LEGAL

Privacy Policy

Effective date: May 30, 2026

1. Who We Are

This Privacy Policy explains how CutiePy (“CutiePy,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information through the cutiepy.org website, the CutiePy desktop application, the FlatLine debugger, and related services (collectively, the “Service”). It applies in addition to our Terms of Service.

2. Information We Collect

2.1 Information you provide

  • Account information. Name, email address, friendly display name, hashed password, and, where applicable, billing details handled by our payment processor.
  • Mobile phone number. When you opt in to text messaging through a sign-up form, your account settings, or a support request.
  • Communications. Email, SMS, and contact-form messages you send us, including their content and any attachments.
  • User Content. Code, prompts, files, images, audio, and other material you submit to the Service or to an AI feature.

2.2 Information collected automatically

  • Site analytics. Page URL, referrer, user-agent, approximate IP-derived geolocation, and interaction timestamps. The site uses Google Tag/Analytics (see js/gtag.js); you can opt out using browser controls or the Google Analytics opt-out add-on.
  • Application telemetry. The CutiePy desktop application and FlatLine debugger may write local diagnostic logs (lifecycle phase traces, freeze detection snapshots, crash reports). These logs stay on your machine unless you choose to send them to us, except for anonymous version-check pings that report only the application version and operating system.
  • Cookies / session storage. We set a PHPSESSID session cookie to keep you signed in, and short-lived cookies for security and CSRF protection. We do not use third-party advertising cookies.

2.3 Information from third parties

If you authenticate using a third-party identity provider, we receive only the profile data you authorize that provider to share (typically email address and display name). Payment processors share transaction confirmations and the last four digits of your card; we never receive your full payment-card number.

3. How We Use Information

  • Provide, maintain, and improve the Service.
  • Authenticate you, secure your account, and detect fraud or abuse.
  • Process payments, refunds, and account changes.
  • Send transactional messages (security alerts, billing notices, support replies) by email and, if you opted in, by SMS.
  • Send product-update and release announcements that you may unsubscribe from at any time.
  • Process content you submit to AI features through the relevant third-party AI provider.
  • Comply with legal obligations and enforce our Terms.

4. Third-Party AI Model Providers

When you use an AI feature in cutiepy.org or the CutiePy desktop application, the prompt, file, image, or audio you submit is transmitted to the third-party AI provider that powers that feature. Providers we currently use include:

  • OpenAI — chat, embeddings, transcription, image generation (privacy)
  • Anthropic — Claude chat (privacy)
  • Microsoft Azure OpenAI — image generation, chat (privacy)
  • Google — Gemini chat (privacy)
  • ElevenLabs — speech-to-text and text-to-speech (privacy)

Each provider processes data under its own privacy policy and contractual data-handling commitments. We do not retain a copy of your prompt beyond what is required to display the response to you in your current session, unless you explicitly save it (for example, by storing it in your account).

5. SMS / Text Messaging Data — No Resale of Opt-In Data

CutiePy does not sell, rent, share, lease, lend, or otherwise transfer mobile opt-in data, mobile phone numbers, or SMS consent records to any third party for marketing or promotional purposes. This restriction applies in addition to every other limit described in this Policy and is not subject to the “Service Providers” or “Business Transfers” exceptions below, except that we may share the minimum mobile information necessary with our SMS gateway provider solely to deliver the messages you have requested.

To stop receiving SMS, text STOP (or END, CANCEL, UNSUBSCRIBE, or QUIT) to the originating code, or email support@cutiepy.org with “STOP” in the subject. Text HELP for program information. Message and data rates may apply; message frequency varies. Full SMS terms appear in our Terms of Service.

6. How We Share Information

We share personal information only as described below:

  • Service providers. Hosting (web host, content delivery), email delivery (SMTP), SMS gateway, payment processors, analytics, and AI model providers, each under written agreements that restrict use to providing the service to us. (See the carve-out in Section 5: this category does not apply to mobile opt-in data beyond the SMS gateway.)
  • Legal compliance. When required by law, subpoena, or government request, or to protect the rights, safety, or property of CutiePy, our users, or the public.
  • Business transfers. If CutiePy is acquired, merged, or sells substantially all assets, your information may transfer to the successor entity, subject to the same protections. (Same SMS carve-out as above.)
  • With your consent. Any other sharing only with your express consent.

We do not sell personal information for monetary or other valuable consideration as defined by the California Consumer Privacy Act, and we do not share personal information for cross-context behavioral advertising.

7. Data Retention

Account data: retained while your account is active and for up to 90 days after deletion to allow recovery, then permanently deleted or anonymized. Billing records: retained for as long as required by tax and accounting law (typically 7 years). SMS consent records: retained for at least 4 years to satisfy TCPA record-keeping requirements. Server logs: rotated after 30 days. AI prompts and responses: not retained beyond your active session unless you explicitly save them.

8. Security

We protect personal information with TLS-encrypted transport, Argon2-hashed passwords, role-based access controls, restricted server access, and periodic security review. No internet service can be guaranteed perfectly secure; if you believe your account has been compromised, contact legal@cutiepy.org immediately.

9. Your Rights

9.1 California (CCPA/CPRA)

If you are a California resident, you have the right to (a) know what personal information we collect about you, (b) request a copy of that information, (c) correct inaccurate information, (d) request deletion, (e) opt out of sale or sharing (we do not sell or share — see Section 6), and (f) not be discriminated against for exercising these rights. To exercise these rights, email legal@cutiepy.org. We respond within 45 days and may extend by another 45 days where permitted. We verify requests against the email on file.

9.2 European Economic Area / United Kingdom (GDPR / UK GDPR)

If you are in the EEA, UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection under Articles 15–22 GDPR. Where processing relies on consent, you may withdraw consent at any time without affecting prior lawful processing. Our lawful bases include performance of a contract (account features), legitimate interests (security, product improvement), consent (marketing email, SMS, optional analytics), and legal obligation. To exercise these rights, email legal@cutiepy.org. You may also lodge a complaint with your local supervisory authority.

9.3 Other jurisdictions

If your jurisdiction grants additional or different privacy rights, we will honor them as required by applicable law. Send requests to legal@cutiepy.org.

10. International Data Transfers

CutiePy is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or equivalent safeguards where required.

11. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact legal@cutiepy.org and we will delete it.

12. Do Not Track

We honor the “Global Privacy Control” signal from browsers that send it, by treating it as an opt-out of any sale/sharing under the CCPA. Because there is no consistent industry standard for legacy “Do Not Track” headers, we do not separately respond to them.

13. Changes to This Policy

We may update this Policy from time to time. Material changes will be posted here with a revised “Effective date.” We will notify account holders by email for changes that materially expand how we use personal information.

14. Contact

Privacy questions and rights requests: legal@cutiepy.org
Support: support@cutiepy.org
Phone: 724‑431‑5207