Privacy Policy
Last Updated: 27.08.2026
1. Introduction
ReelyArt LLC ("ReelyArt", "we", "our", "us") respects your privacy. This Privacy Policy explains what data we collect, how we use it, with whom we share it, and what rights you have regarding your personal information when you use the ReelyArt platform.
By using ReelyArt, you agree to the practices described in this policy. If you do not agree, please discontinue use of the Platform.
2. Information We Collect
Account Information
- Email address and username
- Profile information you choose to provide
- Authentication data (managed via Supabase Auth)
Billing & Subscription Data
- Subscription plan type and billing cycle
- Payment method type (e.g., card brand, last 4 digits), provided by Stripe, not stored by us
- Transaction history and invoice records
- Credit balance, credit type (subscription vs. permanent), and usage history
Content Data
- Images and files you upload to the Platform
- AI-generated visuals, designs, and project files
- Prompts and inputs submitted to AI generation features
- NFT and Web3 project metadata fetched via OpenSea API when using Lab features
Published Community Content
Everything above stays private to your account unless you publish it. Publishing a creation to a community feed is voluntary and per-creation, and it makes the following public, visible to anyone, with or without a ReelyArt account, and reachable by search engines:
- The creation itself, and the community it was published to
- Your display name and profile picture, shown alongside it as attribution
- The prompt behind it, the publish dialog offers to share it and is pre-ticked; clear it to publish the image on its own. The setting is per post.
Generating on a community page also records your membership of that community and a count of how many generations you have made there. That record is used for the member count shown on the page; it does not identify you publicly.
You can withdraw a published post at any time, which removes it from the feed and from public view. Copies that others downloaded or shared elsewhere before removal are outside our control. See Section 4 of our Terms of Service for the licence publishing grants.
Web3 Wallet Data (Holder Perks)
- The public Ethereum wallet address you link to your account after signature verification
- The cryptographic signature used to verify wallet ownership, processed transiently, not stored
- Public on-chain NFT ownership data for the linked address, read via third-party APIs to determine campaign eligibility
- Claim history: campaign, wallet address, NFT token ID, and credits granted
We never receive or request private keys, seed phrases, or transaction approvals. Connecting a wallet is signature-only and cannot move funds.
Discord Account Data (Holder Perks)
- Your Discord user ID and display name, collected when you link your Discord account through Discord's official OAuth consent screen
- OAuth access tokens, stored encrypted and used solely to check your membership and role in a partner's Discord server when you claim a community-gated campaign
- Your role list in the specific partner server tied to a campaign, checked transiently at claim time and not stored beyond the claim record
- Claim history for community-gated campaigns: campaign, Discord user ID, and credits granted
We request only the identify and guilds.members.read Discord permissions. We cannot read your messages, direct messages, or friend list, and we cannot act on your behalf in any server. You can disconnect your Discord account at any time from the Perks page, which removes the link and stored tokens from active use.
Usage Data
- IP address and general location (country/region)
- Browser type, device type, and operating system
- Pages visited, features used, and interaction data
- Error logs and performance diagnostics
Abuse Prevention Data
- A device identifier computed in your browser from non-sensitive browser and device characteristics (such as screen, language, and platform settings), stored only as a hash
- The IP address recorded at sign-up and when a free grant is claimed
- A record of each free-credit claim attempt and its outcome
We use this data solely to enforce one-per-person limits on welcome credits and free community generations, and to detect duplicate or automated accounts, on the basis of our legitimate interest in preventing fraud and abuse. It is not used for advertising, profiling, or cross-site tracking, and it is not shared with third parties. The resulting credit decisions are described in Section 6 of our Terms of Service.
3. How We Use Your Information
We use collected data to:
- Create and manage your account and subscription
- Process payments and manage credit balances
- Deliver AI generation features using your inputs and uploaded content
- Save, display, and export your projects and generated content
- Communicate with you regarding your account, billing, or support requests
- Improve platform performance, reliability, and user experience
- Detect and prevent fraud, abuse, and policy violations, including duplicate accounts created to claim free credits more than once
We do not sell your personal data to third parties.
4. AI Processing
Your uploaded content, prompts, and inputs are transmitted to third-party AI systems to deliver generation features. The specific providers we use are:
- OpenAI language understanding, prompt processing, and image generation. Processes text prompts and reference images you provide.
- Google multimodal image generation and image revision. Processes images and prompts for generation and editing features.
- Replicate image and video generation and background removal. Processes prompts and reference images for background and animated content features, and processes images you submit for background removal.
Your content is transmitted to these providers solely to fulfill your generation request. We do not use your uploaded content or generated outputs to train AI models, and our service agreements with these providers restrict such use.
5. Third-Party Services
We use the following trusted third-party services to operate the Platform:
- Stripe payment processing and subscription management. Handles all card data in compliance with PCI DSS standards.
- Supabase database, file storage, and authentication infrastructure. Hosted in the eu-central-1 region (Frankfurt, Germany).
- Vercel platform hosting, CDN, and edge delivery.
- Cloudflare (R2) object storage and content delivery for the images you upload and the files generated for you, served from cdn.reely.art.
- Resend delivery of transactional email: sign-in codes, the welcome message, and account or billing notices. Receives your email address and the contents of those messages.
- Upstash (Redis) rate limiting and short-lived operational state. Holds request counters derived from your IP address and temporary tokens for sign-in and account-linking flows, all of which expire automatically.
