1. Information we collect
Creation data includes the uploaded photo, crop or orientation information, your description, configured field values, AI suggestions, public research sources, generated designs and your selected version.
Order data includes email, phone number, recipient name, postal address, order and fulfillment status, consent version and acceptance time. Stripe processes payment credentials; EditionKey stores payment and refund references rather than your complete card number.
Operational data may include capability-protected draft references, security logs, provider request identifiers, safety decisions, audit events and device or network information needed to prevent abuse and diagnose failures.
2. How we use information
We use the information to restore your draft, analyze the toy photo, research public sources, suggest fields, generate the card face, perform safety review, take payment, produce and post the physical card, create its digital identity, support My Cards and handle support or disputes.
We also use approved final Toy Cards and confirmed public labels for the public gallery and permitted EditionKey promotion under the licence you accept at checkout.
3. AI, search, payment and delivery providers
Configured AI and public-search providers may receive the minimum content needed for analysis, research, generation and safety review. Results are treated as suggestions and provider access is subject to EditionKey configuration and contracts.
Stripe receives information required to process payment and refunds. Hosting, media storage, email and postal fulfillment providers receive only the information needed for their service. These providers may process data in other jurisdictions under applicable safeguards.
4. What may become public
Only a paid final Toy Card approved for public display may appear in the gallery. Public information may include the final card face, Card ID, collection or category, publication date, confirmed primary and auxiliary labels and the corresponding Registry facts.
The original uploaded photo is not published separately. Your private description, unapproved drafts, unwatermarked print file, name, email, phone number and delivery address are not public gallery information.
5. Retention and deletion
A resumable draft normally expires after seven days. An unpaid source upload is scheduled for deletion no later than thirty days after creation. A paid source upload is scheduled for deletion no later than ninety days after payment, unless a shorter period is required or a lawful preservation need applies.
Deletion of a source upload does not delete the paid final card, Card ID, certificate, consent, order, review, audit or fulfillment record where those records remain necessary for production, verification, legal compliance, fraud prevention or dispute handling.
Backups and provider systems may require a limited additional period to complete secure deletion. Public display removal and deletion of an identity record are different requests and may have different legal outcomes.
6. Security and anonymous drafts
Anonymous drafts use an unguessable capability stored in an HttpOnly cookie. Keep access to your device and browser secure. EditionKey does not place the draft access token, private storage key or unwatermarked asset URL in the public page model.
No system can guarantee absolute security. EditionKey limits access by role, audits sensitive platform actions and uses separate public, draft, review and production media boundaries.
7. Your choices and contact
You can choose not to use AI creation by not uploading a photo. Before checkout, you may stop and allow the draft to expire. Public display requires the checkout grant, and EditionKey may consider a later showcase-removal or rights request subject to identity verification, operational records and applicable law.
Use the official Contact page for access, correction, deletion, privacy or takedown requests. Include the relevant Card ID or draft reference, but never send complete payment-card credentials.