Privacy Policy
Last updated: July 19, 2026
This policy lists exactly what Dolly collects and why. No more, no less. We run no ads, no analytics trackers, and we don't sell data. A plain-English summary sits above each section; the full text governs.
1. What we collect
In plain English: Your email, your prompts and images, billing records (never card numbers), moderation logs, and your IP at signup.
Account: your email address and authentication data, managed by our auth provider. Content: the prompts you write, reference images you upload, and media you generate. Moderation records: every moderation check is logged with a content fingerprint (hash) and verdict; for rejected prompts, the prompt text itself is retained for enforcement; rejected image uploads are never stored, only their fingerprint. Billing: transaction identifiers, amounts, and credit history. Card and payment details go directly to Stripe. They never touch our servers. Technical: your IP address at first sign-in (abuse prevention) and short-lived server logs.
2. How we use it
In plain English: To run the service, keep it safe, and bill correctly. Nothing else. No ads, no selling, no trackers.
We use this data to operate the service (run your generations, store your library, maintain your balance), to enforce the content policy and prevent abuse, and to process payments and refunds. We do not sell personal data, run advertising, or use third-party analytics.
3. Who processes it
In plain English: Five processors, each doing one job: Supabase (accounts), Cloudflare (hosting + storage), Kie.ai (runs generations), Anthropic (moderation checks), Stripe (payments).
Supabase: authentication and database hosting. Cloudflare: application hosting, delivery, and media storage. Kie.ai is our model provider: your prompts and reference images are sent there to run generations. Anthropic runs automated moderation: prompts and uploads are checked by its models before generation. Stripe: payment processing for all purchases; Stripe's own privacy policy applies to checkout. We share data with these processors only as needed to provide the service, and with authorities where the law requires.
5. Retention
In plain English: Media until you delete it; money records as long as the law requires; moderation logs for enforcement.
Generated media and uploads are stored until you delete them or close your account (media deleted within 30 days of closure). Credit and payment records are retained as required for accounting and legal obligations. Moderation logs are retained for policy enforcement and safety. Server logs are short-lived.
6. Your rights
In plain English: Ask for your data, ask for deletion. Email us and we'll do it.
You can access your content anytime in the app, and delete generations individually. Regardless of where you live, we honor requests to access, correct, or delete your personal data. Email support@dolly.to and we will action it. Deleting your account removes your account and generated media; transaction records are retained as required for financial and tax compliance. Where your local law (such as EU/UK GDPR or California CPRA) grants further rights, including data portability or complaint to a supervisory authority, we honor those too.
7. Security and children
In plain English: Encrypted in transit, minimal keys, no card data on our side. Dolly isn't for children.
Traffic is encrypted in transit; secrets and API keys are scoped server-side; payment details never reach our infrastructure. You must be at least 13 years old, or the minimum age of digital consent in your jurisdiction, to use Dolly; the service is not directed at children, and we delete accounts we learn belong to underage users.
8. Changes and contact
In plain English: If this policy changes materially, we tell you before it applies.
Material changes to this policy will be announced by email or on the site before taking effect. Questions and privacy requests: support@dolly.to.