Privacy Policy
This Privacy Policy explains what information Retina Image Works (“Retina”, “we”) collects when your team uses Nuke AI Hub, how we use it, and the choices you have. Nuke AI Hub is a business product; the account holder is your company or studio, and this policy covers the personal data of the individual users on a team.
Account data: username, email address, team name, role, and password (stored as a salted hash, never in plain text).
Billing data: subscription tier, seats, token balances, payment history, and invoice references. Card numbers are handled exclusively by our payment processor and never touch our servers.
Request-level usage and operations data: team and user identifiers, request/trace/job/reservation references, token consumption, model and feature usage, provider route, timing, status, and structured or redacted error categories. These records support billing, quota enforcement, incident recovery, capacity planning, audit, and abuse prevention.
Connection and device data: source IP address, opaque or hashed machine/workstation identifiers, application and Nuke versions, seat-lease state, and last-seen timestamps needed to secure accounts and enforce seats.
Generated media: Nuke AI Hub does not provide permanent cloud media storage. Generated-output working copies are temporary and, when no active job protects them, are normally eligible for cleanup after 15 minutes. Reference uploads are normally eligible for cleanup after 24 hours, with active jobs protected until they finish. Gallery records contain metadata rather than media bytes and expire after 24 hours by default. Third-party model providers may process or retain submitted content under their own provider terms.
Support communications: messages you send to support, so we can respond.
Default telemetry from the desktop application and the Nuke plugin does not include your prompts, chat contents, local file paths, project files, or reference media. Telemetry is summary-only: identifiers, counts, durations, status, and structured error codes/categories; free-form error prose is omitted. Prompts and reference media you submit for a generation are transmitted to fulfil that request and are not retained as telemetry.
To operate, secure, and bill the Service; to enforce seat and quota limits; to send transactional email (account verification, receipts, payment failures, usage statements); to provide support; and to improve reliability and capacity planning using aggregated usage data. We do not sell personal data and we do not use your content to train models.
AI model providers: your prompts and reference media are forwarded to the third-party model providers needed to fulfil each request (for example Google, Anthropic, OpenAI, Fal, Kling), under their respective data-processing terms.
Payment processing: subscription and purchase payments are handled by our payment processor, which receives the billing details necessary to charge you.
Email delivery: transactional email is delivered through our email service provider.
Hosting: the Service runs on cloud infrastructure providers that store data on our behalf.
We may disclose information when required by law or to protect the rights, safety, or property of Retina, our customers, or the public.
Account and billing records are kept for as long as your account exists and as required for tax and accounting obligations. Generated-output working copies, reference uploads, and gallery metadata follow the temporary cleanup windows described above; files needed by an active job are protected until the job finishes. Request-level usage, security, seat, billing, and audit records are retained for the account and business-record lifecycle and as required for security, accounting, dispute, and legal obligations; aggregated analytics may be derived from those records. After account termination you may request an export within 30 days, after which data may be deleted.
Data in transit is encrypted with TLS. Passwords are stored as salted hashes. Access to production systems is restricted and audited. No system is perfectly secure; we will notify affected customers of a personal-data breach as required by applicable law.
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing. Team owners can exercise these rights for their team by contacting support; individual users should route requests through their team owner where the data belongs to the team account.
Our infrastructure and the third-party providers listed above may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
We will post changes to this policy here and, for material changes, notify account owners by email. Privacy questions: contact support through the address on your billing page.