Privacy Policy
Effective Date: May 16, 2026
At Rhinestone Mine & Design (RMD), operated by Morfcraft LLC, your privacy is critically important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you interact with our AI thumbnail studio (the “Services”). By using RMD, you agree to the practices described here. Your continued use of the Services after we update this Privacy Policy signifies acceptance of the revised terms, so please review it regularly.
What this Privacy Policy covers
This Privacy Policy covers how we manage the personal data we collect when you access or use RMD. “Personal Data” means any information that identifies, relates to, describes, or could reasonably be linked with an individual. This Privacy Policy does not apply to companies we do not own or control, or to individuals we do not employ or manage.
Your use of RMD is always subject to our Terms of Service, which incorporate this Privacy Policy. Terms not defined here have the meaning assigned in the Terms of Service.
We may update this Privacy Policy as we evolve RMD. When we make material changes, we will post the revised policy on our website, email you, or provide another appropriate notice. Notices apply to your use of the Services even if you do not read them, so please check back regularly.
Google API Services User Data Policy
RMD’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Use AI Partners
RMD may use artificial intelligence models to power image editing, background removal, analysis, brainstorming, and other creative tooling. We only send the minimum data required to fulfill your request, such as the thumbnail image you provide, optional masks, prompts, or context like a video title. We do not submit your payment details or account credentials to Gemini.
When you request AI image processing, your image and instructions are sent to AI services to process your request. The edited image is returned to your device and saved there. We do not keep copies of your images or instructions on our servers after processing is complete other than as stated in the Terms of Service. Google may log requests according to their privacy policies. For more details, review Google’s privacy documentation.
What we collect and why
- Clear local data: You can clear all local data by clearing your browser storage.
- Account data deletion: You can request deletion of any account-associated data by contacting us.
Where your data is stored
Your projects, preferences, edit history, template favorites, chat messages, and other data are stored on your device in your web browser. This means:
- Your data stays on your device and is not sent to our servers unless you request an AI image edit.
- Data storage: If you clear your browser data or use private/incognito mode, your saved projects and preferences may be lost.
- We don’t access your data: We cannot see your saved projects or preferences unless you choose to share them with us through support requests or other communications.
- Device-specific: Your data is stored on the specific browser and device where you use RMD. It won’t automatically sync to other devices.
This approach keeps your creative work private and on your device. You’re responsible for backing up your work by exporting projects or downloading images if you plan to switch devices or browsers.
Content Moderation & Safety
To maintain a safe platform and comply with our content policies, we automatically analyze images you upload for potentially harmful content. This helps us prevent the distribution of illegal, abusive, or policy-violating material.
What We Analyze
When you upload an image, we use JavaScript content moderation to check for:
- Sexually explicit or pornographic content
- Hate speech or discriminatory imagery
- Harassment or bullying content
- Dangerous or violent content
Images that violate our content policies are blocked from upload, and you will receive an error message explaining why.
Abuse Prevention
We use automated systems to detect and prevent abuse patterns. Accounts that repeatedly violate our policies may be suspended.
Moderation Data Retention
We log moderation events (such as blocked uploads) to detect abuse patterns and improve our safety systems. These logs include metadata about the upload (file type, size, timestamp, moderation result) but do not store the actual image content of blocked uploads. Moderation logs are retained for safety and compliance purposes.
Data Sharing and User Consent
We share your data only when it is necessary to provide the Services, comply with the law, protect our rights, or with your explicit consent. When you upload media or prompts to RMD, you authorize us to transmit that content to AI for processing so we can return images and feedback. Media is retained in your account until you delete it, remove the project, or request account deletion. AI inputs are transmitted over encrypted channels and stored in secured infrastructure.
Third-party Service Providers
We rely on the following service providers to deliver RMD:
- AI: We use AI services to process image editing requests. Images and instructions are sent to Google and others for processing and are subject to their privacy policies. We do not keep your images on our servers after processing other than as stated in the Terms of Service.
- Payment Processors: If you subscribe to paid plans, we may use payment processors such as Stripe to handle transactions. Payment data is processed according to the processor’s privacy policies.
- Hosting Infrastructure: Our services are hosted on secure cloud infrastructure that complies with industry-standard security practices.
- Google Analytics: We use Google Analytics 4 (GA4) to understand how users interact with RMD, including page views, feature usage, and conversion events. Google Analytics collects data such as your IP address, browser type, device information, and interactions with our service. This data helps us improve our product and user experience. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on. For more information, see Google’s Privacy Policy.
We require each provider to handle Personal Data in a manner consistent with this Privacy Policy and applicable law.
Your Choices
You may withdraw consent for AI processing or marketing communications at any time by updating your account preferences or contacting us to have your account terminated and removed. If you opt out of AI processing, certain features (including automated image editing) may become unavailable.
