Privacy Policy
Effective July 2, 2026 · Last updated July 20, 2026
This policy explains how Marsfield collects, uses, shares, and protects personal information when you use marsfield.xyz, our applications, and our APIs (the “Service”).
1. Who we are
Marsfield provides tools for generating, editing, organizing, and storing AI-created media. Marsfield is responsible for the personal information described in this policy. Privacy questions and rights requests can be sent to privacy@marsfield.xyz.
2. Information we collect
Account and profile information
We collect your name, email address, password hash, account identifiers, plan, credit balance, storage allowance, API-key metadata, and account preferences. We do not store your plaintext password or plaintext API keys.
Content and generation data
We process prompts, uploaded images, video and audio, generated outputs, projects, storyboard scenes, model selections, generation settings, and related metadata. Content may include personal information about you or another person.
Billing and transaction data
Freemius handles checkout and payment processing as merchant of record. We receive subscription, plan, license, transaction-status, and customer-identification data needed to activate and administer your plan. We do not receive or store full payment-card numbers.
Usage and technical data
We collect credit usage, storage use, prediction status, API-key usage timestamps, logs, error details, IP address, browser/device information, and security events. Authentication information may be stored in your browser’s local storage to keep you signed in.
Feedback and support data
If you submit feedback or report a problem, we collect your message, issue type, account identifier, current page URL, browser/device details, and related troubleshooting context so we can diagnose and respond to the issue.
3. How we use information
- Provide, secure, troubleshoot, and improve the Service.
- Authenticate users and process API requests.
- Submit generation requests, retrieve outputs, and store assets.
- Administer subscriptions, credits, storage limits, and billing history.
- Detect fraud, abuse, prohibited content, and security incidents.
- Comply with law, enforce our Terms, and protect users and third parties.
- Send essential service, transaction, and policy communications.
Where applicable, we rely on performing our contract with you, legitimate interests in operating and securing the Service, consent, and compliance with legal obligations.
4. AI providers and other service providers
We disclose only the information reasonably needed to providers that help operate Marsfield. These providers may process information in countries outside your own:
- Replicate and model providers process prompts, reference media, generation parameters, and outputs.
- Cloudflare provides R2 object storage and network services.
- Freemius provides checkout, subscription, tax, fraud-prevention, and merchant-of-record services.
- Resend provides transactional email delivery for account recovery, feedback, and support messages.
- Hosting, database, email, monitoring, security, and professional-service providers may process operational information on our behalf.
We may also disclose information during a business transaction, with your direction or consent, or when reasonably necessary to comply with law or protect rights and safety. We do not sell personal information for money.
5. Storage and retention
Uploads and generated assets are stored in Cloudflare R2. Free-plan content is scheduled for retention for up to 7 days and may then be deleted automatically. Paid content is retained while your account and applicable plan remain active, subject to storage limits, user deletion, legal obligations, backup cycles, and operational requirements.
Account, billing, security, and transaction records may be retained after account closure where needed for legal compliance, dispute resolution, fraud prevention, and enforcing agreements. Provider copies may remain for the periods described in each provider’s policy.
6. Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to your local privacy regulator. We may need to verify your identity before completing a request, and some information may be retained where permitted or required by law.
Send requests to privacy@marsfield.xyz. You can revoke API keys from Settings and delete content using available account controls.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, hashed credentials, signed webhooks, and encrypted network transport. No internet service is completely secure, so we cannot guarantee absolute security. Keep your password and API keys confidential and notify us promptly of suspected misuse.
8. Children
The Service is not directed to children under 13, and paid or API use requires the legal capacity to enter a contract. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information without appropriate authorization.
9. Changes to this policy
We may update this policy as Marsfield changes. We will post the revised policy with a new effective date and provide additional notice when required by law. Continued use after the effective date is subject to the updated policy.