Skip to content

Privacy & Data Retention

Full legal text: Privacy Policy and Terms of Service. This page is the developer-facing summary of what actually happens to data you send through the API.

POST /v1/alttext never writes the image itself to disk or a database — the bytes exist only long enough to compute a hash and send them to the vision model. Only the hash and the generated text are kept, so an identical public image (from you or anyone else) can be served from cache instead of re-analyzed. That cache mapping isn’t linked to any account.

Data Retention
Account (email, plan) Until you delete your account
API keys Hashed, never the raw key. Cascades with account deletion.
Usage counters Cascades with account deletion
Generated alt text/caption cache Indefinite, account-independent
Site scanner results (GET /v1/scan) 30 days, per domain
  • The vision model provider — receives the image to generate alt text.
  • Stripe — billing. We never see your card details.
  • Resend — sends transactional/account email.

DELETE /v1/account (session-token authenticated) cancels any active subscription and deletes your account and everything tied to it — irreversible. Or email support@altpilot.com from your account email and we’ll do it for you.

Full detail, sourced from the actual schema: see docs/09-data-retention.md in the repo if you want the underlying source of truth this page summarizes.