AutocraftSign In
Legal · Privacy

Privacy should remain understandable as the product becomes more capable.

This policy explains what Autocraft processes across the website, visual frontend workspace, BYOK and managed-AI workflows, billing, support, and project features.

Effective August 8, 2026autocraft.sh

We do not sell personal information for money.

Information is shared only where reasonably necessary to operate Autocraft, process requests, comply with law, or protect rights and safety.

BYOK credentials are treated as secrets.

Stored provider credentials are encrypted at rest and are not displayed again after submission.

AI processing depends on the workflow you choose.

Requests can use a user-owned provider credential or Autocraft-managed AI access, with relevant request context sent to the provider performing the operation.

1. Overview

This Privacy Policy explains how Autocraft collects, uses, stores, and shares personal information when you use autocraft.sh, the Autocraft visual frontend workspace, billing pages, support channels, and our public website.

By using the service, you acknowledge the processing described in this policy. If you do not agree, do not use the service.

2. Information We Collect

We collect information you provide directly, information created through your use of the platform, and limited information from third-party service providers that support the service.

  • Account information such as name, email address, authentication identifiers, organization details, and profile metadata.
  • Billing information such as subscription status, plan, transaction references, country, and limited payment metadata from our payment processors. We do not intentionally store full card numbers.
  • User content such as business ideas, prompts, sketches, uploaded files, project data, visual systems, product directions, generated pages, code, support messages, and other materials you choose to submit.
  • Project context created through your use of the workspace, including selected directions, visual-system preferences, existing pages, interface patterns, references, media, and other project information used to maintain continuity across generations and refinements.
  • Provider credential metadata where BYOK is used, such as provider name, masked key suffix, validation state, and encrypted credential material. Provider API keys are encrypted at rest and decrypted only in trusted server or worker memory when needed to perform your request.
  • When you connect Cloudflare, we process OAuth tokens, the selected account identifier, a one-way account hash used to share the daily allowance correctly, account display metadata, permission scopes, validation state, reset/exhaustion state, and usage caused through AutoCraft. OAuth tokens are encrypted at rest and are not displayed in the client.
  • Usage and device information such as IP address, browser type, device identifiers, log events, approximate location, session activity, feature usage, provider-reported token consumption, managed-credit consumption, and separate image, audio, or video operation totals where applicable.

3. How We Use Information

We use personal information to operate the service, authenticate users, provide support, process billing, prevent abuse, maintain security, comply with law, and improve product quality.

  • To create and manage accounts, sessions, subscriptions, plans, credits, and entitlements.
  • To generate, deliver, store, sync, and recover your projects, sketches, product directions, visual systems, pages, code, and other outputs.
  • To maintain project-wide context so Autocraft can carry relevant product direction, visual language, existing pages, references, and prior project decisions across supported generation and refinement workflows.
  • To process AI-powered requests using either a user-configured provider credential or Autocraft-managed AI access, depending on the plan and workflow you choose.
  • When you use BYOK, to validate and use the provider credential you enable, transmit the prompts, source, media, project context, and request metadata required for your request to the selected provider, measure usage, enforce disclosed limits, detect fraud, and troubleshoot reliability issues.
  • When you use an Autocraft-managed AI plan, to transmit the request data required to perform the operation to the AI provider used for that workflow, account for managed-credit consumption, apply rate or execution controls, and troubleshoot reliability issues.
  • To communicate with you about account activity, support, product updates, legal notices, and policy changes.
  • To analyze performance and improve workflows, prompts, routing, reliability, and platform stability using aggregated or de-identified data where practical.

4. How We Share Information

We do not sell your personal information for money. We share information only when reasonably necessary to run the service, comply with law, or protect rights and safety.

  • With service providers that help us with hosting, authentication, storage, analytics, support, communications, payment processing, and AI inference.
  • With an AI provider when you direct Autocraft to perform an AI-powered operation, whether through a user-owned provider credential or an Autocraft-managed AI plan. The provider receives the request data reasonably required to perform the operation and processes it under its own applicable terms and privacy practices.
  • With professional advisers, auditors, insurers, or counterparties when reasonably necessary for legal, financial, or compliance purposes.
  • When required by law, subpoena, court order, regulatory request, or to protect the rights, property, security, or safety of Autocraft, our users, or others.
  • As part of a merger, acquisition, financing, reorganization, or sale of all or part of the business, subject to standard confidentiality protections.

