Privacy Policy

How Logo Foundry handles account data, local tools, uploads, AI generation, and payments

2026/10/04

Scope and contact

This policy describes how Logo Foundry handles information when you use our website, logo and icon tools, AI generation, accounts, and payments. Contact support@logofoundry.app with privacy questions or requests. This notice explains our practices; it does not replace consent where consent is required.

What happens to your tool inputs

Browser-only tools

Tools that explicitly say they process locally, including the classic Logo Maker, Text Favicon, icon generators and resizers, PNG to ICO, and image previews, process your selected images or text in your browser. Using those local workflows does not upload their input files to Logo Foundry for image processing. Visiting the page still involves normal website requests and any enabled usage analytics.

Homepage and upload workflow

The homepage/upload asset workflow is server-side. It sends the original image, filename, file metadata, and generation settings to our service. We store the original file, task records, generated assets, and download packages in our database and configured S3-compatible object storage, such as Cloudflare R2. Anonymous uploads also use temporary browser identifiers and task records. Do not upload confidential files on the assumption that this workflow is browser-only.

Favicon Checker

The checker sends the website URL you enter to our server. The server requests the target site's public HTML, manifest, and icon resources to produce a report. The target site receives those requests and may log them. Avoid submitting URLs containing access tokens or private information.

AI generation requires an account. We store your brand name, brief and design choices, generation and refinement records, provider/model identifiers, task status, candidate images, and related credit accounting. We send a prompt based on your brief to the configured third-party image service provider. Image to Logo crops and rasterizes the selected image in your browser; when you generate, it sends that processed crop to our server and the configured image service. We store the cropped reference with the task for comparison; the complete original file and its original filename are not sent by this workflow. Refinement also sends the selected candidate image as a reference. These providers and their model infrastructure process that content to return images. Our AI image-generation service uses GPT Image and FLUX model families, with GPT Image as the current default and FLUX supported as an alternative configuration. See AI image models and providers in our Terms for details.

Do not submit passwords, sensitive personal information, or confidential material you are not authorized to share with an AI provider. We do not promise that a provider never retains inputs or uses them for model improvement; its applicable terms and data practices must be considered separately.

Content safety reports and review

Our Terms of Service set out the six prohibited content categories, reporting channel, moderation process, enforcement measures, and appeals. Send content-safety or copyright/trademark reports and appeals to support@logofoundry.app.

To assess a report or suspected abuse, we may process the reporter's contact details, allegations and supporting information, content links or task identifiers, relevant prompts and reference/generated images, provider/model identifiers and safety responses, and relevant account or technical records. We use this information to locate and assess the content, communicate about the report, protect users and children, enforce our Terms, handle appeals, and comply with legal obligations. We do not use report submissions for marketing. Do not send suspected CSAM or other illegal imagery as attachments; provide links or identifiers and a description instead.

AI generation requests enable the selected provider's automated content safety check. The selected third-party image service provider processes the prompt and reference images for image-based generation or refinement as part of the generation workflow. Authorized personnel may access relevant stored content for human review of reports or suspected abuse; browser-only tool inputs are not uploaded for moderation merely because you use a local tool. Review is not a promise that every generated image receives human approval or that automated checks identify every violation.

We limit report access to personnel and service providers who need it for investigation, support, security, or legal compliance. We may share relevant information with the image provider to investigate an incident, with affected parties where necessary to address a claim, or with competent authorities when legally required or permitted. We seek to avoid disclosing a reporter's identity to the reported user unless necessary for a fair review or required by law; we cannot guarantee absolute anonymity.

Reports, review decisions, appeal correspondence, and necessary evidence are retained for as long as needed to resolve the case, prevent repeated abuse, and meet legal obligations or handle disputes. Relevant evidence may need to be preserved beyond the ordinary AI generation cleanup period; this does not extend retention of all AI content. We delete or minimize case information when it is no longer needed. You may request access, correction, or deletion through support, subject to applicable legal limits and other people's rights. Provider-held copies remain subject to the provider's data practices.

Account, payment, and support information

  • Accounts: We process your name, email, profile image if available, user ID, authentication-provider identifiers and credentials/tokens needed for sign-in, and session information, which can include IP address and user agent. Google and GitHub login are available when configured. If email/password authentication is used, authentication records also include a password hash, not a readable password.

