phantasm

privacy

Last updated 2026-05-22.

Phantasm is operated by an individual sole proprietor based in the Netherlands. This page explains what data we collect, why, with whom we share it, how long we keep it, and the rights you have under the GDPR and equivalent regimes.

1. The short version

  • We don't sell your data. Ever. Not to anyone.
  • We don't train models on your prompts or your outputs.
  • We don't read your prompts. A small operator may need to investigate a specific moderation flag or a support ticket you filed — that's the bar.
  • Account deletion is one email. Privacy at privacy@phantasm.app. 30 days, max.

2. What we collect

  • Account data. Email, display name, Clerk user ID, age-confirmation flag, subscription tier, account-creation timestamp.
  • Generation data. Your prompts, the model and parameters you picked, the seed used, the resulting image / video, and the moderation verdict. Reference images you upload. Tags you apply.
  • Operational telemetry. Request timing, HTTP status, error codes, the asset ID involved. No prompt text in telemetry. Sampled to under 1% of successful requests.
  • Opt-in diagnostics. When you opt in to crash reporting, we forward error traces and device model to Dash0. Off by default.
  • Payment data. Polar.sh (our merchant of record) processes your card. We see only the last 4 digits, country, and the Polar customer ID. We never see the full card number, the CVV, or the billing address.
  • Device data. iOS device model, iOS version, app version. Used for compatibility checks. No IDFA, no advertising identifiers.

3. What we don't collect

  • Location data. We don't ask iOS for it.
  • Contacts, calendar, photo library (beyond a single picked file at upload time), microphone, motion, health.
  • Advertising IDs. We don't run ads.
  • Browsing history outside Phantasm.

4. Why we collect it (legal bases)

Under GDPR art. 6 we rely on:

  • Contract (art. 6(1)(b)). To run your account, deliver generations, and bill for them.
  • Legal obligation (art. 6(1)(c)). To respond to lawful requests, retain VAT records for 7 years, and report CSAM where required.
  • Legitimate interest (art. 6(1)(f)). To prevent fraud, abuse, and to keep the service running. Balanced against your rights.
  • Consent (art. 6(1)(a)). Opt-in diagnostics, marketing emails. You can withdraw at any time.

5. Who we share with (sub-processors)

Phantasm runs on a small set of vendors. Each is a data processor under a written data-processing agreement. None of them are allowed to train on your content.

  • Cloudflare (US/global) — Workers, R2 (asset bytes), D1 (metadata).
  • Modal (US) — GPU compute. Receives your prompt and any reference image you attached; produces the asset; deletes its working copy after delivery.
  • fal.ai (US) — GPU compute, same shape as Modal, for specific models (currently flux-realism).
  • xAI (US) — LLM for the Oracle feature and for prompt-moderation classification. Receives the text you put into Oracle.
  • Clerk (US) — authentication for the iOS app. Holds your email + sign-in events. The web sign-in is self-hosted and sends nothing to Clerk.
  • Polar.sh (US) — payments. Merchant of Record; holds card and billing data we never see.
  • Dash0 (EU) — error tracking. Off by default.

International transfers to the U.S. rely on Standard Contractual Clauses and (where applicable) the EU-U.S. Data Privacy Framework. We do not transfer data to jurisdictions without an adequacy decision or equivalent safeguard.

6. How long we keep it

  • Account record. While the account exists, plus 30 days after deletion.
  • Generated assets. Until you delete them, plus up to 30 days in backups.
  • Moderation refusals. 180 days, then deleted. Retained to detect repeat-offender patterns.
  • Payment records. 7 years, as required by Dutch tax law.
  • Operational telemetry. 90 days, then aggregated and the row-level data deleted.
  • CSAM evidence. Preserved under the rules that apply to NCMEC reports; we do not delete on your request.

7. Your rights (GDPR / UK GDPR / equivalents)

You can:

  • Access — request a copy of the data we hold about you.
  • Rectify — correct anything we have wrong.
  • Erase — delete your account and your data, subject to legal retention.
  • Restrict — pause processing while a dispute is resolved.
  • Object — stop processing that relies on legitimate interest.
  • Port — receive your data in a structured, machine-readable form (JSON).
  • Withdraw consent — turn off diagnostics, marketing emails, at any time.
  • Complain — file with the Dutch DPA Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local DPA.

Send any of the above to privacy@phantasm.app. We respond within 30 days; usually within a week.

8. Cookies and tracking

We use a single session cookie (phantasm_session) to keep you signed in on the web. It is HttpOnly, Secure, SameSite=Lax, and scoped to our own domain. We don't run third-party analytics or advertising cookies. No fingerprinting beyond the User-Agent string the browser sends on every request.

9. Children

Phantasm is 18+ only. We don't knowingly collect data from anyone under 18. If you believe a child has registered, email privacy@phantasm.app and we will delete the account and its data.

10. Asset metadata

Generated assets carry an AI-generation metadata block (model, prompt, seed, timestamp). We strip C2PA / EXIF that could de-anonymise the device, but we deliberately preserve the AI-generation block — it's how downstream platforms recognise the content as synthetic. If you don't want this metadata in a file you share, strip it yourself before sharing. Don't ask us to forge or remove it from the source asset; see Terms §4.

11. Security

iOS sign-in credentials are managed by Clerk; we never see that password. Web sign-in checks a single operator password held as a Cloudflare Worker secret — it is compared as a SHA-256 digest in constant time, and is never written to the database or to logs. Asset bytes live in Cloudflare R2 behind short-lived signed URLs. Worker secrets are stored as Cloudflare secrets; no engineer has standing read access to your prompts. We disclose security incidents that affect you within 72 hours of confirmation, per GDPR art. 34.

12. Changes

We will notify you in-app and by email at least 14 days before a material change to this policy.


Questions? Email hello@phantasm.app. Privacy requests: privacy@phantasm.app. Copyright (DMCA): legal@phantasm.app.