time registration-country lookup, after which the Service stores the country code rather than a separate raw registration-IP record;
  • self-hosted PostgreSQL, MinIO, and Umami services and the Operator’s hosting providers for database, encrypted object storage, delivery, and analytics;
  • professional advisers, auditors, insurers, a successor in a merger or asset transaction, and authorities or other recipients when reasonably necessary and lawful.

The Operator does not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. Data may be preserved or disclosed to investigate abuse, protect a person, respond to valid legal process, establish or defend claims, or make legally required reports. Providers’ own sites and checkout pages are governed by their privacy notices.

7. Storage and retention

  • Generation content: encrypted prompts and successfully captured private input, output, and history media currently have no automatic time-based expiry. They remain until an available customer or administrator deletion or account-erasure process removes them, subject to legal preservation and deletion retries.
  • Account deletion: a verified request blocks access immediately and normally schedules erasure after a seven-day recovery period. Direct identity and generation ciphertext are then erased; pseudonymous financial, credit, generation, moderation, deletion, and security evidence may remain where necessary for accounting, abuse prevention, legal claims, or system integrity.
  • Sessions and tokens: browser login sessions expire no later than seven days. Sign-in codes normally expire after ten minutes and password-reset links after thirty minutes.
  • Support: support cases are normally assigned a two-year retention date, but linked conversations may be erased with the account where applicable.
  • Analytics and logs: session replay, if enabled, is retained by Umami for up to thirty days. Aggregate analytics, operational logs, and immutable security events are kept until deleted or anonymized under the Operator’s operational, security, and legal retention requirements.
  • Payments: transaction and accounting records may remain for the period required by tax, accounting, anti-fraud, chargeback, and legal-claims rules.
  • Backups and providers: residual copies may remain in protected backups or provider systems until their normal overwrite or deletion cycle, unless preservation is legally required.

Deletion may be delayed where verification is incomplete, another person’s rights would be affected, or law permits or requires retention. Pseudonymized records are not represented as fully anonymous.

8. Cookies, browser storage, and analytics

The Service uses strictly necessary authentication and security cookies. It uses session storage for payment-return state and local storage for an unregistered support requester’s private case-access token. Removing these values may sign you out, remove checkout context, or prevent access to a guest support case.

Self-hosted Umami analytics may collect cookie-free pageviews, coarse events, campaign attribution, device data, and performance measurements. Prompts, emails, raw user IDs, filenames, and media URLs are excluded from ordinary event data. Optional replay and heatmaps are more sensitive: when enabled, they may capture visible text, non-password form values, images, fonts, and canvas on allowed public routes. Password inputs remain masked, URLs are sanitized, and configured Do Not Track and Global Privacy Control signals are honored for the recorder. Where law requires consent, optional recording must not begin before valid consent.

9. International transfers

The Operator and providers may process data in countries other than the one where you live, including the United States and countries where hosting or GPU capacity is available. Where required, transfers rely on an adequacy decision, contractual safeguards such as standard contractual clauses, a recognized certification, or another lawful mechanism. You may ask for information about applicable safeguards through Contact support.

10. Your choices and rights

Depending on where you live, you may have rights to know or access data, obtain a portable copy, correct it, delete it, restrict or object to processing, withdraw consent, opt out of sale, targeted advertising or qualifying profiling, limit certain sensitive-data uses, appeal a refusal, and complain to a regulator. The Operator does not discriminate against a person for exercising a privacy right.

Use available account controls or submit a privacy or deletion request through Contact support. Guests and people depicted or referenced by another user may also use Contact support and should provide only the minimum case or generation reference needed to locate the material. The Operator may verify identity or authority, reject excessive or unlawful requests, and retain evidence of the request. An authorized agent may act where local law permits and required authority is provided.

11. Regional disclosures

EEA, United Kingdom, and Switzerland. You may exercise the rights described above and complain to the supervisory authority where you live or work. Special-category data is processed only where an applicable condition exists, such as explicit consent, legal claims, or a substantial public-interest rule supported by local law.

United States. In the preceding twelve months the Service may have collected identifiers, commercial information, internet activity, user content, sensitive information, and moderation inferences from the sources described above, and disclosed them for the listed business purposes. It does not sell or share personal information for behavioral advertising. Residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states receive the rights their applicable law provides. Recognized opt-out preference signals are honored where legally required.

Brazil, Canada, Australia, and other regions. Where applicable, you may request access, correction, deletion, anonymization, restriction, portability, information about disclosures, or withdrawal of consent, subject to local exceptions. Russian users may also request access, correction, blocking or deletion and information about cross-border processing where Federal Law No. 152-FZ applies. Mandatory local rights and remedies are not limited by this Policy.

12. Adults only

The Service is not directed to children and may be used only by a person who is at least 18 and has reached any higher local age of majority or adult-content access age. Do not submit a child’s personal data or any sexualized depiction of a minor. If the Operator learns that a minor used the Service or that prohibited child data was submitted, it may block access, preserve only evidence that law requires, delete other data, and report apparent exploitation to competent authorities.

13. Security

The Service uses measures designed for the sensitivity of its data, including TLS, application encryption for retained prompts and moderation media, private object storage, scoped service credentials, access controls, audited staff access, rate limits, and deletion workflows. No Internet transmission or storage system can be guaranteed completely secure or continuously available. Legally required breach notifications will be made to affected people and authorities.

14. Changes and contact

The Operator may update this Policy prospectively as the Service, providers, or law changes. A new effective date and version will be posted, and material changes will receive additional notice or consent where required. Earlier consent is not treated as agreement to an unrelated new use.

For privacy rights, deletion, safety reports, or questions, use the private Contact support form and choose “Privacy or deletion” or the appropriate safety category. Do not include passwords, payment credentials, prompts, or media unless authorized support staff specifically request the minimum information needed through the private case.

This Policy does not waive any mandatory privacy right or excuse a duty that cannot lawfully be limited. It is a general multi-region notice and must be reviewed for the Operator’s verified jurisdiction and launch markets.

Undress Design

A private creative studio for original, fictional adults.

GenerateUndressClipAboutSafetySupportTermsPrivacyLegal & reports

For adults 18+. Fictional characters only.
© 2026 Undress Design.

?Support