Soutine
New users receive 8 free credits after signing up.
Privacy · Data protection

Privacy Policy

How Harry Lee collects, uses, and protects personal information when you use Soutine.

Last revised 2026/08/30About 6 min read

At a glance

What we collect

Account details, payment status, and AI inputs/outputs needed to run the service. We do not store full card numbers.

Generations are private by default

Assets are accessed through your account, signed downloads, or share links you control.

Analytics can be turned off

First-party analytics are on by default. Stop future analytics in Settings → Security.

Your data rights

Request access, correction, export, or deletion at support@soutine.ai.

Harry Lee ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, store, and share your personal information when you use Soutine (the "Service") at https://soutine.ai, and the rights available to you.

Please read this Policy carefully before using the Service. By using the Service, you agree to this Policy. We may update this Policy periodically and will notify you of material changes by email or in-product notice.

1. Data Controller

The data controller for this Service is:

  • Name: Harry Lee
  • Status: individual / sole trader operating under the laws of China
  • Privacy email: support@soutine.ai
  • Data Protection Officer (DPO): Not applicable

2. Personal Information We Collect

2.1 Information You Provide Directly

  • Account information: name, email, and profile details you provide when you register or sign in (including through Google).
  • Payment information: transaction amount and payment status. Full card numbers are not stored by us — card data is processed by our payment processors (see Section 5).
  • Communications: emails, support requests, and feedback you send us.
  • AI inputs and outputs: prompts, negative prompts, uploaded images, reference media, persona descriptions, generated images, videos, metadata, task status, share links, and download activity when you use AI features.

Do not submit highly sensitive personal information in prompts or uploaded media unless the Service explicitly supports that use case and you have the necessary rights and consent.

2.2 Information We Collect Automatically

  • Device and network data: IP address used for security and infrastructure (we do not retain the raw request IP address in first-party acquisition analytics), device type, operating system, browser type, and time zone.
  • Usage data: pages visited, feature usage, and session activity.
  • Log data: request timestamps, error logs, and performance metrics used to operate and secure the Service.
  • First-party analytics: a pseudonymous visitor and session identifier, the page path without query parameters, campaign fields, referring domain, and a two-letter country code inferred by our infrastructure. We do not retain raw advertising click identifiers in acquisition analytics.

2.3 Third-Party Login

When you sign in with Google, we receive your name, email, and basic profile details provided by Google.

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service (contract performance)
  • Process billing and payments (contract performance)
  • Provide customer support (contract / legitimate interests)
  • Send service notices about billing, security, and policy changes (legitimate interests)
  • Secure the Service and prevent abuse (legitimate interests)
  • Understand product usage and improve reliability (legitimate interests)
  • Comply with law (legal obligation)

We may process prompts, uploaded media, generated media, task settings, and related metadata to provide AI features, enforce limits, prevent abuse, debug failures, support refunds, and maintain security.

We may aggregate or anonymize data for statistical purposes. Such data cannot reasonably be linked to an individual.

4. Cookies and Tracking Technologies

TypePurposeDisableable
Strictly necessaryLogin sessions, security, and checkoutNo
FunctionalLanguage and theme preferencesYes (via browser controls)
AnalyticsFirst-party product analyticsYes (Settings → Security)

We do not use marketing or advertising cookies. Details are in the Cookie Policy.

We enable privacy-conscious analytics by default to understand product usage and reliability. You may opt out in Settings → Security. An explicit analytics opt-out is respected on later visits, subject to technical and legal retention requirements.

5. Sharing and Disclosure

We do not sell your personal information, including as defined under applicable laws such as the CCPA. We share your information only in the following circumstances:

  • Service providers: AI providers, storage providers, payment processors, email providers, analytics providers, and infrastructure providers, bound to process data only as needed to provide their services. They may process personal data, AI inputs, generated media, payment metadata, device data, or support records as needed to provide their services.
  • Payments: when you checkout through Waffo Pancake, payment card data is processed by Waffo Pancake, a PCI-DSS certified payment processor, and is not stored on our servers. When you checkout through another enabled processor (currently including Stripe), that processor handles card data, invoices, taxes, and statutory refunds for that transaction.
  • Legal requirements: where required by law, court order, or a lawful regulatory request.
  • With your consent: for any other purpose, with your explicit prior consent.

Generated assets may be private by default, accessible through account controls, signed download URLs, or share links depending on your settings. Revoking a share link or deleting an asset may not remove copies already downloaded, cached, backed up, sent to a provider, or retained when legally or operationally required.

6. Data Security

  • Encryption in transit (TLS / HTTPS)
  • Passwords and sensitive credentials stored hashed or encrypted by our authentication provider
  • Access limited to what is needed to operate the Service
  • Essential error and performance monitoring with sensitive request data removed before reporting

In the event of a personal-data security incident, we will notify relevant authorities within 72 hours of becoming aware of it where required by law, and we will notify affected users without undue delay where required by law. Keep your credentials secure and do not share them.

7. Data Retention

Data typeRetentionUpon expiry
Account informationWhile the account is active; 90 days after cancellation or deletion request, unless a longer legal period appliesDelete or anonymize
Transaction and billing recordsAs required for tax, accounting, and dispute handlingDelete or archive
AI task metadata and generated-asset recordsWhile needed to provide the Service, then in line with account deletion and asset policyDelete or restrict
Support recordsAs needed to resolve requests, then deleteSecure deletion
First-party acquisition analyticsUp to 13 monthsDelete or rotate identifiers
Security logsAs needed for security and abuse preventionSecure deletion

You can stop future analytics in Settings → Security; account deletion requests are handled separately.

8. Your Data Rights

Depending on your location and applicable law, you may request access, deletion, correction, export, or removal of personal data, generated media, or account content. Email support@soutine.ai. We aim to respond within 30 calendar days. We may need to verify your identity, preserve financial, security, consent, audit, or legal records, and coordinate with providers before completing a request.

You may also lodge a complaint with your local data protection authority.

9. Marketing and Opt-Out

We do not send marketing emails by default. If we ever do, they will require consent where required by law, and you can opt out through the unsubscribe link or by emailing support@soutine.ai. Opting out does not affect essential service notices such as billing and security alerts.

10. International Data Transfers

Our infrastructure and providers may process data in multiple regions, including where our AI, storage, payment, and hosting providers operate. For international transfers we rely on contractual safeguards with providers, including Standard Contractual Clauses where they apply, and transfers only to recipients that provide an appropriate level of protection.

11. Children's Privacy

The Service is intended for users aged 18 and above. We do not knowingly collect information from children below that age. If you believe a child has provided information, contact support@soutine.ai and we will delete it promptly.

The Service may include links to, or integrations with, third-party services (including AI model providers and payment processors). This Policy applies only to data we collect. Review those providers' policies before use.

13. Policy Changes

For material changes, we will provide at least 14 days' advance notice by email or in-product notice, and update the date at the top of this page. Continued use after the effective date constitutes acceptance.

14. Contact Us

Last updated: 30 August 2026 · Harry Lee · https://soutine.ai

Questions about your privacy rights?

Contact support@soutine.ai for access, deletion, or policy details.

Email support