Personal Data We Collect
We collect Personal Data to deliver, secure, and improve RMD. The categories of Personal Data we may collect include:
- Profile or Contact Data: Name, email address, organization, job role, and similar identifiers.
- Payment Data: Billing details, the last four digits of a payment card, and transaction records managed by our payment processors (we do not store full card numbers).
- Commercial Data: Purchase history, subscription tier, usage history, and saved projects.
- Media & Creative Inputs: Images, masks, prompts, project notes, video context, and other creative assets you upload for AI processing. If you choose to upload a selfie image, we may analyze it to extract design-relevant information (such as hair color and eye color) for thumbnail creation purposes only. This analysis data is stored locally in your browser and is not used for identification purposes.
- Device & Technical Data: IP address, browser type, operating system, device identifiers, and settings that help us secure your account and optimize performance.
- Usage Analytics: Feature usage, workflow steps, error logs, session duration, and interactions with our UI to help us enhance RMD.
- Support Communications: Emails, chat transcripts, feedback, and survey responses when you contact us for help or participate in research.
- Social or Marketing Data: Public social media information you link, campaign attribution data, and preferences for receiving updates.
- Inferences: Insights we derive from other Personal Data to better understand product performance and user needs, such as engagement scores or predicted interests.
Sources of personal data
We collect Personal Data from the following sources:
- You: Information you provide directly, including account registration, surveys, support requests, voluntary feedback, uploads, and in-product interactions. We also collect data automatically when you use the Services (such as logs and cookies).
- Public Records: Information available from government or public sources to verify business eligibility or comply with legal requirements.
- Third Parties: Service providers, marketing partners, analytics platforms, payment processors, identity verification vendors, and social platforms you connect to RMD.
Why We Collect Personal Data
We collect and disclose Personal Data to achieve these business purposes:
- Provide, customize, and improve the Services: To create and manage your account, process transactions, deliver AI editing features, store projects, provide support, research product usage, personalize experiences, and maintain security.
- Marketing: To send product updates, educational content, and promotional offers consistent with your preferences, and to deliver contextual or interest-based advertising.
- Communications: To respond to inquiries, notify you about product changes, and provide service-related alerts.
- Legal obligations: To comply with law, enforce agreements, investigate violations, prevent fraud or abuse, and protect the rights, property, or safety of RMD, our users, and the public.
We will not use Personal Data for materially different purposes without providing notice or obtaining your consent, where required.
How We Disclose Personal Data
We disclose Personal Data to the categories of third parties listed below. Depending on applicable state laws, some disclosures may be considered a “sale” of Personal Data, even if no money changes hands.
- Service Providers: Hosting and storage providers, AI infrastructure providers (including Google for Gemini models), customer support tools, communications services, analytics vendors, and payment processors such as Stripe.
- Advertising & Analytics Partners: Entities that assist with marketing campaigns, attribution, and product analytics.
- Business Partners: Companies we collaborate with to deliver integrations, workflows, or co-marketing initiatives you opt into.
- Parties you authorize: Third parties you connect or grant access to through integrations or account linking features.
We may also disclose Personal Data if required by law, in response to valid legal process, to enforce our agreements, or during corporate transactions such as mergers, acquisitions, or asset sales.
We may create aggregated or de-identified data from Personal Data. We may use or share such data for any lawful purpose, and it will not identify you individually.
Tracking tools, cookies, and advertising
We use cookies, pixel tags, local storage, web beacons, and similar technologies (“Cookies”) to run and improve RMD. Cookies help us remember your preferences, authenticate sessions, analyze usage, and deliver relevant content. Some Cookies are set by third parties that provide analytics or advertising services.
Types Of Cookies We Use
- Essential Cookies: These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you, such as setting your privacy preferences, logging in, or filling in forms.
- Functional Cookies: These cookies enable the website to provide enhanced functionality and personalization, such as remembering your preferences and settings.
- Analytics Cookies: These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. This helps us improve our services.
- Marketing Cookies: These cookies may be set through our site by our advertising partners to build a profile of your interests and show you relevant content on other sites.
Managing Your Cookie Preferences
You can manage Cookies through your browser settings. Most browsers allow you to refuse or accept cookies, and to delete cookies that have already been set. Disabling certain Cookies may affect site functionality and limit your ability to use some features of RMD.
You can also use the cookie consent banner on our website to accept or reject non-essential cookies. Your preferences are stored in your browser’s local storage and will be remembered for future visits.
For more information about controlling interest-based advertising, visit resources such as the Digital Advertising Alliance, Network Advertising Initiative, or European Interactive Digital Advertising Alliance.
Data Security
We employ administrative, technical, and physical safeguards to protect your Personal Data. These measures include encryption in transit, access controls, monitoring, and secure development practices. No online service can guarantee absolute security, so we encourage you to use strong passwords, enable multi-factor authentication when available, and log out of shared devices.
