Privacy Policy
Draft revised September 9, 2026
Pre-launch draft. Refund rules and data-processing disclosures remain incomplete. Do not purchase or submit sensitive material until these policies are finalized.
Scope and operator
This notice concerns Sunburst Image at sunburstimage.com, an independent GPT Image 2.5 image-generation and reference-editing website. Read it with the Terms of Service. This pre-launch draft identifies sunburstimage.com as the operator. Send privacy requests to [email protected]. The outstanding processing disclosures below remain under review.
Information the service processes
- Account information, when account functions are used: sign-in identifiers, profile details supplied by the chosen sign-in method, authentication records and sessions.
- Creation content: prompts, reference-image files or links, selected settings, generated images, task identifiers, task status and error information.
- Billing information: customer and transaction identifiers, subscription status, credit balances and ledger activity, and payment or refund records returned by Stripe. Payment details entered in Stripe’s checkout are processed by Stripe.
- Technical and security information: request and device information, IP-related information, session cookies, anti-abuse checks and operational events used to run and protect the service.
- Correspondence you choose to send to [email protected].
Avoid including passwords, identity documents, confidential business material, medical information or unnecessary information about other people in prompts or images. Only upload material you are authorized to share for external processing.
Generation suppliers and storage
The current GPT Image 2.5 integration sends prompts, image settings and reference-image URLs to Miaochuang (秒创). The supplier processes the request and returns task or output data. Its own upstream arrangements, retention, training use and processing locations have not been verified for this service. This notice therefore makes no promise that supplier processing stays in a particular country or excludes training.
The application records generation state and credit activity in its database and uses S3-compatible object storage for uploaded and generated media. Media may be delivered through accessible URLs, including supplier URLs. A URL that works for a recipient can be copied or shared; do not assume that unlisted or undisplayed content is access-controlled. The actual production storage provider, regions, link-access controls and deletion behavior must be confirmed before launch.
Infrastructure, account, email and payment providers may process data needed to supply those functions. Stripe is integrated for checkout and billing. Sign-in providers process authentication when you choose their sign-in option. A final notice must identify the deployed providers and relevant transfer safeguards; the presence of an integration in source code does not establish that it is active.
Purposes and unresolved legal bases
The intended purposes are to authenticate users, fulfill requested image creation and delivery, maintain task history and balances, process purchases, investigate errors, prevent abuse and handle support or lawful requests. The operator must determine and publish the legal bases applicable to each purpose and market before launch. This draft does not treat use of the site as consent to every possible processing purpose.
Cookies, local storage and analytics
The application uses session and preference mechanisms and may save creation drafts in browser storage to help resume work. Clearing browser storage can remove local drafts and sign-in state; it does not necessarily delete server or supplier copies.
Analytics integrations are configurable. These include OpenPanel and, when configured for production, Google Analytics, Umami, Plausible, Ahrefs, DataFast, Seline and Microsoft Clarity. Some tools can process interaction or session-replay data. This is a code inventory, not a claim that all tools are active. The production inventory, consent controls, sensitive-content masking and opt-out behavior have not been verified. Non-essential analytics must not be enabled for launch without the required disclosure and controls for the markets served. This draft does not promise that browser privacy signals are honored by every integration.
Public display and training
Where offered, the public-display option concerns selecting a generated image for a site showcase. It is distinct from processing by the generation supplier and the accessibility of stored media links. The operator must verify the actual publication controls before relying on that setting.
Neither operator nor supplier training and reuse practices have been established by this review. No blanket “never used for training” or “never shared” promise is made. Confirm these practices and update this notice before accepting confidential or sensitive content.
Retention and deletion
No verified retention schedule exists for prompts, uploaded images, outputs, task records, security logs, billing records, caches or backups in this draft. Account deletion is implemented in the authentication layer, but complete deletion of object storage, supplier copies and backups has not been demonstrated. Deleting an account or clearing a local draft must not be described as guaranteed immediate erasure everywhere.
Before launch, the operator must set and publish retention periods or meaningful criteria, establish deletion procedures and exceptions, and verify processor handling. Keep your own copies of outputs you need. The site is not a guaranteed permanent archive.
Your choices and requests
Depending on the law that applies to you, you may have rights concerning access, correction, deletion, restriction, portability, objection or withdrawal of consent, and a right to complain to an appropriate authority. The precise scope depends on the processing and jurisdiction; no jurisdiction is assumed in this draft.
Send privacy requests to [email protected], handled by sunburstimage.com. No response deadline is established by this draft. Only proportionate information should be requested to verify identity.
Security, children and changes
Security controls reduce risk but do not guarantee that data cannot be lost, accessed or disclosed. This draft describes an adult-oriented service, not a service intended for children. The operator must establish an appropriate process for reporting and handling unintended child data.
The date shown above is a revision date for this draft. A final notice must state its effective date, identify the operator and contact channel, complete the outstanding disclosures and explain material updates. See the Refund Policy for billing-related issues.