  • Prompt safety: Before AI generation or refinement, we send the text prompt, including your brand description and refinement instruction where applicable, to Waffo for content safety screening. A restricted or review verdict can stop the request; scanner outages do not stop generation.

  • Payments: AI credit checkout is handled by Waffo. Stripe is used for separately offered subscription or billing features where available. We store payment/customer/order references, amounts, currency, status, purchase and refund records, and credit transactions. Payment providers collect payment instrument details directly; we do not store full card numbers or card security codes in our application database.

  • Support and email: We process information you send in support requests and use Resend for service emails and newsletter delivery. The current signup configuration automatically adds new account emails to the newsletter when that integration is configured. You can unsubscribe through an email's unsubscribe option, account notification settings, or by contacting support. Service emails concerning your account or orders may still be necessary.

Usage information and purposes

Website hosting, security, and enabled analytics services may process IP addresses, browser/device details, visited URLs, referrers, timestamps, and technical errors. Our custom tool events record limited categories such as tool, language, input/output type, coarse duration, and error code; they exclude image contents, filenames, entered logo text, and AI briefs. See our Cookie Policy for browser storage and analytics choices.

We use information to deliver requested tools, authenticate users, store and deliver assets, account for credits, fulfill payments, handle refunds and support, prevent abuse, troubleshoot errors, and understand feature usage. Where applicable data-protection law requires a legal basis, these purposes rely on performing our agreement with you, legal obligations, legitimate interests in operating and securing the service, or consent for activities that require it. You may withdraw consent without affecting processing that was lawful before withdrawal.

Sharing and security

Information needed for these purposes is processed by our hosting/database and object-storage providers, authentication providers, third-party image service providers for AI requests, Waffo for prompt screening and AI credit payments, Stripe for other available billing, Resend for email, and analytics providers when enabled. We may also disclose information when required by law or necessary to address fraud, security incidents, or legal claims. We do not sell your uploaded images or AI briefs.

We use authentication, access checks, server-side secrets, and HTTPS where deployed. AI candidate delivery checks account ownership. Some server-upload assets are delivered through object-storage URLs; possession of an accessible URL may allow others to retrieve the file. Treat such links as shareable and avoid uploading sensitive material. No online service can guarantee absolute security.

Service providers may process information outside your country. Applicable transfer requirements depend on your location and the providers involved; contact us for information about your request. We do not represent that all data stays in a single country.

Retention and deletion

Browser-only inputs are not retained on our servers by those local workflows. Downloads you save remain on your device until you delete them.

Account and stored upload records are kept while needed to provide the service and handle support, security, accounting, and legal obligations. The anonymous-upload cleanup job targets task records older than one day; generated temporary files depend on object-storage lifecycle settings. Original anonymous uploads are excluded from that routine cleanup. There is no blanket automatic 30-day deletion rule for original upload files. You can request their deletion through support; include the relevant task or asset reference if available.

The AI cleanup configuration makes generation records eligible for removal after seven days by default, measured from creation; the setting can differ by deployment and removal depends on the scheduled job actually running. Active tasks cannot be deleted until processing and credit settlement finish. Deleting a completed AI generation removes its application records and attempts to remove stored candidate files. Account deletion alone is not a guarantee that all object-storage files or provider-held copies are removed; contact support for a complete content-deletion request.

Transaction, refund, credit-accounting, and security records may need to be kept after content or account deletion to meet legal obligations or resolve disputes. Provider-held data follows the provider's retention practices. Contact us to ask about retention for a particular record rather than relying on a cookie expiry or a download link as a deletion deadline.

Your choices and rights

You can update available account settings, manage newsletter preferences, delete your account through account settings, or contact support to request access, a copy, correction, or deletion of personal information. Depending on applicable law, you may also request restriction, object to processing, exercise portability rights, withdraw consent, or complain to a data-protection authority. We may need to verify your identity and explain any legal reason that limits a request. There is no automated export interface for all data.

The service is not directed to children under 13. If you believe a child has provided personal information, contact us so we can investigate and address it.

Policy changes

We will publish changes here and update the date. Material changes will be communicated through an appropriate website notice or account communication, with separate consent requested where required.

Last updated: October 2, 2026.