We do not sell personal information for money.
Information is shared only where reasonably necessary to operate Autocraft, process requests, comply with law, or protect rights and safety.
Connection recovery
Your work is safe. Check the connection and try loading the workspace again.
This policy explains what Autocraft processes across the website, visual frontend workspace, BYOK and managed-AI workflows, billing, support, and project features.
Information is shared only where reasonably necessary to operate Autocraft, process requests, comply with law, or protect rights and safety.
Stored provider credentials are encrypted at rest and are not displayed again after submission.
Requests can use a user-owned provider credential or Autocraft-managed AI access, with relevant request context sent to the provider performing the operation.
This Privacy Policy explains how Autocraft collects, uses, stores, and shares personal information when you use autocraft.sh, the Autocraft visual frontend workspace, billing pages, support channels, and our public website.
By using the service, you acknowledge the processing described in this policy. If you do not agree, do not use the service.
We collect information you provide directly, information created through your use of the platform, and limited information from third-party service providers that support the service.
We use personal information to operate the service, authenticate users, provide support, process billing, prevent abuse, maintain security, comply with law, and improve product quality.
We do not sell your personal information for money. We share information only when reasonably necessary to run the service, comply with law, or protect rights and safety.
Autocraft supports AI-powered workflows that may include business-idea analysis, product-direction generation, visual-system creation, frontend generation, sketch-to-code, project-wide contextual generation, Design Chat, scoped refinement, validation, recovery, and related operations.
The exact data sent to an AI provider depends on the operation. It may include prompts, sketches, images, source code, generated code, selected components, existing pages, visual-system data, references, project context, and technical metadata reasonably required to complete the request.
Autocraft may support different AI providers or models for different workflows over time. Model availability and routing may change as the product evolves.
Free access currently uses the user's connected OpenAI credential during a one-time seven-day trial that begins when the key is successfully verified. Managed paid workflows use centrally managed OpenAI access for supported operations. These routes may change as providers and product capabilities evolve.
Where optional Instant Free or Connected Cloudflare access is enabled, it uses fixed GLM-4.7-Flash routing. For connected accounts, AutoCraft records only usage sent through AutoCraft plus provider exhaustion state; it cannot determine activity performed elsewhere or promise an externally remaining balance, and it does not intentionally authorize Cloudflare paid overage.
We do not make a blanket promise that every current or future AI provider uses submitted data under identical training or retention terms. The provider's current terms and data controls apply to the request it processes. Where OpenAI API services are used, OpenAI states that API data is not used to train its models by default unless the customer opts in.
We keep information for as long as reasonably necessary to provide the service, maintain business records, resolve disputes, enforce agreements, and comply with legal obligations. Retention periods may vary depending on the type of data, account status, and technical backup cycles.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We do not display stored provider secrets after submission. Deleting a provider credential removes its encrypted active record, subject to limited security audit records and documented backup-retention cycles that do not expose the plaintext key.
Disconnecting Cloudflare asks Cloudflare to revoke the OAuth token and removes AutoCraft's encrypted active connection record. Limited security, consent, wallet, and aggregate usage records may remain for fraud prevention, accounting integrity, support, and legal obligations without retaining the plaintext token.
Production access is limited to authorized personnel and service processes with an operational need. We maintain incident-response procedures to contain, investigate, remediate, and provide legally required notice of a qualifying personal-data breach.
Request-level provider usage records are retained only for operational reconciliation and abuse review; bounded 7-day, 30-day, and 365-day summaries may be retained for at least 365 days for account transparency and billing support.
Autocraft relies on service providers for authentication, application hosting and data storage, payment processing and merchant-of-record services, operational communications, security, and AI processing. These currently include Clerk for authentication, Convex for application data, Paddle for billing, and OpenAI for supported managed and BYOK AI processing. Cloudflare may also process optional Free AI workflows only when that program is enabled.
A current subprocessor summary or additional information about a provider may be requested at team@autocraft.sh. Provider terms and retention practices also apply to data sent to a provider at your direction or through an Autocraft-managed AI workflow.
You may update certain account information through the product interfaces. You may also contact us to request access, correction, deletion, or export of personal information, subject to legal exceptions and reasonable identity verification.
If you want to close your account or request deletion, contact us at team@autocraft.sh from the email associated with your account. We may retain limited information where necessary for fraud prevention, billing records, dispute resolution, tax obligations, or legal compliance.
If you use BYOK, you can remove your stored provider credential through the available product controls. Removing a credential prevents future Autocraft requests from using that stored credential, subject to the retention and backup limitations described in this policy.
The service may be operated and supported using systems located in multiple countries. By using the service, you understand that your information may be processed in jurisdictions that may have different data protection rules than your home jurisdiction.
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.
We may update this Privacy Policy from time to time to reflect product changes, legal requirements, or operational changes. When we do, we will post the updated version on this page and update the effective date above.
Questions or privacy requests can be sent to team@autocraft.sh.
Privacy questions
Contact the Autocraft team for privacy requests, account deletion, provider questions, or additional information about subprocessors.