Privacy Policy

Last updated 2 September 2026

What we collect

Your email address and a hashed password, so you can sign in. Passwords are hashed with Argon2 and are never stored or logged in plain text.

The character files you upload, the prompts you write, and the animations we generate for you.

Basic operational logs: request times, error messages and job durations. These do not contain your prompts or file contents.

What we do not do

We do not train models on your uploads, your prompts or your generated animations.

We do not sell your data, and we do not share it with advertisers.

Who we share it with

Stripe processes payments. They receive your email and billing details directly; we never see or store your card number.

If a prompt is too open-ended for our own parser to read, the prompt text alone is sent to a language-model provider to interpret it. Your character files are never sent anywhere outside our own infrastructure. You can see which provider is configured on the service status endpoint.

Our hosting and object-storage providers hold the data at rest on our behalf.

How long we keep it

Uploaded characters and generated animations are kept while your account is open, so you can re-download them.

Deleting a character removes its file and its generated outputs. Deleting your account removes everything except the billing records we are legally required to retain.

Your rights

You can export or delete your data at any time from your account, or by asking us. We will respond within 30 days.

If you are in the EU or UK, you also have the right to object to processing and to lodge a complaint with your data protection authority.

Security

Traffic is encrypted in transit. API keys are stored as keyed digests, not as recoverable secrets, which is why a key is shown only once when created.

If we ever have a breach affecting your data, we will tell you without undue delay.

Questions? Reply to any email from us, or reach the team through the address on your receipt. Back to Mocapless