Privacy Policy
Last updated
This Privacy Policy describes how [271DEV LLC] ("2.71," "we," "us," or "our") collects, uses, and shares personal information in connection with the website at https://studio.271.dev, the 2.71 Studio, and any related services that link to this Privacy Policy (together, the "Service").
Jurisdiction-specific notices for residents of the United States, the European Economic Area, the United Kingdom, Switzerland, Canada, Australia, New Zealand, and other countries appear at the end of this Privacy Policy.
1. Personal information we collect
Information you provide to us
- Account information. When you register we collect your email address, a display name, and a password. Passwords are stored in hashed form; we never see them in clear text.
- Social login information. If you sign in with Google, Discord, or X, the provider shares your name, email address, profile picture, and provider account identifier with us, according to your settings with that provider.
- Payment and transaction information. Card and wallet payments are processed by our payment processor, Polar. We receive transaction identifiers, the product purchased, amount, currency, status, and subscription state, but not your full card number. Cryptocurrency payments are processed by NOWPayments; we receive the payment identifier, currency, amount, status, and blockchain transaction references.
- Content you create. Text prompts, character definitions and settings, reference images you upload, images and videos generated for you, generation settings (models, styles, resolution), and titles or descriptions you add.
- Communications. Messages you send us, for example support requests, feedback, or legal notices.
Information we collect automatically
- Device and connection data. IP address, browser type and version, operating system, screen size, language, and similar technical data.
- Approximate location. Country and region derived from your IP address.
- Usage data. Pages viewed, features used, generations requested, coins spent, timestamps, and referring URLs.
- Session replays and error reports. We use Sentry to record errors and, to help us diagnose problems, to capture replays of user sessions (page navigation, clicks, and the content shown on screen at the time). Replays may include text and images displayed in your browser, including your prompts and generated content, and are associated with your account.
- Analytics. We use Vercel Web Analytics, which collects aggregated page-view and visitor data without cross-site tracking cookies.
- Email engagement. Emails we send may include a tracking pixel and tracked links that tell us whether the email was opened and which links were clicked.
- Referral and attribution data. If you arrive through a referral, affiliate, or campaign link, we store the referral code, campaign parameters, referrer, and landing page in a cookie for 90 days and associate them with your account when you sign up, so we can credit referrals and measure marketing. We also record funnel events (for example, sign-up, first generation, first purchase) linked to that attribution.
Information from other sources
- Social login providers, as described above.
- Payment processors, which send us payment status updates and fraud or dispute information.
- Referral partners, who may tell us that you were referred by them (we do not receive personal information about you from them beyond the referral itself).
2. Cookies and similar technologies
We use cookies and similar technologies to operate the Service. None of them are used for third-party advertising.
- Session cookies (strictly necessary) keep you signed in and protect your account. They expire when your session ends or when you sign out.
site-unlocked(strictly necessary) is used only on pre-release environments protected by a password. It lasts one year.user_attr(functional) stores referral and campaign attribution for 90 days, as described in Section 1.- Sentry (functional) may set identifiers used to group errors and session replays.
- Vercel Web Analytics (analytics) uses a hashed, short-lived identifier rather than a persistent cookie.
You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent you from signing in or entering the Service.
Do Not Track and Global Privacy Control. We do not currently respond to "Do Not Track" signals. Because we do not sell personal information or share it for cross-context behavioral advertising, browser-based opt-out signals such as Global Privacy Control do not change how we process your information.
3. How we use personal information
We use personal information for the following purposes:
- Providing the Service. To create and manage your account, generate the content you request, store and deliver your generations and characters, manage coins and subscriptions, process payments, and provide customer support.
- Safety and content moderation. To review prompts and images, automatically and by staff, in order to detect and block content that violates our Terms of Service or the law, in particular any content involving minors and non-consensual content depicting real people. We keep records of blocked requests (including the prompt, any reference image, and the reason) to enforce our rules, identify repeat abuse, and meet our legal obligations.
- Communicating with you. To send transactional messages such as welcome emails, password resets, purchase confirmations, and subscription reminders, and to respond to your requests. We only send marketing communications where permitted by law, and you can opt out at any time.
- Improving the Service. To understand how the Service is used, diagnose errors, measure performance, and develop new features.
- Referral and marketing measurement. To attribute sign-ups and purchases to referral partners and campaigns and to calculate any commissions owed to them.
