1. Operator and contact
PathwayFig is operated by an individual developer based in China. This policy covers personal information processed by PathwayFig when you use the website, accounts, optional AI generation and support/report channels. For privacy questions and requests, contact [email protected].
This policy describes the current beta. Self-service checkout is not available. External sites and service providers have their own privacy terms; a link here does not make their processing identical to ours.
2. Information we process
| Information | Use and location |
|---|---|
| Template edits and exports | Template editing uses browser page state. Edits are not uploaded by the vector editor or saved to an account. Download exports to retain them. |
| Browser preferences and pending tasks | A theme preference can be saved in local storage. Pending AI request IDs can be saved in session storage to resume status checks. Legacy local records may remain on your device after password fields are removed. |
| Account information | Email address, display name, salted password hash, session records, policy acknowledgments and access restrictions are stored on the server when accounts are enabled. We do not store plaintext passwords. |
| AI inputs and task records | Your prompt and settings pass through our server to the disclosed AI service. Task IDs, request hashes, status, timestamps, resulting image URLs and credit adjustments are stored for delivery, balance integrity and support. |
| Safety and support information | Report category, description, optional contact email, optional task reference, submitting account ID when available, timestamps and review decisions can be stored. Information you email is also processed to address your request. |
| Technical and security information | Hosting infrastructure processes IP address and request metadata. The application uses derived identifiers and counts for rate limits and abuse prevention. Normal error responses do not expose prompts, passwords, API keys or database records. |
Do not send patient records, special-category personal data, confidential research, passwords or payment-card information in prompts or reports.
3. Why information is used
We use information to provide requested accounts and generation, preserve credit balances and request consistency, operate and secure the service, prevent abuse, investigate content reports, respond to support requests and meet applicable legal obligations.
Where a law requires a legal basis, the relevant basis may be providing the service you request, legitimate interests in operating and protecting the service (subject to your rights), compliance with law, or consent where required. We do not treat a privacy-policy acknowledgment as blanket consent to unrelated processing.
This version has local analytics event hooks for actions such as opening the editor and exporting; it does not itself send those events to an advertising or third-party analytics service. We do not sell personal information or use it for targeted advertising through this application.
4. Service providers and disclosure
- Cloudflare: hosting, request handling and, where configured, the D1 database that stores account, task and report records. Its infrastructure processes relevant connection metadata.
- APIMart and upstream AI providers: generation prompts, settings and task processing when you request AI generation. Current API route:
gpt-image-2.5-ext, versionflare. The model disclosure explains the route and limitations. - Content safety: prompt content and generated image references are processed for safety decisions before generation or display. A content-safety provider has not yet been configured for public AI access. AI generation must remain unavailable until the required checks are in place.
- Image hosting: viewing an AI result may connect your browser to the provider's image URL, revealing ordinary connection metadata to that host.
- Support communications: email services process correspondence you send to the support address.
We may disclose relevant information when necessary to comply with law, respond to a valid legal request, protect users from harm, investigate abuse or resolve a rights claim. Report information is not a public feed. We limit disclosure to what is appropriate for the purpose.
Waffo Pancake payment onboarding is under review. This version does not collect card details or run a live checkout. If payments are enabled later, payment-provider data handling will be disclosed before collection.
5. International processing and third-party terms
The operator is based in China, and internet infrastructure and AI providers may process information in other countries. We do not currently promise country-specific storage or zero data retention by an upstream provider. Third-party provider handling follows the arrangements and terms applicable to their services.
We do not train our own AI model on user prompts or outputs in this version. That statement is not a guarantee about every third party's training or retention practices. Do not submit information that your institution prohibits you from sharing with external AI services.
6. Retention and security
Browser page state lasts for the current editing session; locally saved preferences and legacy records remain until you or the browser remove them. Session cookies expire after seven days unless you sign out earlier. Authentication, credit, task and report records are retained for service operation, troubleshooting, unresolved disputes and applicable legal obligations.
This beta does not run a general automated deletion schedule for all database records. Ask support to delete data you no longer want retained. We will review the request, verify identity when needed, remove or anonymize information that is no longer required, and explain any applicable reason for retaining some records. Third-party copies and backup retention may follow separate schedules.
We use protections including server-side secrets, password hashing, restricted session cookies and request limits. No internet service or storage system is completely secure. Tell us promptly if you suspect a security issue and avoid sending secrets in a report.
7. Your choices and privacy requests
Depending on the law that applies to you, you may have rights to access, correct, delete or receive a copy of your data, object to or restrict certain processing, withdraw consent where processing relies on it, and complain to an appropriate supervisory authority. These rights can have legal limits and exceptions.
Email [email protected] with the type of request and the account email or relevant reference. Do not include your password. We may need proportionate information to confirm ownership, and we will respond within any period required by applicable law. There is no automated account-deletion or recovery email flow in this version.
You can use the free editor without an account, decline to submit AI prompts, sign out, and remove local site storage using browser settings. Clearing local data may remove preferences and interrupted-task recovery information.
8. Children and policy changes
The service is intended for adults aged 18 or older. We do not knowingly solicit children's personal information. If you believe a child has provided personal information, contact support so that we can investigate and take appropriate action.
The effective date appears at the top. We will update this policy when processing changes and provide additional notice or seek consent when required. See Terms of Service, Acceptable Use and Contact.