How AI Genjutsu collects, uses, and protects your data
10/09/2026
This Privacy Policy explains how AI Genjutsu ("AI Genjutsu", "we", "us", or "our") processes personal data when you use our websites, apps, APIs, billing flows, and related services (collectively, the "Service").
Data controller contact:
When you choose Google Sign-In, AI Genjutsu requests the basic openid, email, and profile permissions. We receive your Google account identifier, name, email address, email verification status, and profile picture when available. We use these details to create or recognize your account, sign you in, display your profile, and associate your credits, purchases, generation history, and service communications with your account.
Google Sign-In does not grant us access to your Gmail messages, Google Drive files, Google Photos library, contacts, or calendar. Photos, videos, and prompts used for generation are supplied separately by you; signing in does not import them from Google.
We store account details and authentication records, which may include Google-issued tokens and their expiry information, in our service database. Access is restricted to service operations and authorized personnel, and data is protected in transit. Hosting and database providers process these records on our behalf. Your name or email may also be used by our payment, email, and support providers where needed to provide the services described in this policy. We do not sell Google Sign-In data, use it for targeted advertising, or use it to train AI models.
Google Sign-In data follows the account retention and deletion rules below. You can remove AI Genjutsu's connection in your Google Account settings to revoke access. Removing the connection does not by itself delete your AI Genjutsu account or existing records. To request their deletion, use Settings or contact support@aigenjutsu.app; legally required records and the exceptions described below may be retained.
We collect data needed to operate, secure, and improve the Service:
We use personal data to:
Where applicable, we rely on one or more of the following legal bases:
We do not sell personal information. We share data only as needed with:
We use Plausible, served from plausible.clapoint.com, Google Analytics, and Microsoft Clarity to understand visits and interactions and improve the site. Clarity provides interaction analysis, including heatmaps and session recordings. Analytics follows the regional consent settings and your choice in Privacy choices in the footer. Google and Clarity receive the current analytics consent state; Plausible starts when analytics is allowed. Advertising consent is denied.
Our Google Analytics and Plausible integration removes URL fragments and arbitrary query parameters before measurement, retaining only validated campaign labels. You can change your analytics choice at any time through Privacy choices. See our Cookie Policy for details.
When you are signed in and explicitly allow analytics, we record when a low-credit offer is shown, including the displayed quote and balance. When you start Checkout, we record the validated price ID and Checkout session ID as part of the purchase flow. We link these records to your account to measure offer-to-purchase and result-delivery rates. These event records contain no prompts, uploads, generated files, card details, or full URLs. We delete raw funnel events after 90 days; account deletion may remove them sooner. You can stop optional offer-view collection through Privacy choices in the footer.
When you explicitly allow both analytics and AI Genjutsu account-linked measurement, we also store the first observed visit source, the latest non-direct source for 30 days, the public landing path, the public page where checkout started, and the checkout country reported by our edge network. A regional default is not that permission. Billing country and card country are taken from that invoice and charge and kept as billing records. We delete the visit-source detail after 90 days, so older payments can show an unknown source. Withdrawing the choice, signing out, or switching accounts clears the browser value, and later checkouts do not reuse it.
We retain data only for as long as needed for the purposes above:
You may request deletion of your account and associated personal data, subject to legal exceptions and required record retention. That request cannot be completed from this version of the site.
Self-service account deletion is not enabled. Settings does not accept a deletion request, and this version does not send a completion email. support@aigenjutsu.app is published as the contact address, but the mailbox is not connected and does not receive mail. Payment-provider billing records, support correspondence, security logs, and backups may still be retained if a later deletion process is configured.
Your data may be processed in countries other than your own. Where required, we implement appropriate safeguards for cross-border transfers.
Depending on your location, you may have rights to:
You can also:
To submit a privacy request, contact support@aigenjutsu.app.
The Service is not directed to children under 13, or any higher minimum age required by local law. If you believe a child provided personal data to us, contact support@aigenjutsu.app so we can investigate and remove the data where appropriate.
We use technical and organizational safeguards such as access controls, encryption in transit, and logging. No system is perfectly secure, and we cannot guarantee absolute security.
We may update this Policy from time to time. Material changes will be posted on this page with an updated date.
For privacy questions or requests:
Payments are processed by Stripe, which receives the payment and billing information needed to process transactions, manage subscriptions and prevent fraud. We do not store full card numbers. See Stripe’s Privacy Policy.
AI Genjutsu is an independent product at aigenjutsu.app. It is not affiliated with Higgsfield and does not share that company's engine, accounts, or customer data. support@aigenjutsu.app is the published contact address, and the mailbox is not connected, so mail sent there is not received. Self-service account deletion is not enabled. Checkout is not connected in this version, so a listed price cannot charge a card and a refund cannot be processed from this site until payment is configured.