Legal
Privacy Policy
Last updated: April 21, 2026
1. What this covers
This policy explains what data mechremix ("we", "us") collects when you use the Service at mechremix.com, how we use it, and your rights over it. It applies to signed-in and anonymous visitors.
2. Data we collect
Account data — email address (required to sign in), role (user or admin), credit balance, and the history of credits granted or spent.
Content you create — source-game inputs you submit, generation prompts and results (concepts, ads, spark reports, visual assets), and feedback you leave on generated versions. Stored so you can see, refine, and share them.
Usage data — job queue entries (timing, status, errors), anonymised request logs (route, response code, latency), and aggregate metrics used to keep the Service healthy. We use Perchlens for lightweight page-view analytics (route, referrer, aggregate device class); no behavioural profiles, no advertising SDKs, no cross-site tracking.
Newsletter signups — if you submit the newsletter form, we store your email, source (e.g., footer), timestamp, and minimal request metadata (user-agent, IP) so we can debug abuse.
3. How we use it
To operate the Service:
- authenticate you and enforce capabilities;
- run generation pipelines and return outputs;
- meter credits and prevent abuse;
- support you when you reach out.
To improve it:
- aggregate, anonymised metrics to find slow routes and broken pipelines (no raw content, no per-user profiling);
- opt-in review of a small sample of generations to improve prompt templates — we'll never use your content to train third-party AI models without explicit consent.
4. Processors we share with
We use the following third-party processors. Each receives only what's needed:
- Supabase — hosts our database and handles email / OAuth authentication.
- Vercel — hosts the web application and serves static assets.
- Anthropic — runs the text models behind concept + ad + spark + GDD generation. Inputs may be retained by Anthropic for abuse monitoring per their policy.
- Google Gemini — runs vision tagging, critic passes, and image generation (nano-banana, Imagen).
- OpenRouter — optional routing layer for the same providers; used transparently.
- Perchlens — page-view analytics. Receives the URL, referrer, and aggregate device info per request; no personal identifiers, no cross-site pixels.
We don't sell your data. We don't share it with advertisers. We don't share with other parties except as required by law or to operate the Service above.
5. Cookies + local storage
We set a session cookie (via Supabase) to keep you signed in. We use browser localStorage for UI preferences (theme, last-viewed version, command-palette state). No advertising or analytics cookies.
6. Your rights
You can export, correct, or delete your account data at any time by emailing support@mechremix.com. Under GDPR / CCPA you have the right to access, correct, delete, port, and restrict processing of your data; we'll honour these requests within 30 days. To unsubscribe from the newsletter, use the unsubscribe link in any newsletter email, or email us.
7. Retention
Account + content data is retained while your account is active and for 90 days after deletion (to recover from accidental deletions or account-takeover cleanup). Job-queue rows are pruned after 180 days. Newsletter emails are kept until you unsubscribe. Request logs are retained for 30 days.
8. International transfers
Our processors operate globally; your data may be transferred to and processed in the United States and other countries. We rely on Standard Contractual Clauses and each provider's adequacy decisions where applicable.
9. Children
The Service is not intended for users under 16. We don't knowingly collect data from children. If you believe a minor has used the Service, email us and we'll delete the account.
10. Security
Data is encrypted in transit (HTTPS) and at rest in Supabase. Authentication uses server-only session cookies with rotation; service-role access is strictly server-side and never exposed to the browser. We're a small team and treat every incident seriously — if we learn of a breach affecting your data, we'll notify you.
11. Changes
Material changes to this policy will be announced on the Service and, if you're subscribed, via email. Minor edits (typos, link fixes, clarifications) happen silently but the "Last updated" date always reflects the latest change.
12. Contact
Privacy questions, access / deletion requests, or "what happened to my data": support@mechremix.com.