- Compliance and protection. To comply with applicable laws (including content laws), respond to lawful requests from authorities, enforce our Terms of Service, detect and prevent fraud, abuse, and security incidents, and protect the rights, safety, and property of 2.71, our users, and others.
- Aggregated and de-identified data. To create aggregated or de-identified data that no longer identifies you, which we may use and share for any lawful purpose.
AI training. We do not use your prompts, reference images, or generated content to train AI models. Our AI service providers process this content only to provide their services to us.
4. Automated decision-making
We use automated systems to screen prompts and images before generation and to estimate the apparent age of people depicted in uploaded reference images. If a request is blocked, you will be told at the time. Automated decisions may affect your ability to use certain features and, in cases of serious or repeated violations, may lead to suspension of your account. You can ask for human review of an automated decision by contacting us at legal@271.dev.
5. How we share personal information
We do not sell personal information. We share it only as follows:
- Service providers that process personal information on our behalf, under contract, to help us operate the Service:
- Hosting and infrastructure: Vercel, Railway, Neon (database), and Cloudflare (storage of uploaded and generated media).
- AI compute and model providers: RunPod (image and video generation), Venice and OpenRouter (prompt processing, enhancement, and moderation).
- Content-safety providers: Everypixel and our self-hosted age-estimation service (analysis of reference images).
- Monitoring, tracing, and analytics: Sentry, LangSmith, and Vercel.
- Email delivery: Resend.
- Internal operations: Discord, which we use to receive automated alerts about sign-ups, purchases, and generations that include the account email address.
- Payment processors (Polar and NOWPayments), which process your payment information as independent controllers under their own privacy policies.
- Social login providers (Google, Discord, X), which receive a record of your sign-in under their own privacy policies.
- Referral partners, who receive only aggregate or pseudonymous information about referred sign-ups and purchases, never your name, email, or content.
- Authorities and other parties for legal reasons, where required by law, legal process, or to protect rights and safety. We report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) and cooperate with law enforcement as required by law.
- Professional advisors, such as lawyers, auditors, and insurers, where necessary.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to the acquiring or successor entity.
6. Retention
We keep personal information for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. Generated content and private characters are kept until you delete them or close your account. Characters you have made public may remain available to other users after you close your account, without your display name or other information that identifies you; make a character private before closing your account if you want it deleted. Records of moderation actions and blocked requests may be retained longer where needed for safety, enforcement, and legal compliance. Payment records are retained as required by tax and accounting laws.
7. Your choices
- Access and update. You can review and update your account information in your profile settings.
- Delete content. You can delete characters and generations from within the Service.
- Close your account. To close your account and request deletion of your personal information, email us at legal@271.dev from the address associated with your account. We will delete or anonymize your information within a reasonable time, except where we must keep it for the reasons described in Section 6. Public characters are handled as described in Section 6.
- Marketing. You can opt out of marketing emails by using the unsubscribe link in the email or by contacting us. You will still receive transactional messages.
- Cookies. See Section 2.
- Social login. You can manage what a social login provider shares with us through your settings with that provider. Revoking access does not affect information we already received.
- Declining to provide information. Some information is required to use the Service; if you do not provide it, we may not be able to serve you.
Response times. We respond to requests to exercise your privacy rights within one month (or within 45 days for requests under U.S. state privacy laws). If a request is complex or we receive many requests, we may extend this period where the law allows and will tell you if so.
8. Security
We use technical, organizational, and physical safeguards designed to protect personal information. Data is encrypted in transit using TLS and at rest by our database and storage providers (Neon and Cloudflare), whose infrastructure is independently audited under SOC 2. Passwords are stored only as salted hashes. Access to production systems and personal information is limited to staff who need it, and we monitor for security incidents. No system is perfectly secure, and we cannot guarantee the security of your information.
9. International data transfers
We are based in the United States and use service providers located in the United States and other countries. Your personal information may be transferred to and processed in countries whose privacy laws differ from those where you live. Where required, we rely on appropriate safeguards for such transfers, as described in the regional notices below.
10. Children
We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information or has accessed the Service, contact us at legal@271.dev and we will take appropriate action, including deleting the information.
11. Other sites and services
The Service may link to third-party websites and services, including social login providers and payment processors. We are not responsible for their privacy practices. Please review their privacy policies.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date at the top of this page and, where appropriate, by email or a notice within the Service. Your continued use of the Service after the effective date of an updated Privacy Policy means you accept the changes.
