Privacy Policy
Last Updated: June 23, 2026
This Privacy Policy explains how MICT (Make Ideas Come True) collects, uses, stores, and shares information when you use our website, applications, APIs, and related services (collectively, the Service).
1. Scope
This Privacy Policy applies to information we collect when you access or use the Service, create an account, purchase a plan, submit prompts or uploads, generate content, contact us, or otherwise interact with MICT.
2. Information We Collect
Account and Profile Information
When you sign in or create an account, we may collect:
- your email address;
- display name, nickname, or profile image;
- account identifiers such as your user UUID;
- authentication provider details such as the provider used to sign in; and
- account creation and sign-in metadata.
MICT currently supports third-party sign-in methods such as Google and GitHub when enabled.
Inputs, Uploads, and Generation Data
When you use AI generation features, we may collect and store:
- prompts and other text you submit;
- uploaded images or image URLs;
- generation settings and parameters such as model, mode, duration, resolution, aspect ratio, output count, quality, and audio settings;
- task identifiers, job status, error messages, and timing metadata; and
- result URLs and generation history.
Billing, Subscription, and Credits Data
If you purchase a plan or otherwise receive paid or promotional value, we may collect and store:
- checkout session identifiers;
- subscription identifiers and billing status;
- invoice, order, and payment metadata;
- pricing plan and plan code information;
- credits balance, credits usage, credits grants, credits reversals, and related ledger entries; and
- limited billing information provided by our payment processor.
We do not store your full payment card number.
API and Access Data
If you use MICT programmatically, we may collect:
- API key identifiers and usage associated with those keys;
- request metadata required to authenticate and process API access; and
- operational logs needed for abuse prevention, debugging, and service reliability.
Support, Feedback, and Communications
If you contact us or submit feedback, we may collect:
- the contents of your message;
- any attachments or screenshots you send;
- rating or satisfaction information you provide; and
- records of our communications with you.
Device, Usage, and Analytics Data
We may automatically collect technical and usage information such as:
- IP address and approximate location derived from IP;
- browser type, device type, operating system, and language preferences;
- pages viewed, links clicked, referral sources, and session events;
- cookie or similar identifier data; and
- diagnostics, crash, performance, and anti-abuse information.
In production, MICT may use analytics and behavior analytics tools such as Google Analytics, OpenPanel, Plausible, and Microsoft Clarity when configured. These tools may process page views, clicks, referral sources, session events, device information, and, for behavior analytics, heatmaps or session recordings. Sensitive content masking and provider-side privacy controls may apply depending on the provider configuration.
3. How We Use Information
We use information we collect to:
- provide, operate, maintain, and improve the Service;
- authenticate users and secure accounts;
- process generations and return outputs;
- process billing, subscriptions, and credits;
- detect, prevent, and investigate fraud, abuse, security incidents, and policy violations;
- monitor performance, debug issues, and maintain system reliability;
- communicate with you about your account, purchases, changes, support requests, and product updates;
- comply with legal obligations and enforce our Terms; and
- develop new features, pricing, and product experiences.
Depending on your jurisdiction, we may rely on one or more legal bases to process data, including performance of a contract, legitimate interests, consent, and compliance with legal obligations.
4. How Information Flows Through Third Parties
MICT depends on third-party providers to operate the Service. Depending on the feature you use, we may share relevant data with:
- authentication providers such as Google or GitHub;
- payment processors such as Stripe;
- infrastructure and data storage providers such as Supabase or S3-compatible storage providers;
- analytics and behavior analytics providers such as Google Analytics, OpenPanel, Plausible, or Microsoft Clarity; and
- upstream AI model or aggregation providers used to process your generation requests, including providers used through our AI generation stack.
For example, when you submit a prompt or upload an image for generation, that prompt, image, and related settings may be sent to the upstream provider needed to process that request.
We may also send prompts, uploaded images, and limited request metadata to automated safety and moderation providers to determine whether a request can be processed safely and in compliance with our policies and provider requirements.
5. Storage and Visibility of Uploaded or Generated Content
MICT stores different types of content in different systems, including database records, cloud storage, and provider-hosted result locations.
Important notes:
- uploaded images may be stored using cloud storage URLs generated by our storage layer;
- generated outputs may be returned or hosted through upstream provider result URLs or storage locations;
- moderation decisions, provider policy outcomes, and limited diagnostic payloads may be stored in internal logs for abuse prevention, support handling, refund decisions, and compliance review;
- anyone who obtains a direct public URL to an uploaded file or generated asset may be able to access that asset, depending on how the underlying storage or provider link is configured; and
- for that reason, you should not upload or generate highly sensitive personal, confidential, or regulated content unless you have assessed the associated risk.
6. Cookies and Similar Technologies
We and our service providers may use cookies and similar technologies to:
- keep you signed in;
- remember preferences such as UI state;
- measure traffic and usage patterns;
- support analytics and attribution; and
- improve performance and reliability.
You can usually control cookies through your browser settings, but disabling cookies may affect how the Service functions.
7. Data Sharing
We do not sell your personal information for money.
We may share information:
- with service providers and subprocessors that help us operate the Service;
- with upstream AI providers as needed to process your requests;
- with safety and moderation providers that help us review prompts, uploads, and policy-related generation outcomes;
- with payment, authentication, analytics, and infrastructure providers;
- if required by law, legal process, or government request;
- to protect the rights, safety, and security of MICT, our users, or others;
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets; or
- with your direction or consent.
8. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including to:
- maintain active accounts and generation history;
- keep safety, moderation, and anti-abuse audit records reasonably necessary to investigate disputes, enforce policy, and process refunds;
- keep billing, order, subscription, and credits records;
- investigate disputes, fraud, or abuse;
- satisfy legal, tax, accounting, or compliance obligations; and
- enforce our agreements.
Retention periods may vary depending on the type of data and the context in which it was collected.
9. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
You are responsible for keeping your account credentials and API keys secure.
10. International Data Transfers
Your information may be processed in countries other than where you live. Those countries may have data protection laws that differ from those in your jurisdiction.
Where required, we take steps designed to support lawful cross-border data transfers.
11. Your Rights and Choices
Depending on where you live, you may have rights to:
- access information we hold about you;
- request correction of inaccurate information;
- request deletion of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- request a copy of certain data where applicable law provides that right.
To exercise rights available to you, contact us through any support, feedback, social, or contact channel that MICT makes available on the website or in the Service. We may need to verify your identity before acting on your request, and some requests may be limited by law, security, fraud-prevention needs, or the rights of others.
12. Children's Privacy
The Service is not directed to children under the age at which they may legally use the Service in their jurisdiction without required parental or guardian authorization. If you believe a child has provided us personal information unlawfully, contact us so we can review the situation.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version and update the "Last Updated" date above. Your continued use of the Service after the updated Policy becomes effective means you acknowledge the revised Policy.
14. Contact
If you have questions or requests relating to this Privacy Policy, please contact MICT through any support, feedback, social, or contact channel that MICT makes available on the website or in the Service.