THE FIELD GUIDE
Private by default.
We need account and job information to create your assets. Your game should not need your account credentials.
Information we process
Google sign-in provides your account identity, verified email, name, and profile image. We do not receive your Google password.
Generation uses your prompts, uploaded references, selected settings, and generated files. We keep job status and usage records to operate the service.
Favorites, collections, and feedback belong to your account. Administrators can access records for support and service operations.
Storage and providers
We use infrastructure providers for private object storage, queues, email, hosting, and payments. Some asset providers process requests through external APIs.
Provider selection can affect where request data is processed. Inspect the request provider before sending sensitive material.
Stripe processes payment details during checkout. Do not send card details through prompts, email, or the CLI.
Sessions and security
Login requires session cookies. The CLI uses separate credentials. Never include either credential in a public game.
Private previews require authentication. Anyone who can play audio can still record it. We do not promise technical prevention of all copying.
Retention and your choices
Generated file retention will follow the storage policy after enforcement begins. Billing, security, and operational records can remain after file deletion.
We have not published a fixed retention period for every operational record. Contact us for account export or deletion requests.
This notice does not authorize public publishing of your assets. Public sharing requires a separate action or product feature.
Contact
XP.COM, LLC operates Asset Yard. Contact linh@ai-hacker.com with privacy questions or an account request.
Updated September 5, 2026.