Legal

Privacy Policy

Last updated: March 16, 2026

ProductScene (“we”, “us”, or “our”) operates productscene.com. This policy explains what data we collect, why we collect it, and how we protect it.

1. Information We Collect

Account data

When you sign up, we collect your email address and, if you use Google OAuth, your name and profile photo. This is used to identify your account and personalise your experience.

Product images

You upload product photos to use our service. These images are stored in Supabase Storage and are associated with your account. We use them solely to generate your product gallery — we never use your images to train AI models or share them with third parties.

Generated images

Images generated by ProductScene are stored in Supabase Storage under your workspace. You retain full ownership of all generated images.

Usage data

We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the service. We use PostHog for anonymous product analytics.

Payment data

Payments are processed by Stripe. We do not store card numbers or banking information. We receive a token from Stripe representing your payment method along with billing details you provide.

2. How We Use Your Data

  • To provide and operate the ProductScene service
  • To process payments and manage your subscription
  • To send transactional emails (generation complete, credit alerts, billing receipts)
  • To respond to support requests
  • To monitor for abuse and enforce our Terms of Service
  • To improve the product through aggregate, anonymised analytics

We do not sell your data. We do not use your data for advertising.

3. Third-Party Services

We use the following sub-processors to deliver the service:

  • Supabase — database, authentication, and file storage
  • Google (Gemini API) — AI image generation
  • Stripe — payment processing
  • Brevo — transactional email delivery
  • Sentry — error monitoring
  • PostHog — anonymous product analytics (EU-hosted)
  • Hetzner — server infrastructure (EU)

Each sub-processor is contractually bound to process your data only as instructed and to protect it appropriately.

4. Data Retention

We retain your account data for as long as your account is active. If you request account deletion, we will delete your personal data and all associated product and generation images within 30 days.

Generation revision history is retained for 30 days before automatic deletion.

5. Your Rights (GDPR)

If you are located in the European Economic Area, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Export your data in a machine-readable format

To exercise any of these rights, email us at privacy@productscene.com.

6. Cookies

We use essential cookies to maintain your session. We do not use third-party advertising or tracking cookies. PostHog analytics uses a first-party cookie that can be opted out of via your browser settings.

7. Security

All data is transmitted over HTTPS. Stored images are accessible only via short-lived signed URLs. Access controls ensure that users can only access their own data.

8. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or with a notice in the product. Continued use after changes take effect constitutes acceptance.

9. Contact

Questions about this policy? privacy@productscene.com