cutkit legal
Privacy Policy
Last updated: 21 July 2026
cutkit is a background-removal API for developers and AI agents, operated by CUTKIT ai (the "operator", "we"). We are the data controller for the processing described here. You can reach us through your account in the cutkit console.
Your images
Images exist in cutkit for one purpose: to produce your cutout. In particular:
- Deleted within 24 hours. Results are stored in object storage with a 24-hour expiry, and the result URL we return stops working after the same 24 hours. There is no long-term image archive.
- Zero-retention mode. Accounts on the privacy tier get immediate deletion: the result is removed from storage as soon as it has been delivered to you, and no stored result record is kept at all.
- Never used for training. We do not use your images or cutouts to train or fine-tune any model, ever.
- Where processing happens. Paid, privacy-tier, and EU-tier requests are processed exclusively on our cloud inference provider. Free-trial and batch requests may instead be processed on inference hardware operated by us; privacy- and EU-tier traffic is never routed there — that separation is enforced in code and covered by tests.
Account data we store
- Sign-in identity: your email address and, if you sign in with Google or GitHub, the provider's account identifier. Magic-link sign-in stores your email and a hashed, single-use token.
- Credentials, hashed: session tokens and API keys are stored only as hashes (we display a key's prefix and last four characters for identification). We can never show you a full key again — nor can anyone who reads the database.
- Billing references: Stripe event and payment-intent identifiers linked to your credit purchases. Card details never touch our systems — payment runs entirely on Stripe's hosted checkout.
- Usage ledger: per-request billing events (operation, cost, timestamps) and a daily usage rollup — this is how your balance and usage page work.
- Stored results: for non-privacy accounts, a pointer to each result (storage key, dimensions, variant) so the console can re-show it during its 24-hour lifetime. Zero-retention accounts get no such record.
Logs
Our request logs are structured and PII-scrubbed by design: they record the request method, path, status, timing, request id, and account id — and never query strings (which could carry an image URL), never image bytes or base64, and never API keys or authorization headers.
Processors
We use the following categories of sub-processors; a detailed list is available on request through the console:
| Processor | Purpose | Location / transfer basis |
|---|---|---|
| Edge network & object-storage provider | Content delivery, application hosting, image storage | Global edge; EU/US — DPF & SCCs |
| Cloud GPU inference provider | Image processing (paid, privacy, and EU tiers) | US — SCCs |
| Managed database provider | Accounts and billing ledger | EU (Frankfurt) |
| Stripe | Payments (hosted checkout; we store references only) | EU/US — DPF & SCCs |
| OAuth sign-in; Google Analytics 4 (only with your consent) | EU/US — DPF & SCCs | |
| Transactional-email provider | Magic sign-in links | US — SCCs |
| Documentation-hosting provider | cutkit.ai/docs | US — SCCs |
Cookies & analytics
- Essential cookies: the console session cookie
(
ck_session, httpOnly), its CSRF token (ck_csrf), and your analytics choice (ck_consent). These are required for the service to work and involve no tracking. - Analytics (consent-only): we use Google Analytics 4 to
understand aggregate usage. It loads only after you allow it
in the consent bar — before that, nothing is sent to Google. Declining is
remembered and equally respected. You can revoke consent at any time by
clearing the
ck_consentcookie / site data, after which the consent bar asks again. Analytics events never contain personal data.
Retention
| Data | Retention |
|---|---|
| Images / cutouts | At most 24 hours; zero-retention tier: deleted immediately after delivery |
| Account & sign-in data | Until you delete your account |
| Billing ledger & purchase records | As long as statutory accounting rules require |
| Operational logs | Short-lived, rotated automatically |
Legal bases
We process account, image, and billing data to perform our contract with you (Art. 6(1)(b) GDPR); security and abuse-prevention data on legitimate interest (Art. 6(1)(f)); and analytics only with your consent (Art. 6(1)(a)), which you may withdraw at any time.
Your rights
Under the GDPR you can request access to, rectification or erasure of your personal data, restriction of processing, data portability, and you can object to processing based on legitimate interest. Contact us through your account in the cutkit console — we respond within the statutory period. You also have the right to lodge a complaint with your supervisory authority.
Changes
We will update this policy when the service changes and adjust the "last updated" date above. Material changes are announced in the console or by email.