Kitsmith

Privacy policy

Draft — not yet reviewed by counsel. This policy describes how the service works today and is published for transparency during the beta. It will be replaced by a reviewed version.

Last updated: September 2026

What we collect

Account data

  • Your email address and name.
  • Your password, stored only as a salted hash. We never store or see it in plain text.
  • Session records, stored in our Postgres database, so you stay signed in. A session cookie in your browser identifies your session.
  • Your credit balance and a history of credit charges and refunds.

Content you provide

  • Kit specs, prompts, game descriptions and asset names.
  • Reference images you upload.

Content we generate for you

  • Generated assets: 3D models, textures, concept images, renders and packages.
  • Derived data such as image embeddings, style scores and your project’s style model (LoRA).

Technical data

  • Basic server logs (IP address, request time, errors) kept for security and debugging.

Where it is stored and processed

  • Database: account data, sessions, kit specs and job records are stored in a managed Postgres database on Google Cloud in the United States.
  • Files: uploaded reference images and generated assets are stored in Google Cloud Storage in the United States. Files are private and served to you through short-lived signed links.
  • Kit planning: when you use the planner, your game description and kit spec are sent to Google Vertex AI (Gemini models) to propose an asset list and prompts. Google processes this data as our service provider under its cloud terms.
  • Generation: prompts, reference images and kit specs are processed on our own GPU workers running in Google Cloud to generate your assets. These workers are not shared with third parties.

How we use it

  • To provide the service: generate assets, maintain your project’s style memory, and build packages.
  • To run your account: authentication, credits and support.
  • To keep the service secure and fix problems.
  • To send essential service emails, such as account and policy changes.

Your inputs and outputs are used to serve your own projects. We do not use them to train models that are shared with other users.

What we do not do

  • We do not sell your personal data or your content.
  • We do not share your data with advertisers.
  • We do not make your kits or assets public.

Sharing

We share data only with service providers that help us run Kitsmith (currently Google Cloud, including Vertex AI), when required by law, or as part of a merger or acquisition, in which case this policy continues to apply to your data.

Retention and deletion

  • We keep your data while your account is active.
  • Deleting a kit removes it and its assets from your account; the stored files are purged afterwards.
  • You can ask us to delete your account and all associated data at any time. We will do so within 30 days, except where we must keep limited records by law (for example payment records, once paid plans exist).
  • Server logs are kept for a limited period and then deleted.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the address on the site. We will respond within the time required by law.

Security

Data is encrypted in transit and at rest by our cloud provider. The database is reachable only on a private network. Access to production systems is limited to the people who operate the service.

Children

The service is not intended for children under 16, and we do not knowingly collect their data.

Changes

We will post updates here and notify you by email about material changes. See also the Terms of service.