BabyShower AI Planner Privacy Policy
How BabyShower handles account data, private venue photos, AI planning files, payments, and optional analytics.
Last updated: 2026-08-11
Our privacy approach
BabyShower AI Planner is built around private home and venue photos. This policy explains what information is needed to provide the planning service, where third parties are involved, and how project retention and deletion work.
Information we process
We may process:
- Account information — such as your name, email address, authentication provider, and account status.
- Planning information — event date, guest count, venue type, budget, selected colors or styles, constraints, and the theme you choose.
- Private project files — the room-only venue photo you upload, AI-assisted previews, HD variants, revisions, shopping plans, and PDFs.
- Payment records — order identifiers, product, amount, currency, payment status, and provider references. Payment providers process the payment credentials; we do not store full card numbers.
- Security and operational data — limited request, device, browser, error, and abuse-prevention information needed to protect accounts and operate the service.
- Optional analytics — only after consent, privacy-minimized product events that exclude names, photos, prompts, storage keys, and exact home details.
Do not upload people, children, faces, addresses, private documents, or screens in the venue photo. Images are checked and sanitized before private storage, but you remain responsible for reviewing what you upload.
How we use information
We use information to authenticate you, save and retrieve your project, inspect the room for safe planning, generate requested themes and visuals, create the shopping plan and PDF, process and verify purchases, provide support, prevent abuse, diagnose failures, and meet legal obligations.
We do not publish your private venue photo or sell it as personal information. We do not use private venue photos to train our own models.
AI and service providers
Requested AI features require selected model providers to process bounded planning instructions and, for image-aware work, temporary access to the relevant private image. Storage, authentication, email, analytics, infrastructure, and payment providers may also process the minimum information needed for their role. Their handling is governed by their agreements and applicable policies.
We limit provider inputs to what is needed for the requested task and do not include account names in generation prompts. No online system can remove every third-party or transmission risk, so use a room-only photo without identifying details.
Creem prompt safety screening
Before an image-generation task is created, we send the final text prompt and a technical request identifier to Creem's Content Moderation API. The text prompt can contain the planning choices and room description needed to produce the requested concept. Creem returns an allow, flag, or deny decision; only allow continues. Screening failures and uncertain responses stop generation by default.
Your venue photo is not sent to Creem for this prompt-safety check. Creem receives the final text prompt, not the image, and does not receive your account name or email in this request. The venue photo may still be processed separately by the selected image or vision provider when you request an image-aware feature, as described above.
Private storage and access
Project files are stored as private assets. Access requires an authenticated ownership check or a short-lived authorized link. Public search engines and unrelated users should not be able to retrieve them through a public asset path.
Free projects may expire after 30 days. Paid projects may remain available for up to 12 months. Failed cleanup may be retried while access remains denied after expiry. Certain payment, fraud-prevention, support, and deidentified measurement records may be retained longer when needed for accounting, dispute handling, security, or legal obligations.
Cookies and analytics choices
Essential cookies support sign-in, security, language selection, and core project behavior. Optional analytics is disabled unless you accept it through the consent notice. Declining optional analytics does not block planning, account access, checkout, downloads, or support.
Your choices
You can update profile details, delete available projects, decline optional analytics, and contact support about account or data requests. Some records cannot be deleted immediately when retention is required to protect a transaction, resolve a dispute, prevent fraud, or comply with law.
Security
We use encrypted transport, private object storage, access controls, ownership checks, limited-duration asset access, content validation, and operational review. No service can promise absolute security; contact support promptly if you suspect unauthorized access.
Children and sensitive images
The service is not intended for children to use directly. Even when planning a celebration for a child, do not upload photos containing children or any other person. Use a clear room-only venue image.
Changes and contact
We may update this policy when the product, providers, or legal requirements change. The latest revision date appears above. For privacy questions or deletion requests, email support@babyshowervideo.com or sign in and submit a support ticket.