Skip to content
MerchKern
AblaufWorkflowErgebnisseResultsCSVCSVPreisePricingFAQFAQ
DEEN
Log inTry it free
AnmeldenKostenlos ausprobieren

Responsible data use

Privacy notice

This notice explains which personal data MerchKern processes for the website, accounts, generation, billing and support.

Last updated: 16 August 2026

Legal draft. Processor agreements, regions and international transfer mechanisms must be confirmed before production.

On this page
  1. 1. Controller
  2. 2. Website, hosting and logs
  3. 3. Account and sign-in
  4. 4. Inputs, references and outputs
  5. 5. File retention
  6. 6. Payments and invoices
  7. 7. Email and support
  8. 8. Security and signup-credit protection
  9. 9. Cookies and local storage
  10. 10. Account deletion and other retention
  11. 11. Your rights
  12. 12. Changes to this notice

1. Controller

Max BauerLazy Ass ToolsSole proprietorship (Einzelunternehmen)Franz-Xaver-Neun-Str. 1384347 PfarrkirchenGermany
Privacy contact[email protected]

2. Website, hosting and logs

When you access the website, the server processes connection data required for delivery and security, including IP address, time, requested URL, referrer, browser and device information, status codes and error data.

The application is hosted on netcup server infrastructure. Domain registration and DNS are managed through IONOS. Security, access and error logs are intended to be deleted after 30 days in ordinary operation; incident-specific evidence may be retained for up to three years after the incident is closed. These periods will be enforced in hosting, logging and backups before production. The legal basis is our legitimate interest in a secure and stable service under Article 6(1)(f) GDPR.

We use Sentry, with storage located in the European Union, to be notified of server-side faults. Only operational messages leave the server: a technical incident key, the affected component, the time and technical reference identifiers. Free text, request contents, reference images, email addresses and credentials are stripped before transmission; no Sentry service is embedded in the browser. The legal basis is our legitimate interest in an available and fault-free service under Article 6(1)(f) GDPR.

3. Account and sign-in

For an account we process your name, email address, verification status, technical account identifiers and, for password sign-in, a cryptographically secured password value. Sessions normally last up to 30 days and may be renewed or ended for security reasons.

If you intentionally choose Google sign-in, we process the profile data Google releases as well as provider, account, token and permission information to the extent stored for authentication and account linking. Google is not activated merely by visiting the MerchKern website.

The legal bases are performance of the user contract under Article 6(1)(b) GDPR and our legitimate interest in secure authentication under Article 6(1)(f) GDPR.

4. Inputs, references and outputs

For a generation run we process your artwork description, requested wording, settings, reference images, generated files, previews, status and quality information, and your acceptance or rejection decision.

Production processing uses OpenAI (image generation and editing), Google Gemini (visual analysis of references) and fal.ai (ESRGAN upscaling). Do not submit references or personal content you are not entitled to use for this purpose.

The legal basis is contract performance under Article 6(1)(b) GDPR. Where a provider processes data outside the EEA, an appropriate Chapter V GDPR transfer mechanism is required before production.

5. File retention

Final download files and previews from Free and Starter runs are generally available for seven days. For Plus and Premium results not accepted into the library, this window is currently generally 14 days. Accepted library files remain available while a Plus or Premium plan includes the library.

After losing a library plan there is generally a 30-day download window, after which library files are deleted. Encrypted backups are intended to be overwritten on a rolling 30-day cycle; this production configuration will be verified before public launch.

A reference image selected in the Composer remains a local browser draft until you submit it. It is uploaded and assigned to your account only when you submit the run. If run creation then fails, the browser immediately attempts to delete the unused upload. If that technical cleanup does not succeed, an unbound upload becomes eligible for deletion after 24 hours and is removed by the next automatic cleanup run. Reference images used for a run remain stored for processing, traceability and run retries and are removed no later than account deletion; deleting an individual run does not currently remove its reference image automatically.

The availability windows above apply to final image files and previews. Run, input, quality and decision data and run-related source files generally remain until the relevant run or account is deleted. Used reference images currently remain stored until account deletion. Minimal contract and credit evidence needed to establish or defend claims may remain for up to three years after the end of the relevant contract or claim year. Automated enforcement of this retention schedule will be fully verified before production.

6. Payments and invoices

We use Stripe for payments. Stripe processes billing and payment details, billing country, tax information, payment-method characteristics, transaction identifiers and, where provided, a VAT ID. We do not receive full card details.

If you use a creator or campaign code, we process the code, the redeeming account, the assigned creator, plan and discount data, invoice reference, reward status and timestamps. This supports contract performance, abuse prevention, reversals and correct crediting under Article 6(1)(b) and (f) GDPR.

The legal bases are contract performance under Article 6(1)(b) GDPR and statutory record-keeping under Article 6(1)(c) GDPR. Billing and tax records are retained for the period required by law.

7. Email and support

Transactional and security emails are sent through Resend. Incoming support, privacy and rights requests are processed through a Google email mailbox. We process the sender, message, attachments, technical references and communication history as required to handle the request.

Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR. General enquiries are normally deleted twelve months after closure. Contract, refund, privacy, rights and other evidence-relevant correspondence may be retained for up to three years after the end of the closure year; tax-relevant records follow statutory periods.

8. Security and signup-credit protection

To limit automated signup attempts and repeated claims for free credits, we process network and identity characteristics. An IP-related protection window normally expires after seven days. We also create a pseudonymised SHA-256 check value from a versioned, normalised email identity. It replaces the clear-text address in this claim record but may still be attributable, particularly where address candidates are known, and is therefore protected as personal data. The claim is intended to be retained while the account exists and for no more than three years afterwards for abuse and claims prevention, with annual necessity review. Automated enforcement will be implemented before production.

This key neither changes your login email nor prevents normal use of distinct email addresses. We do not collect MAC addresses; ordinary websites cannot access them. The legal basis is our legitimate interest in abuse and fraud prevention under Article 6(1)(f) GDPR.

Automated protection rules may deny the one-time signup credit or stop a generation for security reasons. Denial of the signup credit does not block the account or access to paid services. You can contact support with questions.

9. Cookies and local storage

MerchKern uses technically necessary session and security information for authentication and account protection.

  • __Secure-better-auth.session_token: necessary login session; HttpOnly, Secure, SameSite=Lax, path /; generally up to 30 days
  • __Secure-better-auth.state: short-lived security state for an intentionally started Google sign-in; HttpOnly, Secure, SameSite=Lax, path /; generally 5 minutes
  • Local storage: merchkern.locale for language, merchkern.theme for appearance and merchkern.library.previewTone for the garment-preview tone; until you change the selection or clear browser data
  • Local storage: merchkern.consent.v2 for the version, time and selection of your privacy preferences; generally 180 days, until an earlier change or until you clear browser data
  • With analytics consent: merchkern.analytics.posthog-consent in local storage as PostHog's technical consent status; other analytics and session-assignment state remains only in the memory of the open page and is discarded when the page closes or reloads. The consent status is removed automatically when consent is withdrawn or expires

MerchKern uses PostHog Cloud EU in Frankfurt for consent-based product and usage analytics. PostHog loads only after you expressly enable analytics. It may process predefined event names, the normalised page path without query strings or fragments, time, browser and device information, a pseudonymous browser identifier, and the technically received IP address. A heavily masked session replay may show navigation, clicks, and scrolling. Every input and page text is masked; uploads, reference images, generated results, and other media are blocked. Email addresses, names, prompts, file names, run, job, checkout, and billing identifiers are not sent to PostHog as analytics properties. Raw events and session recordings are generally retained for no more than twelve months. Automatic click capture, heatmaps, Web Vitals, AI analysis, console and network contents, advertising, and retargeting pixels are disabled.

You can reject every non-essential category, choose categories individually and change your choice at any time through Privacy settings with effect for the future. PostHog is not loaded before the first analytics consent. Withdrawal stops further capture immediately; an SDK that has already loaded remains in the page memory until the page is reloaded. A transfer technically started before withdrawal may still complete or be retried after a network failure. The legal basis for analytics is your consent under Article 6(1)(a) GDPR and section 25 TDDDG.

10. Account deletion and other retention

Before account deletion, any locally linked active Stripe subscription is cancelled. If cancellation cannot be confirmed, deletion stops safely and can be retried. After successful checks, local authentication data, sessions, runs, owned reference uploads, outputs, library files, niches and personal settings are removed; the clear-text name and login email are removed from retained local account records.

Pseudonymised records may continue to be retained for billing, credit evidence, abuse prevention and legal claims. These include the internal user ID, credit entries and technical references, Stripe customer ID, the pseudonymised signup-credit check value, and creator-code and redemption links. These records are not anonymous; self-selected codes or external billing references may remain indirectly attributable. Stripe retains invoice and customer data under its applicable legal and contractual periods. We retain personal data only for as long as its purpose, legal duties, or the establishment, exercise or defence of claims require; the specific standard periods will be set before production.

Account and authentication data is required to create and use an account. Inputs and settings are required when you request the relevant generation. Billing, address, tax and payment data is required for paid contracts. Without the relevant required information, we cannot provide that service or complete the purchase.

11. Your rights

  • Access to your personal data
  • Correction of inaccurate data
  • Erasure or restriction of processing
  • Data portability where the statutory requirements apply
  • Objection to processing based on legitimate interests
  • Withdrawal of consent with future effect

You may also complain to a data protection authority. For private-sector controllers in Bavaria, the Bavarian State Office for Data Protection Supervision is generally competent.

Privacy request[email protected]

12. Changes to this notice

We update this privacy notice when features, providers or legal requirements change. The current version and date are published on this page.

MerchKern

Merch design. Down to the core.

ProductWorkflowResultsCSVPricingFAQ
Learn moreSee the reference workflowSee file specifications
Account
Log inTry it free
© 2026 MerchKern
Legal noticePrivacyTermsRefundsWithdrawalContactCancel subscriptionExercise withdrawal