RemaGem
Sign In

Privacy Policy

Last updated: 31 August 2026

This Privacy Policy explains what information RemaGem (“RemaGem”, “we”, “us”) collects when you use the RemaGem service at www.remagem.com, why we collect it, who we share it with, and what rights you have over it.

1. Who we are

RemaGem is an AI-powered thumbnail and asset generation service for the iGaming industry. You upload source images, and we use third-party AI models to generate new creative assets from them. For the purposes of the EU General Data Protection Regulation (GDPR), RemaGem is the data controller for the personal data described below.

Privacy questions and requests: support@remagem.com.

2. What we collect

Account information

Authentication is handled by Supabase Auth. When you create an account we store:

  • Your email address, and a securely hashed password if you sign up with email and password. We never see or store your password in plain text.
  • If you sign in with Google, the basic profile information Google returns to us: your email address, your name, and your profile picture (avatar) URL. We request only the basic profile and email scopes. We do not receive your Google password, and we do not access your Google Drive, Gmail, contacts, or any other Google service data.

Content you upload

  • Images you upload to your library, together with any metadata you supply about them (such as a title or provider name, including via CSV upload).
  • Prompts and generation settings you enter when configuring a generation.

Content we generate

  • AI-generated output images produced from your inputs, which we store so you can view, re-generate, and download them.
  • Generation records: status, timestamps, variant labels, and any error details.

Billing and credits

  • Your prepaid credit balance, credit purchases, promotional credit grants (such as the sign-up credit), and per-generation credit consumption records.
  • Payments are processed by our payment provider. We do not store your full card number or other complete payment instrument details on our systems.

Support correspondence

  • When you contact us through the in-app contact form, we store the email address, subject, and message you submit, along with your account identifier if you were signed in at the time. You can reach us without an account, in which case no identifier is recorded and the address you give is not verified.

Technical and usage data

  • Standard server and application logs generated when you use the service: IP address, browser user-agent, request paths, timestamps, and error traces. These are used for security, abuse prevention, and debugging.

We do not collect special categories of personal data (such as health, biometric, or political data), and you should not upload images containing such data.

3. How we use your information

  • To create and maintain your account and authenticate you.
  • To operate the core service: storing your uploads, sending them to AI models for processing, and storing and serving the generated results back to you.
  • To track and deduct your credit balance and process purchases.
  • To send you service-related email (account confirmation, password reset, and important notices about your account or the service).
  • To handle support requests. When you contact us, the message you send, the email address you give, and — if you were signed in — your account identifier are stored and processed by an AI model so we can categorise the request, look up any related errors on your account, and prepare a response. A human reviews every reply before it is sent to you. Support messages are never used to train AI models.
  • To secure the service — detecting, investigating, and preventing abuse, fraud, and technical faults.
  • To comply with legal obligations.

We do not sell your personal data, and we do not use your uploaded images or generated outputs to train our own or third parties’ AI models.

4. Third-party processors

We rely on the following service providers to run RemaGem. Each processes data only as needed to provide their service to us:

  • Supabase — authentication, database, and file storage. Our Supabase project is hosted in the EU (Frankfurt, eu-central-1)region. This is where your account data, image files, and generation records live.
  • Vercel — hosting and content delivery for the RemaGem web front-end.
  • Railway — hosting for the RemaGem backend API.
  • FAL — AI inference. Images and prompts you submit for generation are transmitted to FAL to run the AI models that produce your output.
  • Google (Gemini) — AI inference. Images and prompts you submit for generation are analysed by Gemini models as part of the generation pipeline, and the text of support requests you send us is processed by Gemini to help us triage and answer them.
  • OpenAI — AI inference used by parts of the generation pipeline to process prompts and generate text.
  • Resend — email delivery. Used to send account email (confirmation, password reset) and to deliver support correspondence.
  • GitHub — source code hosting. When triaging a support request, our system reads our own source code from GitHub to diagnose the issue. Your personal data is not sent to GitHub.

We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, safety, and property of RemaGem or our users.

5. International transfers

Your account data and stored images are held in the EU (Frankfurt). Some of our processors — in particular our hosting and AI inference providers — may process data outside the European Economic Area, including in the United States. Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

6. The public gallery

RemaGem includes a public gallery. A RemaGem administrator may mark a generation as public. When that happens, the output images from that generation become visible to all logged-in RemaGem users in the Gallery, and they can be viewed and downloaded by those users.

Public gallery entries do not display your email address or account identity, and do not expose the prompt or configuration used to produce them. Generations are private by default. If you want a generation removed from the public gallery, contact us at support@remagem.com.

7. Cookies

RemaGem uses cookies only for authentication. The session cookies set by Supabase Auth keep you signed in as you move between pages, and are strictly necessary for the service to function. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. Clearing these cookies signs you out.

8. Data retention

  • Account data is kept for as long as your account is active.
  • Uploaded images and generated outputs are kept until you delete them or your account is deleted.
  • Billing and credit records may be kept longer where we are required to retain them for tax or accounting purposes.
  • Server logs are kept for a limited period for security and debugging, then discarded or aggregated.
  • Support correspondence is kept for as long as needed to resolve your request and to maintain a record of past issues, and is deleted on request.

When you ask us to delete your account, we delete your account data, uploads, and generated outputs, except where we must retain records to meet a legal obligation. Backups are purged on their normal rotation schedule.

9. Security

Data is transmitted over TLS and stored with our providers’ encryption at rest. Access to production data is limited to personnel who need it to operate the service. No system is perfectly secure, so we cannot guarantee absolute security, but we take reasonable technical and organisational measures to protect your data.

10. Your rights

You can ask us at any time to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and associated data (the “right to be forgotten”).
  • Export a copy of your data in a portable format.
  • Restrict or object to certain processing, including processing based on our legitimate interests.
  • Withdraw consent where processing is based on consent.

Send requests to support@remagem.com. We will respond within one month. We may need to verify your identity before acting on a request.

11. Legal bases (EU/EEA and UK users)

Where the GDPR applies, we process your personal data on these bases:

  • Performance of a contract — creating your account, running generations you request, storing your assets, and managing your credit balance.
  • Legitimate interests — securing the service, preventing abuse and fraud, debugging, and improving reliability. We balance these against your rights.
  • Legal obligation — retaining billing and tax records.
  • Consent — where we ask for it specifically, for example for non-essential communications. You can withdraw consent at any time.

You also have the right to lodge a complaint with your local data protection supervisory authority.

12. Children

RemaGem is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service evolves. We will update the “Last updated” date above, and for material changes we will notify you by email or an in-app notice before the change takes effect.

14. Contact us

Questions, requests, or complaints about this policy or your data: support@remagem.com.


See also our Terms of Service.

RemaGem
PrivacyTerms

© 2026 RemaGem Infrastructure. Laboratory-Grade Precision.