Privacy Policy
Last updated: 17 September 2026
1. Introduction
This Privacy Policy explains how NSFW API (“we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you use the NSFW API website, developer API, and Playground (the “Service”). It applies to visitors browsing without an account as well as registered users.
We do not sell or rent personal data. We process only the information needed to provide, secure, and improve the Service.
2. Definitions
- Account: an account used to access the Service and private history.
- Personal Data: information relating to an identified or identifiable person.
- User Content: photos, videos, prompts, and other material you submit.
- Face Data: content in an uploaded image depicting a human face and processed only to fulfil the requested generation.
- Biometric Identifiers: facial geometry, templates, embeddings, or similar information used to identify a person.
- Usage Data: technical data generated when you interact with the Service.
3. Information We Collect
3.1 Account information
When you register, we process your email address, account identifier, password authentication data, and records of the Terms, Privacy Policy, and adult-age declarations accepted at registration. Passwords are handled by our authentication service; they are not stored in plain text.
3.2 Uploaded content
We access and process only the photos, videos, prompts, and settings you intentionally submit. We do not access your entire photo library.
3.3 Generation and account history
We store job status, selected model, generation parameters, USD reservations and charges, generated results, and related technical information so you can use the Service and view your private history.
3.4 Device and usage information
We may process IP address, browser and device information, language, timestamps, pages viewed, diagnostics, and security events. We do not request precise GPS location.
3.5 Payment information
Account top-ups are currently arranged manually with the operator. We keep billing contact information, top-up references, ledger entries, reservations and generation charges. The website does not currently collect payment-card details or offer automatic subscriptions.
4. How We Use Personal Data
We use personal data to:
- authenticate users and maintain accounts;
- process uploads and fulfil photo or video generation requests;
- store private generation history and manage prepaid USD balances;
- provide support and service-related notifications;
- monitor reliability, prevent abuse and fraud, and protect the Service;
- comply with applicable legal obligations;
- create aggregated or anonymized statistics that do not identify you.
We do not use uploaded photos, videos, face-related content, or prompts for advertising, profiling, or training our own AI models.
5. How We Share Personal Data
We share information as needed to deliver, secure and support the Service, or comply with law. Our infrastructure uses self-hosted Supabase software for authentication, PostgreSQL data storage, private file storage and Realtime notifications. Infrastructure operators may process data necessary to host and protect these systems.
- MuleRouter and the selected model's processing providers: prompts, source images, video or audio, generation settings and technical identifiers needed to execute your request.
- Amazon Web Services (Amazon SES): recipient email addresses and transactional account messages, such as confirmation and password-reset emails.
- Cloudflare and hosting/network providers: connection information and data required to route, secure and deliver requests.
- Restricted operational providers, professional advisers, authorities or business transferees where necessary and lawful.
Generation inputs must be transmitted to the relevant AI provider to fulfil your request. We do not sell or rent personal data. Provider terms and privacy practices may impose their own processing and retention requirements; the Service's local deletion schedule does not guarantee deletion of all independently controlled provider records.
We are established in Hong Kong. Data may be hosted or processed in other jurisdictions, including where infrastructure and AI providers operate. We use access restrictions and applicable contractual and legal safeguards for these transfers. Third-party websites you access independently have their own terms and privacy policies.
6. Face Data and Facial Images
6.1 What we process
If your chosen upload contains a face, that image may be processed only to perform the editing or generation you requested. NSFW API does not use faces to identify, authenticate, recognize, or track people.
We do not intentionally create or retain facial geometry, biometric templates, feature maps, or face embeddings.
6.2 Why we process face-related content
Face-related image content is used only to process the selected model and produce the requested output. It is not used for recognition, profiling, advertising, or training our own AI models.
6.3 Third-party processing
Images containing faces may be temporarily transmitted to third-party processors when required by the selected workflow. Their processing is governed by the selected provider’s applicable terms and privacy obligations. We do not operate a facial identification service; an AI model may nevertheless perform technical analysis necessary to generate an image or video.
7. Storage and Retention
- Inputs and outputs: scheduled for deletion 24 hours after the generation reaches a terminal state. Unused uploads expire after 24 hours. Downloads must be saved before the storage period expires.
- Prompts and normalized generation inputs: scheduled for redaction 24 hours after a terminal state.
- Redacted provider diagnostics, application request logs and webhook payloads: generally retained for 30 days.
- Audit records, including registration acceptance records: generally retained for one year.
- Ledger, usage and billing records: retained under our seven-year operational retention policy, subject to applicable legal requirements. Removing generated files does not erase billing history.
- Account data: retained while the account is active and as needed for support, security and legal obligations.
Deletion is an automated background process; technical failures may delay physical removal and are retried. Limited data may be retained for a legal hold, dispute, accounting or abuse investigation. Backups can temporarily retain data after deletion from active systems and are restricted from ordinary use and rotated separately.
To request access, correction, deletion or account closure, email [email protected]. We may verify your identity and authority over the account and respond within applicable legal time limits. We cannot erase records we are legally required to retain.
8. Data Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction. These include access controls, authenticated account access, server-side credentials, encrypted transport, and restricted database and storage rules.
No method of Internet transmission, electronic processing, or storage is completely secure. While we take reasonable measures to protect personal data, we cannot guarantee absolute security.
You are responsible for protecting the credentials, devices, and accounts you use to access the Service. Contact us if you suspect unauthorized access to your account.
9. Cookies and Similar Technologies
We use necessary Supabase authentication cookies to maintain and refresh your sign-in session. Browser memory also holds unsubmitted form values, including a password you are entering; we do not put passwords into URLs or persistent browser storage. Connection and security services may use necessary technical cookies or identifiers.
You can delete or restrict cookies through your browser settings. This can sign you out or prevent account features from working. These authentication cookies are not marketing consent.
10. Your Rights
Depending on your location, you may have the right to:
- access or correct personal data associated with your account;
- request deletion of generated content, personal data, or your account;
- object to or restrict certain processing;
- request a portable copy of applicable personal data;
- withdraw consent where processing is based on consent;
- submit a complaint to the relevant data-protection authority.
To exercise these rights, contact [email protected].
11. Children
The Service is not intended for children. The entire Service is available only to adults aged 18 or older and at least the age of majority where they live. We do not knowingly process images of minors for sexualized or intimate transformations.
If you believe a minor is depicted in prohibited content connected to the Service, stop sharing it and contact [email protected]. We may preserve limited information when legally required to investigate and report abuse.
12. Changes to This Policy
We may update this Policy as the Service changes. The date at the top identifies the latest version. Material changes may also be communicated through the Service where appropriate.
13. Contact Us
This website is operated by HONG KONG YAOCHEN GROUP TECHNOLOGY LIMITED, UNIT 05, 12/F THE CLOUD, 111 TUNG CHAU ST, TAI KOK TSUI, HONG KONG.
For privacy questions or requests, contact [email protected].