Privacy
Privacy policy
What Raywake collects when you use the studio and the API, why, on what legal basis, who helps us process it, how long we keep it, and the rights you have.
Last updated 5 October 2026
Who is responsible
Raywake, operated from Germany, is the controller for the personal data described here. For any privacy question or request, write to hello@raywake.com. We have not appointed a data protection officer, as the law does not require one for a business of our size.
What we collect and why
- Account details: your email address and, if you sign in with Google or GitHub, the name, email and profile picture they share. For email sign-in we store a salted hash of your password, never the password. Basis: performing our contract with you (GDPR Art. 6(1)(b)).
- Email preferences: the English or Turkish language used for account emails, and whether you choose to receive model announcements and offers. Optional campaign consent records its time and notice version; withdrawing it records the withdrawal time. New accounts are not automatically subscribed. You can change the language or withdraw consent in Settings. An unsubscribe stops campaign emails; essential account, security and payment emails continue. For these campaigns, we may use account age, promotion redemption, generation activity and credit records to send a first-generation gift-code invitation or a low-gift-credit reminder. We retain delivery status and a keyed address digest to prevent duplicate campaigns and block addresses that bounce or report spam. A queued message and unsubscribe link are erased on completion or cancellation, or when a running worker clears an expired item. Paused processing can delay expiry cleanup; expired items cannot be sent. Basis: contract for account emails; consent for campaigns where you have given it (Art. 6(1)(a)).
- What you create: prompts, settings, uploaded input files and the images, video and audio generated for you, with each generation’s model, status and credit cost. Basis: contract.
- Credits and payments: your credit balance and its history and the packs you buy. Stripe processes the payment; we receive its status, amount and currency, never your full card number. Basis: contract, and our legal duty to keep accounting records (Art. 6(1)(c)).
- API keys: a hash and a short prefix of each key you create; the full key is shown to you once. Basis: contract.
- Technical data: your IP address, to limit request rates and keep the service secure, and your country as reported by our network provider, to show prices in your region’s currency. Basis: our legitimate interest in a secure, correctly priced service (Art. 6(1)(f)).
- Site and studio analytics: Google Analytics starts when you open a customer-facing page, including sign-in and sign-up, without waiting for a button click. It receives a fixed page name, limited interactions (such as choosing a model), referring site and technical request information such as your IP address and browser information. Analytics cookies distinguish browser visits and sessions. Advertising storage and personalization remain disabled. Studio visits use fixed page categories, including Dashboard Home, Dashboard Explore and Model playground. We exclude account identifiers, email addresses, API keys, generation identifiers, prompts, results, form values, raw query strings and URL fragments from the events we send. From campaign links, we retain only recognized source and medium labels and validated short campaign names and identifiers; free-text search terms and content parameters are excluded. Administration and non-page API/file routes are excluded. We measure successful account creation on the server, including the sign-up method (email, Google or GitHub), linked to the browser’s analytics session. Completed purchases are measured only after Stripe confirms payment, with a transaction reference, purchased pack, paid amount and currency, linked to an available browser analytics session. Purchase events do not include your email, account identity, payment card details or promotion code. We do not enable advertising features or Google signals.
- Emails you send us, and withdrawal declarations. Basis: contract and legal obligation.
We do not sell personal data, show ads or build advertising profiles, and we do not use your prompts, uploads or results to train models. Account and payment details are needed to provide the service; without them we cannot open an account or sell credits. We do not make decisions about you based solely on automated processing.
To prevent repeated promotion claims through Gmail aliases or recreated accounts, we retain keyed mailbox and account digests linked to the promotion and its use. These keys remain after account deletion, contain no plain-text email address and do not change your sign-in address. Basis: legitimate interest in preventing promotion abuse (Art. 6(1)(f)).
Who processes it for us
These providers process data on our behalf under data processing agreements, or as independent controllers where they say so (for example Stripe for fraud prevention):
| Recipient | Purpose | Location |
|---|---|---|
| Stripe | Payments and fraud prevention | EU and USA |
| Cloudflare | Delivering the site, storing uploaded and generated files, forwarding email | Global network, incl. USA |
| Hetzner Online | Servers and databases | Finland (EU) |
| Resend | Sending account and receipt emails, and optional campaign emails | EU and USA |
| AI model providers | Running the generations you start | USA and elsewhere |
| Google Analytics | Measurement of visits, campaigns, registration and completed purchases | EU and USA |
| Google, GitHub | Sign-in, only if you choose it | USA |
AI model providers receive only the prompt, settings and input files of a generation you start, to produce its result. Where data leaves the EU/EEA, we rely on the European Commission’s adequacy decision (including the EU–US Data Privacy Framework for certified providers) or on Standard Contractual Clauses. You can ask us for a copy of the safeguards.
ChatGPT and Codex plugin
If you connect Raywake in ChatGPT or Codex, we keep a separate connection record with your Raywake account identity, permissions, credit ceiling and expiring token hashes. Quotes also keep the prompt or speech text and fixed generation settings so retries use the same approved request. Connection records and their quote copies last at most 30 days, or until revoked or rejected by the account-session check.
