Privacy Policy
Effective date: August 18, 2026
This Policy explains how Code Canyon LLC handles account, generation, credit, payment, and technical information when you use Kanvora.
Scope and operator
This Privacy Policy applies to Kanvora at seedream-5.site, operated by Code Canyon LLC. It applies when you visit the site, sign in, purchase credits, submit generation work, or download an output. Kanvora is offered globally except in mainland China and is not offered or intended for people located in mainland China.
Information we collect
Account information
When you continue with Google, Supabase handles the authentication flow and Kanvora receives account details such as a user identifier, email address, display name, avatar, and session information. Kanvora does not receive your Google password.
Generation content and metadata
We process prompts, selected settings, model and provider identifiers, request identifiers, queue and completion status, timing, errors, credit cost, and generated output files. Moderation audit records contain a one-way prompt hash rather than raw prompt text, the decision source, result, categories or reason codes, and the generation identifier when a job is created. Stored asset records may include file type, dimensions, size, checksum, storage location, and provider-supplied provenance information.
Outputs are AI-generated. Pages that display generated media identify it as AI-generated. We preserve provider-supplied machine-readable AI provenance, content credentials, and C2PA-style marks when they are present, and users must not strip them. Generation metadata is retained for traceability, integrity, safety, reconciliation, and legal compliance.
Credit and payment information
We keep an account balance and an append-only record of credit grants, purchases, reservations, charges, and releases. When you select a credit pack, Kanvora and Waffo Pancake process pack, order, payment-status, and fulfillment references needed to complete the purchase and add credits. Waffo Pancake is the merchant of record and hosts payment checkout. Kanvora does not receive or store your full payment-card number.
Technical information
Our hosting, security, and service providers may process IP address, browser and device information, request times, pages requested, cookie or session identifiers, and diagnostic logs needed to deliver and protect the service.
How we use information
Code Canyon LLC uses the information described above to:
- authenticate accounts and maintain sessions;
- submit, reconcile, store, display, and deliver generation work;
- grant, reserve, charge, release, and display credits accurately;
- complete Waffo purchases and respond to refund records;
- secure Kanvora, diagnose failures, prevent duplicate work, and investigate misuse;
- preserve AI provenance and generation traceability; and
- comply with applicable law and enforce the Terms of Service.
How information is shared
We share information only as needed to operate Kanvora, process transactions, protect the service, or comply with law. The recipients may include:
- Google and Supabase for authentication and account infrastructure;
- AI model and inference providers, currently through fal, to process prompts and generation settings;
- OpenAI and Waffo Prompt Sift to assess prompt safety;
- Cloudflare R2 for durable output storage;
- Waffo Pancake as merchant of record for hosted checkout, payment confirmation, and refund administration;
- hosting and operational infrastructure providers, including Vercel; and
- authorities or affected parties when disclosure is required by law or reasonably necessary to protect rights, safety, and service integrity.
Cookies and session storage
Kanvora and Supabase use cookies or similar browser storage needed to start and maintain authentication, secure requests, preserve an intended return path, and operate the service. Blocking these technologies may prevent sign-in or other essential features from working.
Retention
We retain account and service records for as long as reasonably needed to provide Kanvora, maintain accurate credit and payment records, secure the service, resolve disputes, and comply with law. Generation metadata is retained for traceability.
Some records must be kept after an account request, including payment records, security logs, immutable credit-ledger entries, and generation metadata needed for traceability or legal compliance.
International processing
Kanvora is a global service except in mainland China. Information may be processed in countries where Code Canyon LLC and its service providers operate. Those countries may have privacy laws different from the laws where you live.
Your choices and rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, or a copy of certain personal information, and to object to certain processing. A request may be limited when records must be retained for transaction integrity, security, traceability, or legal compliance. You can also manage information shared by Google through your Google account controls.
Code Canyon LLC may need to verify that a request comes from the account holder before acting on it.
Security
Code Canyon LLC uses technical and organizational measures intended to protect information, including authenticated access, signed provider callbacks, durable storage, and integrity records. No internet service or storage system can guarantee absolute security.
Changes to this Policy
We may update this Policy when Kanvora, its providers, or applicable law changes. The current version will appear on this page with its effective date.