Privacy Policy
Effective date: August 20, 2026
This policy covers qart.uk. thinkwith.pictures has its own policy; signing in on one does not sign you in on the other.
What we collect
- Account identity. Signing in with Discord gives us your Discord user ID and username. Signing in with Google gives us your Google account identifier and first name. We do not request or store your email address from either provider — if you email support, we have that address only because you sent it.
- What you create. The codes you claim, the destinations you point them at, the payloads and prompts you submit, images generated for you, and any image you upload to guide generation.
- Purchase records. Which credit pack you bought, when, the amount, and a Stripe identifier. We never see or store your card number — Stripe handles the card. Print-order totals and shipping destination come from Stripe Checkout the same way.
- Print-order phone number (optional). Only if you tap “Text me when this ships” on an order page and enter a number. We do not take a number from Stripe’s shipping form for texts. See Print-order text messages.
- Usage records. Your credit balance and its transaction history, generation runs and their status, daily allowance counters, and an approximate scan count per code.
- Technical data. Standard server logs including IP address and browser user-agent, collected by our host Cloudflare, used for security, abuse prevention, and debugging.
Scan data
When someone scans one of your codes we increment a counter so you can see roughly how often it has been used. The count is deliberately approximate — responses are cached, so bursts undercount. We do not build a profile of the person scanning, and we do not give you their identity, location, or device.
How we use it
- To run the service: resolving your codes, generating images, tracking your balance.
- To process payments, through Stripe.
- To send opted-in print-order shipping and cancellation texts, through Twilio.
- To enforce allowances and prevent abuse.
- To answer you when you contact support.
We do not use your prompts, uploads, or generated images to train our own models, and we do not sell your data.
Who else sees it
- Cloudflare — hosting and network. Handles all traffic.
- Modal — the GPU infrastructure that generates images. Receives your payload and prompt, and any image you upload, solely to produce your result.
- OpenRouter — used for some image-editing actions, on the same basis.
- Stripe — payment processing. Receives what it needs to take the payment, and for print orders the ship-to address you enter at Checkout.
- Twilio — SMS delivery for print-order updates, only if you opted in. Receives the phone number and the message body.
- Discord / Google — only as your sign-in provider, at the moment you sign in.
We may also disclose information where legally required, or to investigate abuse of the service.
Print-order text messages
Print-shop SMS is transactional only: shipping and cancellation notices for an order you already paid for. There is no marketing list and no keyword opt-in (no START/YES). Consent is a web form on the signed-in order page.
We collect a number only after that explicit opt-in. We use it for that order’s texts: an opt-in confirmation, a shipped message with a tracking link when the printer has one, or a cancellation notice. Frequency is typically 1–3 messages per opted-in order. We share the number with Twilio solely to deliver those messages. Reply STOP (also STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT) and we stop texting that number for open print-order opt-ins. Reply HELP (or INFO) for help, or email support@qart.uk. Message and data rates may apply. You can also tap Stop texts on the order page.
What is public
A claimed code's destination is public by nature: anyone who scans the code follows it. Your account identity is not attached to a code, and we do not publish who owns what.
Retention
Account and purchase records are kept while your account exists; purchase records may be kept longer where tax or accounting rules require it. Generated images you do not explicitly keep are deleted after about 30 days. Runs and their billing records are pruned after about 180 days once they hold nothing you kept.
Your choices
You can retarget or retire any code you own at any time. You can stop print-order texts by tapping Stop texts on the order page or by replying STOP. You can ask us to delete your account and its content by emailing support@qart.uk. Deleting your account disables your codes — anything already printed stops working — and forfeits unspent credits.
Depending on where you live you may have rights to access, correct, export, or erase your personal data. Email us and we will action it.
Cookies
One strictly functional cookie keeps you signed in. No advertising cookies and no third-party tracking cookies. We use privacy-preserving aggregate analytics that do not profile individual visitors.
Children
qart.uk is not intended for under-13s, and purchases require you to be 18 or older.
Changes and contact
We will update this page and its effective date if this policy changes. Questions: support@qart.uk.