Privacy Policy.

Last updated: July 3, 2026

This policy explains what data NSFWGuard collects, how we use it, and — because our core product classifies images you submit — exactly what happens to that content.

Information We Collect

We collect the following categories of information when you use NSFWGuard:

  • Account information — your email address, name, and a hashed password, or your Google/GitHub profile identifier if you sign in with a social provider.
  • Billing information — your subscription plan, Stripe customer and subscription identifiers, and invoice history. Card details are collected and stored directly by Stripe; we never see or store your full card number.
  • API keys — we store a SHA-256 hash and a 7-character prefix of each key for identification. The raw key is shown to you once at creation and is never stored or logged in plaintext.
  • Technical data — IP address, browser user agent, and session tokens, used to authenticate requests and detect abuse.
  • Content you submit — images sent to our classification API. See How We Handle Your Images below for exactly how this is processed and discarded.

How We Handle Your Images

Image content is the most sensitive data our API touches, so we minimize how long it exists on our infrastructure:

  • When you submit an image to POST /classify, it is resized and briefly written to encrypted object storage solely so our classification worker can pick it up.
  • The object is automatically deleted as soon as classification completes.
  • We do not use images you submit to train, fine-tune, or evaluate any machine learning model.
  • The classification result (labels and scores) is returned directly in the API response and cached for up to 1 hour, then it is automatically purged.
  • We retain only aggregate usage metadata — timestamps, request counts, and whether content was flagged — for billing and abuse prevention. We never retain the image itself.

How We Use Your Information

  • To provide, operate, and maintain the API and dashboard.
  • To process payments and manage subscriptions through Stripe.
  • To send transactional emails — payment receipts, plan-change confirmations, and security notices.
  • To enforce rate limits, usage quotas, and detect fraudulent or abusive use of the API.
  • To respond to support requests you send us.
  • To comply with tax, accounting, and other legal obligations.

Third-Party Service Providers

We share the minimum data necessary with the following providers to operate NSFWGuard:

  • Stripe — payment processing and subscription billing.
  • Resend — delivery of transactional emails (receipts, plan updates, security notices).
  • Neon (PostgreSQL) — encrypted hosting of our application database.
  • Cloudflare R2 — transient, encrypted object storage used only during image classification, as described above.
  • Google / GitHub — optional OAuth sign-in, if you choose to use it instead of an email and password.

Each provider processes data under its own privacy policy and is contractually limited to using it only to provide services to us.

Data Retention

  • Account data is retained for as long as your account is active.
  • Billing records are retained as required by tax and accounting regulations, typically several years after account closure.
  • Session tokens expire automatically and are not retained beyond their validity period.
  • Submitted images are retained only transiently — typically seconds — during classification, as described above.
  • You can request deletion of your account and associated data at any time; see "Your Rights" below.

Security Measures

  • All API and dashboard traffic is encrypted in transit using TLS 1.3.
  • API keys and passwords are hashed with SHA-256 / industry-standard algorithms — we never store them in plaintext.
  • Database connections use SSL with certificate verification.
  • Object storage used for image processing is encrypted at rest.
  • Access to production systems is restricted to authorized personnel on a least-privilege basis.

Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your account and associated data.
  • Request a copy of your data in a portable format.
  • Object to or restrict certain processing of your data.

To exercise any of these rights, contact us via Support. We will respond within the timeframe required by applicable law.

Cookies

We use a small number of strictly necessary cookies to maintain your login session and protect against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies.

Children's Privacy

NSFWGuard is a developer tool and is not directed at, or knowingly used to collect data from, individuals under the age of 16. If you believe a minor has provided us with personal data, contact us and we will delete it.

International Data Transfers

Our infrastructure providers may process and store data in countries other than your own. Where this occurs, we rely on the safeguards required by applicable data protection law, such as standard contractual clauses.

Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or through a notice on the dashboard before the change takes effect. The "Last updated" date at the top of this page always reflects the most recent revision.

Contact Us

Questions about this policy or how your data is handled? Reach out through Contact Support and we'll get back to you.