Last updated: 9/15/26
Welcome to CoralFlavor (“we,” “our,” or “us”). This Privacy Policy explains how information is handled when you use https://coralflavor.com (the “Website”), including our web chat, API, and related services.
By using the Website, you agree to this Privacy Policy. If you do not agree, do not use the Website.
We intentionally minimize chat retention:
If you enable Save mode, your saved chats may be disclosed when we are legally required to do so (for example, in response to a valid subpoena, warrant, court order, or other lawful process).
When you sign in (for example with Google / Firebase Authentication), we may collect and store:
We collect and store your email address (and, where provided, your name or display name) to send:
We may also store marketing preferences, unsubscribe / suppression status, and records of when and how you consented to marketing email, so we can honor opt-outs and demonstrate permission if required.
Email delivery is handled by Mailgun (Sinch Email), a third-party email service provider. Mailgun processes recipient addresses, message content, and related delivery metadata (such as bounces, complaints, and, if we enable tracking, opens or clicks) solely to send and measure our emails on our behalf. Mailgun’s practices are described in their policies at https://www.mailgun.com/legal/privacy-policy/ . We do not sell your email address as a mailing list.
You can unsubscribe from marketing email at any time via the unsubscribe link in those messages (or via in-product controls where available). We honor unsubscribe requests without undue delay. Unsubscribing from marketing email does not delete your account and does not stop transactional email needed to provide the service. We may retain your address on a suppression list so we do not email you again after you opt out.
Each marketing email includes a link to this Privacy Policy and a way to opt out, and identifies us as the sender.
Paid features (such as Pro) are processed by Stripe (and, where offered, crypto payment processors). We may store billing-related identifiers (for example a Stripe customer ID), plan status, and purchase metadata. We do not store full payment card numbers on our servers; card data is handled by Stripe according to Stripe’s policies.
If you upload images or PDFs, we process them for text extraction (OCR) only, so extracted text can be included in your prompt. Uploads are not intended for generative deepfakes, face-swap pipelines, or other identity-misuse features. Raw uploaded files are processed to extract text and are not retained as a permanent media library on our side; extracted text may be retained in a chat if Save mode is enabled.
If you use Pro or Pro+ image generation, your image prompts are sent to a third-party image generation provider to create images. Generated image URLs or related content may appear in your chat history if Save is enabled. On Pro+, a prior generated image from the same chat may also be sent to that provider as a reference so later images can keep character consistency. Monthly image quotas differ by plan (for example, higher limits on Pro+).
We use Google Analytics to understand general Website usage. Google Analytics may collect information such as:
This data is processed by Google according to their privacy policy: https://policies.google.com/privacy
Google Analytics and sign-in providers may use cookies or similar technologies. You may disable cookies through your browser settings; however, some functionality (including authentication) may be limited.
We use collected information to:
To generate AI responses, your prompts and related chat content are sent to third-party model providers (for example via an API gateway such as OpenRouter). Those providers may process and technically access that content in order to return a response. We respect your privacy and do not share your identity (such as your name, email, or account identifiers) with those model providers as part of inference.
Unless we route a request only to zero-data-retention (ZDR) endpoints, providers may retain prompts or outputs for a period that varies by provider (sometimes days or weeks, and in some cases longer or open-ended under their policies). ZDR-capable endpoints claim not to retain content after processing. Provider policies change; we do not control third-party retention practices.
We are not responsible for the privacy practices of third-party services, including model providers, image providers, Stripe, Firebase/Google Authentication, Mailgun, Exa (web search, where used), and Google Analytics. Use of third-party services is at your own risk.
We take reasonable technical measures to protect the Website. However, no internet transmission or electronic storage method is completely secure, and we cannot guarantee absolute security. We enforce SSL/TLS encryption in transit on this website. Saved chats stored in our server-side database are without encryption at rest as described above.
You may request account deletion in product settings (subject to requirements such as canceling an active Pro subscription first). When an account is deleted, we delete associated saved chats and remove authentication access. We may retain a limited credits / billing record and deletion markers needed for abuse prevention, accounting, or legal compliance.
The Website is strictly intended for users 18 years of age or older. We do not knowingly collect information from anyone under 18. If we learn we have collected personal information from a child under 18, we will delete it.
We may update this Privacy Policy at any time. Updates will be posted on this page with a revised “Last updated” date. Continued use of the Website constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, contact us at:
[email protected]