Privacy Policy

Last updated: July 1, 2026

Contents

1. Introduction

Autorender, Inc. ("Autorender," "we," "us," or "our") provides a media transformation, optimization, and delivery platform, including our website, APIs, SDKs, dashboard, upload widget, Model Context Protocol (MCP) server, and our marketplace applications for Shopify, WordPress, and WooCommerce (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.

Autorender is a business-to-business ("B2B") service. Our customers are businesses and developers ("Customers") who use the Service to process and deliver their own images, video, and other media assets ("Customer Content").

This Policy applies to:

  • Account and website data — information about the individuals who register for, administer, or use a Customer's account (for this data, Autorender acts as a business/controller); and
  • Customer Content — media and associated data that a Customer uploads to, or connects to, the Service. Customer Content may contain personal information about the Customer's own end users (for this data, Autorender acts as a service provider/processor, processing it only on the Customer's documented instructions and on the Customer's behalf).

If you interact with Autorender as an end user of one of our Customers, the Customer — not Autorender — is responsible for that data, and you should consult the Customer's privacy policy.

2. Who we are and how to contact us

Data controller / business: Autorender, Inc., 8 The Green, STE R, Dover, DE 19901, United States.

Privacy, legal, and support contact: engineering@autorender.io

3. Information we collect

3.1 Information you provide

CategoryExamplesSource
Account & profileName, username, email address, password (stored only as an Argon2id hash — we never store your plaintext password), avatar/profile imageYou, at registration
AuthenticationEmail verification and password-reset tokens; if you use social sign-in, the OAuth tokens and account identifier provided by Google or GitHubYou / your identity provider
Workspace & teamWorkspace names and settings, team-member and invitation records (including invitee email addresses and invitation messages)You / workspace admins
Credentials you configureAPI keys you generate (stored as a hash plus an encrypted copy); credentials for third-party storage buckets (Amazon S3, Google Cloud Storage, Azure Blob) you connect as an "origin" — stored encrypted using AES-256-GCMYou
IntegrationsConnection details for integrations you enable (e.g., Shopify, WordPress, WooCommerce), including site/store URLs and encrypted integration keysYou
Support & feedbackMessages, feedback, and communications you send usYou
BillingBusiness/billing contact details. See §3.4 regarding payment card data.You

3.2 Customer Content

When you upload media directly to Autorender, or connect your own cloud-storage bucket or store as an origin, we process:

  • Media assets — images, video, and their file names, sizes, formats, dimensions, and metadata;
  • AI-derived metadata — where you use our optimization and AI features, we generate and store technical descriptors about your assets (e.g., captions, object/label/face detection, extracted text (OCR), color data, content-safety flags, quality scores, and search embeddings);
  • Custom metadata — any metadata schemas and values you define.

Customer Content is processed on your instruction and on your behalf. You are responsible for having the necessary rights and, where applicable, consents for any personal information contained in Customer Content (for example, images depicting identifiable individuals).

3.3 Information we collect automatically

CategoryExamples
Device & connectionIP address and user-agent string (captured with your session for security and abuse prevention)
Usage & delivery logsAPI and CDN request data, bandwidth and storage usage, transformation and delivery events, error samples (including requested URLs/paths), and aggregated usage analytics derived from our CDN logs
AI/agent usagePrompts and outputs, conversation history, and token-usage counts where you use our AI Studio, agents, or MCP features
Cookies & similarSee §8

3.4 Payment information

Autorender currently bills paid plans by manual invoicing, and, where you purchase through a marketplace (such as Shopify), through that marketplace's billing system. We plan to introduce a third-party payment processor (e.g., Stripe) for direct billing. In all cases, payment card details are collected and processed directly by the marketplace or payment processor, not stored by Autorender. We will update this Policy and our sub-processor list before enabling any new processor.

3.5 Information from third parties

  • Identity providers (Google, GitHub) if you use social sign-in — your basic profile and email.
  • Marketplace platforms (Shopify, WordPress, WooCommerce) — store/site data and, where applicable, limited customer data necessary to provide the Service (see §5.4).
  • AI clients you connect via our MCP server (e.g., Claude, Cursor, v0) — requests you route through those clients.

4. How we use information

We use personal information to:

  • Provide and operate the Service — create and manage accounts, authenticate you, process and deliver Customer Content, run transformations and AI operations, and enforce plan/usage limits;
  • Bill and administer subscriptions, AI credits, and usage;
  • Communicate — send verification, security, transactional, and service messages, and respond to support requests;
  • Secure the Service — detect, prevent, and investigate fraud, abuse, and security incidents (this is a primary purpose for retaining IP/user-agent data);
  • Improve and analyze — understand usage and improve features and reliability, using first-party analytics and error monitoring;
  • Content safety — apply content-moderation and safety classification where enabled or required;
  • Comply with law and enforce our Terms.

We do not sell your personal information, and we do not use your Customer Content to train our own AI models. We process Customer Content only to provide the Service to you.

4.1 Legal bases (for users protected by GDPR/UK GDPR)

Where applicable, we rely on: performance of a contract (providing the Service); legitimate interests (securing, analyzing, and improving the Service); consent (certain cookies/marketing, withdrawable at any time); and legal obligation.

5. How we share information — sub-processors and third parties

We share personal information with the following categories of recipients. We do not sell it and do not share it for cross-context behavioral advertising.