5. AI Processing, BYOK And Managed AI

Autocraft supports AI-powered workflows that may include business-idea analysis, product-direction generation, visual-system creation, frontend generation, sketch-to-code, project-wide contextual generation, Design Chat, scoped refinement, validation, recovery, and related operations.

The exact data sent to an AI provider depends on the operation. It may include prompts, sketches, images, source code, generated code, selected components, existing pages, visual-system data, references, project context, and technical metadata reasonably required to complete the request.

Autocraft may support different AI providers or models for different workflows over time. Model availability and routing may change as the product evolves.

Free access currently uses the user's connected OpenAI credential during a one-time seven-day trial that begins when the key is successfully verified. Managed paid workflows use centrally managed OpenAI access for supported operations. These routes may change as providers and product capabilities evolve.

Where optional Instant Free or Connected Cloudflare access is enabled, it uses fixed GLM-4.7-Flash routing. For connected accounts, AutoCraft records only usage sent through AutoCraft plus provider exhaustion state; it cannot determine activity performed elsewhere or promise an externally remaining balance, and it does not intentionally authorize Cloudflare paid overage.

We do not make a blanket promise that every current or future AI provider uses submitted data under identical training or retention terms. The provider's current terms and data controls apply to the request it processes. Where OpenAI API services are used, OpenAI states that API data is not used to train its models by default unless the customer opts in.

  • BYOK: when you connect a supported provider credential, provider usage is associated with and billed through your provider account according to that provider's terms.
  • Managed AI: when you use an Autocraft-managed plan, Autocraft supplies the provider access and measures usage against the plan's included credits or limits.
  • Rate limits, queuing, execution limits, and other usage controls may be applied to protect service reliability, prevent abuse, and manage bounded AI usage.
  • Autocraft does not intentionally expose stored provider secrets in the client after submission.

6. Retention And Security

We keep information for as long as reasonably necessary to provide the service, maintain business records, resolve disputes, enforce agreements, and comply with legal obligations. Retention periods may vary depending on the type of data, account status, and technical backup cycles.

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

We do not display stored provider secrets after submission. Deleting a provider credential removes its encrypted active record, subject to limited security audit records and documented backup-retention cycles that do not expose the plaintext key.

Disconnecting Cloudflare asks Cloudflare to revoke the OAuth token and removes AutoCraft's encrypted active connection record. Limited security, consent, wallet, and aggregate usage records may remain for fraud prevention, accounting integrity, support, and legal obligations without retaining the plaintext token.

Production access is limited to authorized personnel and service processes with an operational need. We maintain incident-response procedures to contain, investigate, remediate, and provide legally required notice of a qualifying personal-data breach.

Request-level provider usage records are retained only for operational reconciliation and abuse review; bounded 7-day, 30-day, and 365-day summaries may be retained for at least 365 days for account transparency and billing support.

7. Service Providers And Subprocessors

Autocraft relies on service providers for authentication, application hosting and data storage, payment processing and merchant-of-record services, operational communications, security, and AI processing. These currently include Clerk for authentication, Convex for application data, Paddle for billing, and OpenAI for supported managed and BYOK AI processing. Cloudflare may also process optional Free AI workflows only when that program is enabled.

A current subprocessor summary or additional information about a provider may be requested at team@autocraft.sh. Provider terms and retention practices also apply to data sent to a provider at your direction or through an Autocraft-managed AI workflow.

8. Your Choices And Rights

You may update certain account information through the product interfaces. You may also contact us to request access, correction, deletion, or export of personal information, subject to legal exceptions and reasonable identity verification.

If you want to close your account or request deletion, contact us at team@autocraft.sh from the email associated with your account. We may retain limited information where necessary for fraud prevention, billing records, dispute resolution, tax obligations, or legal compliance.

If you use BYOK, you can remove your stored provider credential through the available product controls. Removing a credential prevents future Autocraft requests from using that stored credential, subject to the retention and backup limitations described in this policy.

9. International Processing And Children

The service may be operated and supported using systems located in multiple countries. By using the service, you understand that your information may be processed in jurisdictions that may have different data protection rules than your home jurisdiction.

The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.

10. Policy Changes And Contact

We may update this Privacy Policy from time to time to reflect product changes, legal requirements, or operational changes. When we do, we will post the updated version on this page and update the effective date above.

Questions or privacy requests can be sent to team@autocraft.sh.

Privacy questions

Need clarification about your data or account?

Contact the Autocraft team for privacy requests, account deletion, provider questions, or additional information about subprocessors.