Privacy Policy
How [Legal entity name] ("SchemGen", "we", "us") handles your data when you use the SchemGen website and app.
Last updated August 12, 2026
1. What we collect
- Account data — your email address and, if you sign up with a password, a bcrypt hash of it (never the password itself). If you sign in with Google we receive your name, email address, and profile picture from Google.
- Content you send — your prompts, the chat history, any images or documents you attach, and the schematics, design notes, and firmware generated in response. These are stored so your chats are there when you come back.
- Billing data — your Stripe customer and subscription identifiers, plan, and subscription status. Card numbers go directly to Stripe; we never receive or store them.
- Usage data — how many generation requests you have made in the current period (to enforce plan quotas), and counters keyed to your account or IP address for rate limiting.
- Technical data — standard server logs from serving requests, including IP address, user agent, timestamps, and errors.
2. Why we use it
To run your account and authenticate you; to generate schematics in response to your prompts; to store and show your chat history; to bill you and enforce plan quotas; to send you the transactional emails the service requires (address verification, password resets, and billing notices); to keep the service secure and prevent abuse; and to diagnose faults.
Where the GDPR applies, our legal bases are performance of a contract (running the service and billing you), our legitimate interests (security, abuse prevention, and improving reliability), and consent where we ask for it (advertising cookies).
3. AI model providers
Generating a schematic means sending your prompt, recent chat history, and any attachments to a third-party model provider — currently OpenAI. We send a one-way hashed identifier for abuse reporting rather than your email address, so the provider does not receive your identity from us.
Before an image is sent, it is re-encoded and its embedded metadata — including any GPS coordinates from a phone camera — is removed. PDFs are reduced to their text layer. Providers process this content to return a result under their own terms, and we use providers’ business/API tiers, which do not train their public models on API content.
4. Who else processes your data
We do not sell your personal data. We share it only with the service providers we need to operate:
- Neon — the Postgres database holding accounts, chats, and messages
- Vercel — application hosting and request logs
- Stripe — payments, subscriptions, and the billing portal
- Resend — sending verification, password-reset, and billing emails
- Google — the optional "Continue with Google" sign-in, and conversion measurement on our marketing pages
- OpenAI — generating schematics, as described above
We may also disclose data if the law requires it, or to protect our rights, safety, or the integrity of the service.
5. Cookies
We use a session cookie to keep you signed in — the app does not work without it. On our public marketing pages we also load Google’s conversion tag, which sets advertising cookies to measure whether an ad led to a signup. You can block those in your browser without affecting the app.
6. How long we keep it
Account and chat data are kept while your account exists. When you delete your account, we delete your chats, messages, and attachments within 30 days, aside from copies in encrypted backups that age out on their own. We keep the minimum billing records that tax and accounting rules require, and short-lived security logs and rate-limit counters that expire on their own.
7. Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct or delete it, object to or restrict a use, or withdraw consent. Email support@schemgen.com from your account address and we will respond within 30 days. We will not treat you differently for exercising these rights, and if you are in the EU or UK you can also complain to your local data-protection authority.
8. Security
Passwords are stored as bcrypt hashes. Email verification and password-reset links are single-use and stored hashed, so a database copy does not yield working links. Traffic is served over HTTPS only. No system is perfectly secure, so please use a unique password and tell us at support@schemgen.com if you suspect a problem with your account.
9. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
10. International transfers
We and our providers operate in the United States and elsewhere, so using the service involves transferring your data internationally, including out of the EEA and UK. Where required, those transfers rely on standard contractual clauses or another approved safeguard.
11. Changes and contact
If we change this policy we will update the date above and, for material changes, tell you by email or in the app. Questions or requests: support@schemgen.com. See also our Terms of Service.