Privacy

The data needed to make and deliver your badges

Awardlet minimizes collection to account access, purchase fulfillment, generation, support, and optional product analytics.

Launch policy draft · Updated August 20, 2026

What we process

  • Account email, password hash, sessions, and password-recovery records.
  • Project names, badge prompts, style choices, purchase references, generation status, and generated files.
  • Security and operational events containing correlation IDs and error codes, not passwords, raw tokens, or complete payment payloads.

How services are used

A secure payment service handles payment details. An AI image service processes generation instructions. Infrastructure services host the application, database, background jobs, and private files. An email service delivers account-recovery messages. Optional product telemetry is disabled when not configured and must not receive prompts, payment data, or authentication secrets.

Retention and deletion

Paid-order and ledger records are retained for support, fraud, and accounting needs. Expired sessions, used reset tokens, old rate-limit windows, raw service diagnostics, and generated assets require the scheduled retention policy in the launch runbook. Contact support to request account or project deletion; legal or transaction-retention duties may limit deletion of purchase records.

Your choices

You can turn off optional analytics in this browser, archive projects, and request account access or deletion through the support page. Never send a password, session token, reset link, or card number to support.

Product analytics

Checking this browser's analytics preference.