Skip to main content
Legal · Privacy policy

Privacy policy

How Ombak handles personal information for accounts, creation and support.

Review draft · Updated 2026-02-15
In short

Ombak collects only what the service needs. This page says what we process, who receives it, how long it is kept and how to delete it.

01

What we process

Account email and display name; the email, name and avatar Google supplies if you sign in with it; your prompts, uploaded references and generated results; generation records and the credit ledger; server logs kept for troubleshooting. We never receive card details — payments are handled by Waffo, and we see only the order and its amount.

02

Where data lives

Account and application data are stored in Cloudflare D1 and image files in Cloudflare R2, hosted on Cloudflare’s global network. Prompts and reference images are sent to the connected model provider at generation time (see Models and content).

03

Third parties and retention

Currently connected: Cloudflare (hosting and storage), fal.ai (image generation), Google (optional sign-in), Resend (transactional email) and Waffo Pancake (payments, as Merchant of Record). Results and assets are kept until you delete them; deleting your account deletes account data, assets and generation records with it. Billing records may be kept longer where the law requires. Send deletion requests to support@ombak.ai.

Disputes and contact

For questions about these terms, billing or content handling, contact support@ombak.ai first and we will respond as soon as we can. These terms may change as the product changes; material changes will carry an effective date on this page.