Privacy policy
Last updated: August 5, 2026
The short version
We collect what we need to run Cuevi and nothing more. Photos you upload to the AI features are processed to generate your result, then discarded — we don't keep them. We don't sell your data. We do use Meta's measurement tools to know whether our Instagram ads work — details under "Ads measurement" below.
What we collect
Your account details (email, username, anything you add to your profile), the content you post (prompts, comments, votes, saves), and basic usage records — like how many featured app tries or prompt runs you've used, which power the fair-use limits. We also ask for your birth year and gender at signup — they personalize your feed, help us understand our community in aggregate, and help us keep content age-appropriate. They're never shown on your profile or to other users, and you can update them in settings. While you're signed in we also note which prompts you've already scrolled past or opened — only so your feed can put things you haven't seen first, and visible to no one but you. If you're signed in, your recent searches are saved to your account so they follow you across devices — you can delete any of them (or all of them) right in the search panel, and they're only ever shown to you. Signed out, recent searches stay on your device and never reach our servers. If you upgrade to Pro or buy credits, Stripe processes the payment; we only store your subscription status, never your card details.
Photos and AI processing
When you use a featured app (like the MBTI reading or the professional headshot) or run a template here with a photo, your photo is sent to the AI provider powering that feature — OpenAI, Anthropic, Google, or (for video templates) fal.ai running ByteDance's Seedance model — to generate the result, and that's it. We never store the photo you upload.
The RESULT is different, and this changed: if you're signed in, everything you generate here is kept privately in your own Run history — the latest 100 of each kind: images, videos, and text results. Only you can see it. You can delete any of it at any time, one at a time or a screenful at once, and all of it is wiped if you delete your account. It used to be a checkbox, and the usual outcome was that people lost the thing they had just made.
Signed out, nothing is kept: there is no account to keep it in. The one exception is if you start signing up while your result is being made so you can keep it — we hold that one result privately for up to 24 hours so it can land in your new account. Anything you deliberately PUBLISH is public by definition: a creation you post, or an example image you attach to a template.
Who we share data with
Only the services that run Cuevi, and only what each needs: Supabase (database and sign-in), Vercel (hosting), Stripe (payments), Resend (email delivery), the AI providers above (prompt and photo processing), and Meta for ad measurement (see below). We never sell your data to anyone.
Cookies
We use cookies to keep you signed in, one that remembers your language choice, and one that tracks whether you've used your free try of a featured app. The Meta Pixel described under "Ads measurement" also sets its own cookies (like _fbp) so Meta can tell an ad visit from a repeat one.
Analytics
We use privacy-friendly, cookieless analytics to see which pages are popular and catch errors. No cross-site tracking, and nothing is shared with anyone.
To count a visit as one visit rather than one per page, your browser keeps a random id for the current tab only — in session storage, not a cookie. It disappears when you close the tab, and it isn't linked to anything about you. Against that id we record which pages you opened, roughly how long you stayed, whether you ran one of the AI apps, and where you arrived from (the site that linked you, or the app whose built-in browser you're using). If you're signed in we also record which account it was, so we can see how much people actually use Cuevi.
Against that same id we also record what you do here: which prompts you open and roughly how long you read them, how far down a page you scroll, when you tap "Open in" and which app you picked, when you run a prompt and how long the wait was, when you refresh the feed or search, and when you tap through to someone's profile. We use it to work out which prompts are actually worth showing people, and to make the feed better at picking them. It is behaviour on Cuevi and nothing else — we don't follow you to other sites, we don't record what you type into a prompt, and none of it is sold or shared. The detail is deleted after 90 days; what stays after that is day-by-day totals, like "this prompt was read 40 times".
Ads measurement
We advertise Cuevi on Instagram, and we use the Meta Pixel and Meta's Conversions API to know whether those ads actually bring people here. Meta receives standard technical data (pages you visit here, your IP address, browser info, and Meta's cookie ids) plus key milestones like signing up, trying a featured app, or upgrading. Where a milestone includes your email address, it's sent as a one-way hash, never in plain text. Photos you upload, prompts you write, and your AI results are never shared with Meta. If you're in the EEA, the UK, or Switzerland, none of this runs until you agree to it — we ask when you first visit, and declining doesn't change how the site works for you. You can control how Meta uses this data in your Meta ad preferences.
Emails
We send three kinds of email. Account emails — sign-up confirmation, password resets, and billing receipts through Stripe if you upgrade. Activity emails — a note when someone comments on your post, follows you, messages you, or likes what you made. At most one a day, and the like/save/remix group triggers one at most once a week. And a weekly prompt email with a handful of prompts we think you'll like, chosen from what's on the site.
Activity and weekly emails are on when you join, and each is separately yours to turn off — in settings, or with one click from the footer of any email we send, without signing in. The two are independent: turning off the weekly email leaves your activity notifications alone, and vice versa. Account emails are the exception — we'll always be able to send you a password reset.
To choose which prompts go in the weekly email we use the same interest signals that shape your feed (the topics you engage with, and the age/gender bracket you told us at sign-up), plus a record of which prompts we have already emailed you so we don't repeat one. No email content is ever generated per person by an AI model.
Our email is delivered by Resend, which tells us whether a message was delivered, opened, clicked, bounced, or reported as spam. We keep that per message so we can stop emailing an address that bounces or complains, and so we can email people less often if they never open anything. Opens are unreliable by nature (Apple Mail loads images on your behalf), so we treat them as a rough signal only.
Deleting your data
Deleting your account in settings removes your profile and content. We may keep minimal records where we're legally required to — for example, payment records.
Children
Cuevi isn't intended for children under 13. We ask for your birth year at signup and don't allow accounts for anyone under 13, and we don't knowingly collect their data.
Changes and contact
If this policy changes in a meaningful way, we'll flag it on the site. Questions? Email hello@cuevi.app.