1. Controller
2. Website, hosting and logs
When you access the website, the server processes connection data required for delivery and security, including IP address, time, requested URL, referrer, browser and device information, status codes and error data.
The application is hosted on netcup server infrastructure. Domain registration and DNS are managed through IONOS. Security, access and error logs are intended to be deleted after 30 days in ordinary operation; incident-specific evidence may be retained for up to three years after the incident is closed. These periods will be enforced in hosting, logging and backups before production. The legal basis is our legitimate interest in a secure and stable service under Article 6(1)(f) GDPR.
We use Sentry, with storage located in the European Union, to be notified of server-side faults. Only operational messages leave the server: a technical incident key, the affected component, the time and technical reference identifiers. Free text, request contents, reference images, email addresses and credentials are stripped before transmission; no Sentry service is embedded in the browser. The legal basis is our legitimate interest in an available and fault-free service under Article 6(1)(f) GDPR.
3. Account and sign-in
For an account we process your name, email address, verification status, technical account identifiers and, for password sign-in, a cryptographically secured password value. Sessions normally last up to 30 days and may be renewed or ended for security reasons.
If you intentionally choose Google sign-in, we process the profile data Google releases as well as provider, account, token and permission information to the extent stored for authentication and account linking. Google is not activated merely by visiting the MerchKern website.
The legal bases are performance of the user contract under Article 6(1)(b) GDPR and our legitimate interest in secure authentication under Article 6(1)(f) GDPR.
4. Inputs, references and outputs
For a generation run we process your artwork description, requested wording, settings, reference images, generated files, previews, status and quality information, and your acceptance or rejection decision.
Production processing uses OpenAI (image generation and editing), Google Gemini (visual analysis of references) and fal.ai (ESRGAN upscaling). Do not submit references or personal content you are not entitled to use for this purpose.
The legal basis is contract performance under Article 6(1)(b) GDPR. Where a provider processes data outside the EEA, an appropriate Chapter V GDPR transfer mechanism is required before production.
5. File retention
Final download files and previews from Free and Starter runs are generally available for seven days. For Plus and Premium results not accepted into the library, this window is currently generally 14 days. Accepted library files remain available while a Plus or Premium plan includes the library.
After losing a library plan there is generally a 30-day download window, after which library files are deleted. Encrypted backups are intended to be overwritten on a rolling 30-day cycle; this production configuration will be verified before public launch.
A reference image selected in the Composer remains a local browser draft until you submit it. It is uploaded and assigned to your account only when you submit the run. If run creation then fails, the browser immediately attempts to delete the unused upload. If that technical cleanup does not succeed, an unbound upload becomes eligible for deletion after 24 hours and is removed by the next automatic cleanup run. Reference images used for a run remain stored for processing, traceability and run retries and are removed no later than account deletion; deleting an individual run does not currently remove its reference image automatically.
The availability windows above apply to final image files and previews. Run, input, quality and decision data and run-related source files generally remain until the relevant run or account is deleted. Used reference images currently remain stored until account deletion. Minimal contract and credit evidence needed to establish or defend claims may remain for up to three years after the end of the relevant contract or claim year. Automated enforcement of this retention schedule will be fully verified before production.
6. Payments and invoices
We use Stripe for payments. Stripe processes billing and payment details, billing country, tax information, payment-method characteristics, transaction identifiers and, where provided, a VAT ID. We do not receive full card details.
If you use a creator or campaign code, we process the code, the redeeming account, the assigned creator, plan and discount data, invoice reference, reward status and timestamps. This supports contract performance, abuse prevention, reversals and correct crediting under Article 6(1)(b) and (f) GDPR.
The legal bases are contract performance under Article 6(1)(b) GDPR and statutory record-keeping under Article 6(1)(c) GDPR. Billing and tax records are retained for the period required by law.
7. Email and support
Transactional and security emails are sent through Resend. Incoming support, privacy and rights requests are processed through a Google email mailbox. We process the sender, message, attachments, technical references and communication history as required to handle the request.
Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR. General enquiries are normally deleted twelve months after closure. Contract, refund, privacy, rights and other evidence-relevant correspondence may be retained for up to three years after the end of the closure year; tax-relevant records follow statutory periods.
8. Security and signup-credit protection
To limit automated signup attempts and repeated claims for free credits, we process network and identity characteristics. An IP-related protection window normally expires after seven days. We also create a pseudonymised SHA-256 check value from a versioned, normalised email identity. It replaces the clear-text address in this claim record but may still be attributable, particularly where address candidates are known, and is therefore protected as personal data. The claim is intended to be retained while the account exists and for no more than three years afterwards for abuse and claims prevention, with annual necessity review. Automated enforcement will be implemented before production.
This key neither changes your login email nor prevents normal use of distinct email addresses. We do not collect MAC addresses; ordinary websites cannot access them. The legal basis is our legitimate interest in abuse and fraud prevention under Article 6(1)(f) GDPR.
Automated protection rules may deny the one-time signup credit or stop a generation for security reasons. Denial of the signup credit does not block the account or access to paid services. You can contact support with questions.
10. Account deletion and other retention
Before account deletion, any locally linked active Stripe subscription is cancelled. If cancellation cannot be confirmed, deletion stops safely and can be retried. After successful checks, local authentication data, sessions, runs, owned reference uploads, outputs, library files, niches and personal settings are removed; the clear-text name and login email are removed from retained local account records.
Pseudonymised records may continue to be retained for billing, credit evidence, abuse prevention and legal claims. These include the internal user ID, credit entries and technical references, Stripe customer ID, the pseudonymised signup-credit check value, and creator-code and redemption links. These records are not anonymous; self-selected codes or external billing references may remain indirectly attributable. Stripe retains invoice and customer data under its applicable legal and contractual periods. We retain personal data only for as long as its purpose, legal duties, or the establishment, exercise or defence of claims require; the specific standard periods will be set before production.
Account and authentication data is required to create and use an account. Inputs and settings are required when you request the relevant generation. Billing, address, tax and payment data is required for paid contracts. Without the relevant required information, we cannot provide that service or complete the purchase.
11. Your rights
- Access to your personal data
- Correction of inaccurate data
- Erasure or restriction of processing
- Data portability where the statutory requirements apply
- Objection to processing based on legitimate interests
- Withdrawal of consent with future effect
You may also complain to a data protection authority. For private-sector controllers in Bavaria, the Bavarian State Office for Data Protection Supervision is generally competent.
12. Changes to this notice
We update this privacy notice when features, providers or legal requirements change. The current version and date are published on this page.