13. How to contact us
[271DEV LLC]
[Company address], Delaware, United States
Email: legal@271.dev
14. Notice to residents of U.S. states
This section applies to residents of California and other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Montana, Oregon, Texas, Utah, and Virginia) and supplements the rest of this Privacy Policy.
Categories of personal information collected. In the past 12 months we have collected the categories listed in Section 1, which correspond to the following categories under the California Consumer Privacy Act (CCPA): identifiers (name, email, account ID, IP address); customer records (payment and transaction information); commercial information (purchase history); internet or network activity (usage data, session replays); approximate geolocation; audio, electronic, or visual information (uploaded and generated images and videos); inferences (only for content-safety purposes); and sensitive personal information (account credentials).
Sources, purposes, and disclosures. We collect this information from the sources in Section 1, use it for the purposes in Section 3, and disclose it to the categories of recipients in Section 5.
Sale and sharing. We do not sell personal information and do not share it for cross-context behavioral advertising. We have no actual knowledge that we collect personal information of consumers under 16.
Sensitive personal information. We use sensitive personal information only for the purposes permitted by the CCPA, such as providing the Service you request and ensuring safety and integrity. We do not use it to infer characteristics about you.
Your rights. Subject to applicable law, you have the right to: know what personal information we collect, use, disclose, and sell or share; access a copy of your personal information in a portable format; correct inaccurate personal information; delete personal information; opt out of the sale or sharing of personal information and of certain profiling; limit the use of sensitive personal information; and not be discriminated against for exercising these rights. You may appeal a decision we make on your request by replying to our response.
Exercising your rights. Email legal@271.dev from the address associated with your account. We will verify your identity before responding, which may involve confirming control of your account email. An authorized agent may submit a request on your behalf with your written permission; we may still ask you to verify your identity directly.
California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing purposes.
Nevada. We do not sell covered information as defined in Nevada law.
15. Notice to users in the European Economic Area, the United Kingdom, and Switzerland
Controller. [271DEV LLC] is the controller of your personal information for the purposes of the EU General Data Protection Regulation, the UK GDPR, and the Swiss Federal Act on Data Protection (together, "GDPR"). We have not appointed a data protection officer.
Legal bases. We rely on the following legal bases:
- Performance of a contract to provide the Service to you: account management, content generation and storage, coins, subscriptions, payments, and transactional communications.
- Legitimate interests in operating, securing, and improving the Service, moderating content, preventing fraud and abuse, measuring referrals, and enforcing our terms. Our interests do not override your rights and freedoms.
- Consent, where required, for example for marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal obligations, including tax and accounting rules, responding to lawful requests, and reporting illegal content.
Your rights. You may ask us to: provide access to and a copy of your personal information; correct inaccurate information; delete your information; restrict processing; port your information to you or another provider; and object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior processing. To exercise these rights, contact us at legal@271.dev. We may ask you to verify your identity.
Complaints. You have the right to lodge a complaint with your local data protection authority. In the EEA, contact details are available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, the Information Commissioner's Office can be reached at https://ico.org.uk. In Switzerland, the Federal Data Protection and Information Commissioner can be reached at https://www.edoeb.admin.ch.
International transfers. We transfer personal information to the United States and other countries outside Europe. Where the destination has not been recognized as providing adequate protection, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss recognized versions of those clauses, or on another lawful transfer mechanism. Contact us for more information.
Retention. See Section 6.
16. Notice to users in other countries
Canada. We process personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws. By using the Service you consent to the collection, use, and disclosure described in this Privacy Policy, including transfers to service providers outside Canada. You may request access to or correction of your personal information and withdraw consent by contacting us. You may also complain to the Office of the Privacy Commissioner of Canada.
Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Your information may be disclosed to recipients located in the United States and other countries as described in Section 5. You may request access to or correction of your personal information and complain about our handling of it by contacting us; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
New Zealand. We handle personal information in accordance with the Privacy Act 2020. You have the right to access and correct your personal information and to complain to the Office of the Privacy Commissioner.
Other countries. If you are located in a country whose law grants you rights over your personal information (for example Japan, South Korea, Singapore, India, or Latin American countries), you may exercise those rights by contacting us at legal@271.dev. We will honor your request to the extent required by applicable law. By using the Service, you acknowledge that your personal information will be transferred to and processed in the United States.