OpenAI receives the tool results needed for your requests, such as available models, balance, quoted cost, job status and signed links to your own files. Anyone holding a signed link can access that file while the link remains valid. OpenAI processes your conversation and received results under the terms and settings of your OpenAI account. Raywake does not send your password, provider credentials or payment card details through the plugin. Starting a generation sends its text and settings to the model service, as described above; the plugin uses the selected model from Raywake's current catalogue. Model inputs may include text, settings and supported media references.
Disconnect in Settings → ChatGPT connections to stop future tool access. The web account export includes your connection and quote records. Deleting your Raywake account or revoking its sessions causes background checks to remove the separate connection records and quote text without a new plugin request. Checks run at startup and repeat after a 60-second pause; service outages or validation delays can postpone cleanup. Removing records is logical database deletion, not a guarantee that residual storage pages or existing backup copies are immediately overwritten.
Generation records in your main account follow the retention periods below. Disconnecting does not cancel work already submitted or delete information already received by OpenAI. For access or deletion questions, contact hello@raywake.com. The Raywake plugin is published by OGUZHAN KAYAN.
How long we keep it
| Data | Kept for |
|---|---|
| Uploaded files and generated results | 30 days, then deleted automatically |
| Prompts, settings and generation records | While your account is open |
| Account details | While your account is open; deleted on request |
| Email language and campaign consent | While your account is open; consent can be withdrawn in Settings |
| Campaign delivery records | Linked to your account while it is open. After deletion, detached campaign/address/provider keys and delivery status/timestamps remain to prevent repeats, respect cooldowns and process late receipts. Retry message content is removed on completion/cancellation or when a running worker clears an expired item; paused processing can delay expiry cleanup |
| Campaign duplicate and suppression keys | Retained after account deletion to prevent repeat mail and respect bounce/complaint blocks; these keys do not store your address in plain text |
| Promotion eligibility keys | Retained after account deletion to prevent repeated gift-credit claims; these keyed mailbox/account digests contain no plain-text email address |
| Payment and credit records | 10 years, as tax and accounting law requires |
| Security logs (IP address) | Up to 30 days |
| Analytics user and event data | 2 months; aggregate reports may remain longer |
| Notice dismissal (session storage) | Until the browser tab session ends |
Cookies and your choices
When you close a campaign announcement, the raywake_announcement_dismissed preference cookie remembers that edition for up to one year. A newly published announcement can appear again. This cookie contains only the edition number and is not used for analytics.
We keep the raywake.pricing-locale preference cookie for 180 days so the currency selected by your site language continues through checkout. English pages use USD and Turkish pages use TRY. Without a language preference, currency defaults to your country. This cookie is not used for analytics or advertising.
Essential cookies keep you signed in, protect sign-in forms and remember security state (§ 25(2) TDDDG). They do not require optional analytics consent.
Google Analytics uses _ga and _ga_* first-party cookies to measure visits and sessions. We configure a 30-day cookie lifetime without renewing expiry on each visit. Google receives measurement requests before you close the notice. Closing it only hides the notice for the current tab session; it is not treated as consent and does not change collection.
The raywake_ga_context first-party analytics cookie holds only the tag’s pseudonymous browser and session identifiers and their capture time for 30 minutes, so successful server-side registration and payment can be linked to their preceding visit. A checkout keeps a copy until payment settles or the checkout expires. A pending purchase event is retained for delivery retries; its payload is cleared when delivery is accepted or retries end. These analytics records are separate from the payment records kept for accounting.
Essential cookies still support authentication and security. The notice dismissal is stored in session storage under raywake.analytics-notice.v3. We do not use advertising cookies. You can block Google Analytics with browser controls or Google’s opt-out browser add-on. See Google’s privacy policy for its data processing practices. Analytics transmits data to Google and uses pseudonymous browser identifiers; this data is not anonymous.
Your rights
You can ask to access, correct, delete or export your personal data, and to restrict processing. Where we rely on legitimate interest, you can object at any time. Write to hello@raywake.com from the email on your account; we answer within one month. You can also complain to a data protection supervisory authority, in particular where you live or work.
For users in Turkey (KVKK)
This notice is also our information notice under Article 10 of Turkey’s Personal Data Protection Law No. 6698. We collect personal data electronically through the site, the API and our payment and sign-in providers, for the purposes and on the legal grounds above (Article 5: performance of a contract, legal obligation, legitimate interest and consent for optional campaigns). Data is transferred abroad to the recipients listed above to provide the service. Under Article 11 you can ask whether your data is processed, request information, correction, deletion or notification of recipients, object to results of automated analysis, and claim compensation for unlawful processing. Send requests to hello@raywake.com.
Children
Raywake is not meant for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy we update the date above and tell you by email or in the studio when the change is significant. See also our Terms and Refund policy.