- Google Analytics aggregated measurement of traffic and feature usage. Loaded only if you accept analytics cookies, never linked to your ReelyArt account, and never used for advertising. See our Cookie Policy.
- Vercel Analytics anonymous page-view and performance metrics, also loaded only if you accept analytics cookies.
- OpenSea API public NFT collection and wallet metadata used in Lab and Holder Perks features.
- Alchemy on-chain NFT ownership verification for Holder Perks. Receives only the public wallet address being checked.
- WalletConnect (Reown) encrypted relay used when connecting a mobile wallet on Holder Perks. Carries session metadata only; never keys or funds.
- Discord OAuth-based account linking and server membership/role verification for community-gated Holder Perks campaigns. Governed by Discord's Privacy Policy.
- OpenAI, Google, Replicate AI generation infrastructure (see Section 4).
Each provider processes data only to the extent necessary to support Platform functionality and is bound by their own privacy policies and data processing agreements.
6. Payment Data
All payment transactions are processed by Stripe, Inc. We do not store, have access to, or transmit your full credit card number, CVV, or bank account details. Stripe processes and stores payment information in accordance with PCI DSS Level 1 compliance standards.
We store only non-sensitive billing references such as your Stripe customer ID, subscription status, and invoice history for account management purposes.
By making a purchase, you also agree to Stripe's Privacy Policy.
7. Cookies & Sessions
ReelyArt uses essential session cookies and local storage to maintain your authenticated state, managed through Supabase Auth. These are required for the Platform to function correctly.
- We do not run advertising or behavioural tracking pixels, and we do not share personal data with ad networks.
- Session data is stored securely and cleared upon logout or session expiry.
- If you accept analytics cookies, we load Google Analytics and Vercel Analytics to understand general usage patterns and improve the Platform. Google Analytics sets persistent cookies that can last up to two years; Vercel Analytics sets none. Neither is linked to your ReelyArt account, and neither is used for ad personalisation, remarketing, or audience targeting. Declining analytics cookies stops both from loading at all, and you can change your choice at any time from the Cookie Policy page.
For a complete breakdown of the cookies and tracking technologies we use, including how to manage your preferences, see our Cookie Policy.
8. Data Location
Your account information, project records, and every other database record we hold about you are stored on Supabase infrastructure in the eu-central-1 region (Frankfurt, Germany), within the European Union.
The image and video files themselves, both the ones you upload and the ones generated for you, are stored in Cloudflare R2 object storage and delivered through Cloudflare's global content-delivery network. Cloudflare is a United States company, and the files may be held or cached outside the European Union.
AI generation requests are transmitted to the providers listed in Section 4, which also process data outside the European Union. Where personal data leaves the EEA, whether to Cloudflare, to an AI provider, or to any other processor in Section 5, the transfer is covered by that provider's data processing agreement and the European Commission's Standard Contractual Clauses, or by the EU-U.S. Data Privacy Framework where the provider is certified under it.
9. Data Retention
- We retain your account data for as long as your account is active. We do not run a separate expiry clock on it: operational records such as generation history, credit transactions, sign-up and free-credit checks, and page-view logs are kept while the account exists and are removed when it is deleted.
- Upon account deletion, your profile, designs, generated content, uploaded files, published community posts, community memberships, linked wallet and Discord records, credit history, and usage logs are permanently and immediately deleted, together with your stored files in Cloudflare R2. This action is irreversible.
- Two things survive deletion, and neither can be used to identify you on the Platform any more: a partner-programme application, if you ever submitted one, is kept with its business contact details but with the account link removed; and internal cost and usage logs keep a bare account reference that no longer points to an existing account. Ask us at info@reely.art if you want these erased as well.
- Billing and transaction records held by us or by Stripe may be retained for up to 7 years for legal and tax compliance purposes.
- Aggregated analytics data sits with Google and Vercel under their own retention settings and is not tied to your account, so it is unaffected by account deletion.
- You may delete your account at any time directly from your Account page. No email request is required.
10. Your Rights
Depending on your location, you have the following rights regarding your personal data:
GDPR (EU / EEA Users)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten"), exercisable directly via the Account page
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority, normally the data protection authority of the EU or EEA country where you live or work. You do not have to contact us first, though we would rather hear from you and put it right.
CCPA (California Residents)
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell personal data)
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at info@reely.art. We will respond within 30 days.
11. Age Requirement
ReelyArt is intended for users who are 13 years of age or older. Users between 13 and 16 in the European Union require verifiable parental or guardian consent under GDPR Article 8.
We do not knowingly collect personal data from children under 13. If we become aware that a user under 13 has created an account, we will delete the account and associated data promptly. If you believe a minor has submitted data without consent, please contact us at info@reely.art.
12. Security
- We implement reasonable technical and organizational security measures including encrypted data transmission (HTTPS), access control policies, and secure credential management.
- Payment data is handled exclusively by Stripe and never passes through our servers.
- No system is completely immune to security risks. We encourage you to use strong, unique passwords and notify us immediately of any suspected unauthorized access.
13. Changes to This Policy
- We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-platform notice.
- Continued use of the Platform after the effective date of any changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related inquiries, data requests, or concerns, contact us at info@reely.art.
The controller of your personal data is:
ReelyArt LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States