Caika
HomeGenerationsFavorites

Create

Loading creation tools…

Home
Create
Generations
Favorites
Back to top
← Back to home

Privacy Policy

Last updated: 2026-07-24

This Privacy Policy explains how the operator of Caika ("Caika," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the Caika website, applications, image-generation features, public gallery, subscriptions, credit purchases, and related services (collectively, the "Service").

1. Introduction and Scope

This Policy applies to information processed through the Service. It does not govern third-party websites or services that you choose to visit or use under their own terms and privacy policies.

Caika is an independently operated online service. In this Policy, "Caika," "we," "us," and "our" refer to the operator of the Service. Privacy questions and requests may be sent to support@caika.app.

2. Information We Collect

The information we process depends on how you use the Service. It may include the following categories:

  • Account and profile information, including your name, email address, email-verification status, avatar, preferred locale, and account role.
  • Authentication information, including password hashes (not your readable password), Google OAuth identifiers and tokens where applicable, and records used for magic-link or one-time-code authentication.
  • Session and security information, including session tokens and expiration times, IP addresses, User-Agent strings, and signals used to detect abuse or automated traffic.
  • Generation and content information, including original and enhanced prompts, model selections, generation parameters, uploaded or linked reference images, provider task identifiers, job status, errors, generated images, and related credit events.
  • Billing and transaction information, including your email address, selected product or plan, price, currency, credits, billing period, subscription status, and internal order or customer identifiers. Caika does not store your complete payment-card number.
  • Communications, including support requests, policy notices, authentication emails, and the content and delivery status of messages sent through the Service.
  • Public-gallery and community information, including works you publish, the prompt, model and parameters associated with a published work, your displayed profile name and avatar, and likes or other public interactions.
  • Device and preference information, including essential cookie data, a locally stored theme preference, and the sidebar-state cookie.

3. Sources of Information

We receive information directly from you when you register, sign in, submit prompts or images, purchase credits, manage a subscription, publish a work, or contact us. We also create or collect information automatically when the Service establishes a session, processes a generation job, records a transaction, prevents abuse, or saves a local preference.

We may receive account, payment, generation, moderation, hosting, delivery, and job-status information from the service providers described below, including Vercel, Google, Creem, APIMart, Evolink, KIE.ai for legacy task recovery, Cloudflare, OpenAI when configured, Resend, and Upstash.

4. How We Use Information

We use information to operate and improve the Service, fulfill the transactions and requests you initiate, and maintain the integrity of accounts, credits, and generated content. Uses include:

Where applicable law requires a legal basis, we process information as needed to perform our agreement with you, comply with legal obligations, pursue legitimate interests such as security, fraud prevention, support, and service improvement, or based on consent where we specifically request it. You may withdraw consent for future processing where consent is the applicable basis, without affecting processing already completed.

  • Creating accounts, authenticating users, maintaining sessions, and providing localized settings.
  • Submitting and tracking image-generation jobs, delivering generated images, handling provider failover, and restoring eligible held credits after a failed job.
  • Processing subscriptions and credit purchases, reconciling payment events, applying plan changes, and maintaining billing records.
  • Moderating prompts and images, enforcing our Terms, preventing fraud or abuse, protecting accounts, and diagnosing errors.
  • Operating the public gallery and displaying content and profile information that a user chooses to publish.
  • Sending authentication, transactional, support, billing, and policy-related communications.
  • Complying with applicable legal obligations and responding to valid legal requests.

5. AI Generation and Moderation

Caika uses third-party AI providers to perform image generation. New jobs may send prompts, selected settings, reference-image URLs or image data, and job metadata to APIMart or Evolink. KIE.ai is retained only to finish or recover jobs submitted before the provider cutover. If a new job fails over, the same prompt and reference material may be submitted to APIMart and Evolink at different stages of the request.

When the relevant moderation integration is configured, prompt text may be sent to OpenAI for safety review, and image bytes may be sent to Cloudflare Workers AI for image moderation. Moderation results may be used to reject content, restrict features, or review suspected violations.

These providers process submitted data on infrastructure outside Caika and may keep limited operational or security records under their own terms, configurations, and legal obligations. Do not submit confidential, sensitive, or personally identifying material unless you have the right and a clear need to process it through these services.

6. Service Providers and Disclosures

We disclose information to providers that perform functions needed to deliver the Service. The providers and data involved may include:

Based on the current implementation of the Service, Caika does not sell personal information or disclose it for cross-context behavioral advertising. We will update this Policy and provide any legally required choices before materially changing that practice.

