Privacy Policy
Version 1.3 · Effective 2026-08-08
This Privacy Policy explains what personal data IceFold collects, why, how we use it, and the choices you have. We aim to collect the minimum needed to run the Service reliably.
1. Data we collect
We collect the following categories of data:
- Account data — your user id, username, login email address, and a salted password hash.
- Flow data — the graphs, node configurations, prompts, and media you create or upload.
- Usage data — per-request LLM metering (tokens in/out, provider, model) so we can show your usage, enforce credit limits, and prevent abuse.
- Payment data — when you buy a paid plan, our payment processor collects billing information and returns a subscription id to us. We never see your full card number.
- Diagnostic data — basic request logs (timestamps, endpoints, status codes) kept for a limited period for troubleshooting and abuse prevention.
2. How we use your data
We use the data listed above to: operate and improve the Service, keep it secure, enforce quota and prevent abuse, process payments, provide support, and comply with legal obligations. We do not sell your personal data.
3. Third-party AI providers
When you run a node that calls an external AI provider, the input you supply (prompt text, reference media, parameters) is forwarded to that provider under IceFold’s own provider accounts to produce the requested output.
IceFold only works with AI providers that contractually commit to zero data retention: they process your input solely to return the requested output and do not store it, log it beyond the active request, or use it to train their models.
IceFold normally stores only metadata about each call (timestamps, model, token counts, credits charged, success/failure) for the credits ledger and usage dashboards. Prompt and response bodies are stored when you save them as part of your flow, or temporarily when an administrator enables diagnostic tracing to investigate a service problem; diagnostic tracing is disabled by default.
4. Cookies and local storage
We use first-party cookies and the browser's localStorage to store your session and user preferences (theme, layout, notes font). The legal-document versions you accepted and the acceptance timestamp are retained on your account for audit purposes. We do not use third-party advertising or tracking cookies.
5. Data sharing
We share data only with the service providers that help us run IceFold (hosting, payment processing, AI providers you call, customer support tooling). Each processor is bound to use the data only to perform the services we engage them for.
We may disclose data where required by law, or where we have a good-faith belief that doing so is necessary to protect the rights, property or safety of IceFold, our users, or the public.
6. Retention
We keep account data and User Content for as long as your account is active. Diagnostic logs and LLM usage metadata are retained for a rolling window (typically 90 days). When you delete your account or invoke "Delete all my data" from Settings, we purge your User Content and account record on a short timeline, subject to legal or accounting retention requirements.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. Most of these are self-service via Settings > Profile; for anything else, contact us via Support.
8. International transfers
Your data may be processed in countries other than the one where you live. Where required, we rely on appropriate legal mechanisms (such as standard contractual clauses) to protect data transferred across borders.
9. Children
The Service is not directed at children under the age of 13 (or the applicable minimum digital consent age). We do not knowingly collect personal data from children. If you believe a child has given us personal data, please contact Support and we will delete it.
10. Changes to this Policy
We may update this Privacy Policy. When we make material changes, we will bump the version number and re-prompt you for consent on your next visit.
11. Contact
For privacy questions or to exercise your rights, reach us via Settings > Support.
