Privacy Policy

Last updated: July 4, 2026

This is a template policy for a self-hosted Genavoo deployment. The operator of this instance controls the infrastructure and should adapt it to their actual data practices and jurisdiction.

What we store

Your account (name, email, and a hashed password), the workspaces you belong to, and the projects, prompts, and assets you create. Assets are stored in the instance operator's own storage. Passwords are hashed with scrypt and never stored in plain text.

Third-party model providers

When the operator configures provider keys (e.g. fal.ai, OpenAI, Pexels), the prompts and reference images for a generation are sent to that provider to produce a result, subject to their own privacy terms. Without keys, generation falls back to a local preview renderer and nothing leaves the instance.

Cookies

A single httpOnly session cookie keeps you signed in. No third-party advertising or tracking cookies are used.

Your choices

You can delete individual assets at any time, and workspace admins can remove members. To delete your account or export your data, contact the operator of this instance.