5.1 Sub-processors

We share personal information with the third-party sub-processors that help us provide the Service (for example, cloud hosting, content delivery, transactional email, and AI processing). Each is engaged under terms requiring appropriate confidentiality and security, and processes data only as needed to provide its service to us. The current, complete list — with each sub-processor's function and processing location — is maintained on our Sub-processors page.

AI and your content. When you use our AI-powered features, the relevant Customer Content and prompts are transmitted to the AI sub-processor(s) listed there solely to perform the operation you requested. These sub-processors do not use your Customer Content to train their models; we access them through enterprise/paid API tiers whose terms prohibit such training.

5.2 Customer-connected storage

If you connect your own S3, GCS, or Azure bucket as an origin, your assets remain in your storage under your control; we access them only to perform the transformations and delivery you request. Your cloud provider's terms and privacy practices govern that storage.

5.3 Other disclosures

We may disclose information: to professional advisors (lawyers, auditors); in a corporate transaction (merger, acquisition, financing, or asset sale); to comply with law, legal process, or lawful requests, and to protect our rights, users, and the public; and with your consent or at your direction.

5.4 Marketplace integrations (Shopify, WordPress, and WooCommerce)

If you use Autorender through a marketplace application:

  • What we receive. When you install and configure our Shopify, WordPress, or WooCommerce application, the application transmits your store's or site's media and assets (and related metadata) to the Service for processing, optimization, and delivery. Depending on the features you enable, we may also process limited store information and, for Shopify, personal information relating to your customers accessed through Shopify's APIs ("Protected Customer Data").
  • Our role. For your customers' personal information, you are the controller/business and Autorender is your processor/service provider. We apply data minimization, process such data only to provide the Service, and protect it as described in §10.
  • Deletion. We support the marketplace's data-protection requests. For Shopify, we honor customer data-access requests, delete a customer's personal information upon a redaction request within thirty (30) days, and erase a shop's data following uninstallation. For WordPress/WooCommerce, deactivating and removing the plugin stops further transmission, and account data is deleted per §7.
  • Consent. Installing and configuring the application (including providing your API key) constitutes your instruction and consent for this processing.

6. International data transfers

Autorender is based in the United States and hosts data in the United States. If you access the Service from outside the United States (including from India, the EEA, or the UK), your information will be transferred to and processed in the United States and other countries where we or our sub-processors operate, which may have different data-protection laws than your own. Where required, we implement appropriate safeguards (such as the EU Standard Contractual Clauses) for such transfers.

7. Data retention and deletion

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, prevent abuse, and enforce our agreements.

  • Account data is retained for the life of the account.
  • Customer Content and associated personal information is retained until you delete it or your account is closed. Following account closure or termination (or uninstallation of a marketplace application), we delete Customer Content and associated personal information within thirty (30) days, and purge it from routine backups within a further ninety (90) days.
  • Financial and tax records may be retained for up to seven (7) years where required by law.
  • Security and usage logs are retained for up to ninety (90) days.

Deletion and export requests. To request access to, correction of, export of, or deletion of your personal information, contact engineering@autorender.io. We will verify your request and respond within the timeframe required by applicable law.

8. Cookies and similar technologies

We use cookies and similar technologies for the following purposes:

  • Strictly necessary — authentication and security. We set an HTTP-only, Secure session cookie to keep you signed in, and a short-lived oauth_state cookie to protect the OAuth sign-in flow against CSRF.
  • Analytics — PostHog may set cookies/identifiers to measure product usage.
  • Error monitoring — Sentry may collect diagnostic identifiers (in production).

You can control non-essential cookies through your browser settings and, where offered, our cookie controls. Disabling strictly necessary cookies will prevent you from signing in.

9. Your privacy rights

Depending on where you live, you may have some or all of the following rights. To exercise them, contact engineering@autorender.io. We will verify your request and respond within the timeframe required by applicable law, and we will not discriminate against you for exercising these rights.

9.1 California residents (CCPA/CPRA)

You have the right to know/access, delete, correct, and to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.

  • We do not sell or share personal information as those terms are defined under the CPRA, and we do not use or disclose sensitive personal information for purposes requiring a "limit" right.
  • Categories collected (CCPA): identifiers (name, email, IP); customer records (billing contact); internet/network activity (usage/logs); commercial information (plan/usage); and audio/visual information (Customer Content you provide). Sources and purposes are described in §§3–4; recipients in §5.
  • You may use an authorized agent to submit requests.

9.2 EEA / UK residents (GDPR / UK GDPR)

You have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right to lodge a complaint with your supervisory authority.

9.3 India residents (DPDP Act, 2023)

You have the right to access, correction and erasure, grievance redressal, and to nominate another person to exercise your rights in the event of death or incapacity. Grievance/privacy contact for India: engineering@autorender.io.

10. Security

We use technical and organizational measures to protect personal information, including: encryption in transit (TLS) and application-level encryption at rest for sensitive stored credentials (AES-256-GCM); Argon2id password hashing; hashed API keys and access tokens; HTTP-only, Secure session cookies; role- and workspace-scoped access controls; and rate limiting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children's privacy

The Service is a B2B product intended for use by businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact engineering@autorender.io and we will delete it.

The Service may link to or integrate with third-party sites and services (including marketplace platforms, Customer-connected storage, and AI clients). We are not responsible for their privacy practices; review their policies.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (e.g., email or in-product). Your continued use of the Service after an update constitutes acceptance of the revised Policy.

14. Contact us

Questions or requests: engineering@autorender.io · Autorender, Inc., 8 The Green, STE R, Dover, DE 19901, United States.