Your Data Control and Deletion Rights
Because RMD stores your data locally in your browser, you have direct control over your data:
- Delete through your browser: You can delete your projects, clear preferences, or remove all RMD data by clearing your browser data.
- Delete in RMD: You can delete individual projects, clear chat history, or reset preferences through RMD’s interface.
- Account deletion: If you have created an account (if account features are available), you may request account deletion by contacting us. However, because most data is stored on your device, clearing your browser data may be the primary method of deletion.
Important: Once you delete data from your browser, it cannot be recovered. We do not keep backups of your data on our servers.
Data Retention
We retain Personal Data for as long as needed to provide the Services, comply with legal obligations, resolve disputes, protect our interests, and enforce agreements. The retention period depends on the type of data and the context of our interactions. We may retain anonymized or aggregated information indefinitely.
- Profile information is kept while your account remains active.
- Projects and media remain until you delete them, your account is closed, or we no longer need them for business or legal purposes. Note that most projects are stored locally in your browser and are deleted when you clear browser data.
- Payment records are retained as required for accounting and regulatory compliance.
Children’s Privacy
RMD is not intended for children under 13, and we do not knowingly collect Personal Data from them. If we learn that a child under 13 has provided Personal Data, we will delete it. Please contact us if you believe we have collected such data.
If you are between 13 and 17 years old, you must obtain permission from a parent or legal guardian before using RMD. Parents and guardians are responsible for monitoring their children’s use of the Services.
California privacy rights (CPRA) – detailed rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request information about the categories and specific pieces of personal information we collect, use, disclose, or sell. Because most of your data is stored locally in your browser, we may have limited access to your personal information unless you have created an account or contacted support.
- Right to Delete: You may request deletion of your personal information. Most data can be deleted directly through your browser settings or RMD’s interface. For account-related data, contact us to request deletion.
- Right to Correct: You may request correction of inaccurate personal information. Most data can be corrected directly in RMD’s interface.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. We may share data with Google Gemini for processing your requests, which may be considered “sharing” under CPRA. You have the right to opt out of the sale or sharing of your personal information. You may opt out of AI processing, though this may limit functionality. To opt out, you can use the “Do Not Sell or Share My Personal Information” link in our cookie banner, or contact us directly at matt@rhinestonemine.com with “Opt-Out Request” in the subject line.
- Right to Limit Sensitive Personal Information: You may request limits on the use of sensitive personal information. Contact us to exercise this right.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CPRA rights.
We do not sell Personal Data and have no actual knowledge of selling Personal Data of consumers under 16. Authorized agents may submit requests on your behalf if they provide evidence of authorization.
To exercise these rights, email us at matt@rhinestonemine.com with “CPRA Request” in the subject line. We will respond within 45 days and may request verification of your identity.
California Shine the Light Act
California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. As of the effective date of this policy, we do not share personal information with third parties for their direct marketing purposes. If this practice changes in the future, we will update this policy and provide California residents with an opportunity to opt out.
To make a Shine the Light request, please contact us at matt@rhinestonemine.com with the subject line “Shine the Light Request.”
Virginia privacy rights
Virginia residents have rights under the Virginia Consumer Data Protection Act (VCDPA), including the rights to confirm whether we process your Personal Data, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of Personal Data, or profiling in furtherance of decisions with legal effects. To appeal a decision, email us at matt@rhinestonemine.com with the subject line “VCDPA Appeal.”
Other U.S. state privacy rights
Residents of states such as Nevada, Colorado, Connecticut, Utah, and others may have additional rights to access, correct, delete, or limit the sale or disclosure of Personal Data. Contact us to learn how these rights apply to you.
International users
If you access RMD from the European Economic Area (EEA), United Kingdom, Switzerland, Brazil, South Korea, Indonesia, the United Arab Emirates, Vietnam, South Africa, the Philippines, Egypt, Mexico, or other jurisdictions with data protection laws, you may have specific rights regarding your Personal Data, including rights to access, rectify, delete, restrict processing, object, withdraw consent, or lodge complaints with regulators. We process Personal Data on legal bases such as contract performance, legitimate interest, consent, and legal obligation. We may transfer Personal Data to the United States or other countries with appropriate safeguards, including standard contractual clauses.
To exercise these rights or request information about cross-border transfers, contact us using the methods below. We may request additional information to verify your identity before processing your request.
Exercising your rights
To submit a privacy request, email us at matt@rhinestonemine.com. Provide enough detail to verify your identity and describe your request so we can respond appropriately. We may deny requests that are unfounded, excessive, or prohibited by law. We respond within the timeframe required by applicable regulations.
Contact us
If you have questions or concerns about this Privacy Policy or our data practices, reach out at matt@rhinestonemine.com.