  • Supabase/Postgres for account, session, generation, credit, subscription, and application records.
  • Vercel for hosting the application and invoking scheduled maintenance tasks. Vercel may process request metadata such as IP address, User-Agent, application logs, and application data needed to serve a request or run a scheduled task.
  • Cloudflare R2 for reference and generated image storage. An R2 object URL may be publicly accessible to anyone who has the URL even when it is not indexed or shown in the public gallery.
  • Cloudflare Turnstile for anti-abuse verification and related browser, network, and security signals, and Cloudflare Workers AI for image moderation when configured.
  • APIMart and Evolink for prompts, reference material, model settings, task metadata, and generated outputs needed to perform AI generation; KIE.ai only for finishing or recovering legacy jobs submitted before the provider cutover.
  • OpenAI for prompt moderation when that integration is configured.
  • Creem for payment and subscription processing, including email, product or plan, price, currency, credit quantity, billing period, and internal identifiers. Complete card details are processed by Creem and its payment partners rather than stored by Caika.
  • Resend for sending email addresses and message content needed to deliver authentication, transaction, support, or policy emails.
  • Upstash QStash for asynchronous job delivery, including job identifiers and callback metadata. Caika's queue messages are designed not to include prompts or image content.
  • Google OAuth for sign-in, including Google account identifiers, basic profile information made available by Google, and authentication tokens needed for that sign-in flow.

7. Public Gallery and Shared Content

When you choose to publish a generated work, the work becomes public and may display the generated image, prompt, model, generation parameters, profile name, avatar, likes, and other public interactions. Other people may view, save, copy, share, or independently archive public content. Search engines or external services may also retain copies outside our control.

Removing a work from a Caika view or later deleting an account cannot guarantee deletion of copies previously obtained by other people or third parties. Public works may remain available in a de-identified form after account deletion where they are no longer linked to your active profile.

8. Cookies and Local Storage

The Service uses essential authentication and session technologies to keep you signed in, protect requests, and provide account features. Disabling these technologies may prevent sign-in or other core functions from working.

The Service stores the theme preference in browser local storage and stores the desktop sidebar state in a first-party cookie named sidebar_state for up to seven days. These preferences remain on your device until they expire, you clear site data, or you change them. Caika does not currently rely on a dedicated advertising SDK for the functions described in this Policy.

9. Retention and Deletion

We retain information for as long as reasonably needed to provide the Service, maintain account and transaction records, secure the platform, resolve disputes, enforce agreements, and meet applicable legal obligations. Retention periods vary by data type and by the systems of the providers involved.

Caika does not currently provide a self-service account-deletion control. You may request deletion by emailing support@caika.app from the email address associated with your account. Before requesting account deletion, cancel any active Creem subscription through the available subscription-management flow. Deleting a Caika account does not itself cancel a Creem subscription or stop a future renewal.

Deletion from the primary application database does not automatically delete every R2 object or every copy held by an AI, payment, email, authentication, queue, security, or storage provider. Public works may remain in de-identified form, and content copied or archived by third parties may remain outside our control. We will assess deletion requests under applicable law and the technical and legal limits described in this Policy.

10. International Transfers and Security

Caika and its providers may process information in countries other than the country where you live. Those locations may have different data-protection rules. Where applicable law requires transfer safeguards, we rely on the safeguards made available for the relevant provider and processing relationship.

We use technical and organizational measures appropriate to the nature of the Service, including hashed passwords, session controls, provider access restrictions, and anti-abuse checks. No internet transmission, storage system, or third-party service is completely secure, so we cannot guarantee absolute security. You are responsible for protecting access to your email account, authentication methods, and active sessions.

11. Your Privacy Rights

Depending on where you live, applicable law may give you rights to request access to, correction of, deletion of, restriction of, or a portable copy of certain personal information, or to object to certain processing. You may also have the right to withdraw consent where processing is based on consent and to complain to an appropriate data-protection authority.

To make a request, email support@caika.app from your account email and describe the right you wish to exercise. We may need to verify your identity and account ownership before acting. Some requests may be limited where retention or processing is required for security, fraud prevention, transaction records, legal compliance, establishment or defense of claims, or the rights of others.

12. Children

The Service is intended only for people who are at least 18 years old. We do not knowingly offer the Service to, or seek personal information from, children. If you believe a person under 18 has provided personal information through the Service, contact us so we can review the report and take appropriate action.

13. Changes and Contact

We may update this Privacy Policy to reflect changes to the Service, providers, data practices, or applicable requirements. The revised version will be posted with an updated effective or last-updated date. Where required, we will provide additional notice or request consent before a material change takes effect.

For privacy questions, requests, or concerns, email support@caika.app. Please do not include passwords, full payment-card details, or unnecessary sensitive information in your message.

Contact: support@caika.app