Privacy policy
What Myrlin Studio stores about you, why it is stored, and who else handles it.
Your account
Sign-in is handled by Clerk. Myrlin receives and stores your Clerk user ID, email address, name, profile picture link and the time you last signed in.
When an account is created, Myrlin records the IP address it was created from. To stop one person from collecting the signup bonus many times, Myrlin also keeps a device fingerprint for seven days: a one-way hash of browser details (user agent, language and compression settings), stored with the account ID, IP address and time.
What you create
Myrlin stores what you put into Studio and what it builds for you: prompts, reference pictures you upload, generated models, textures, preview and inventory images, animations, effects, exports and your build history. Files are kept in Cloudflare R2 storage and records in Myrlin's database.
To build a model, your prompt and reference pictures are sent to the AI model providers that Studio uses.
Your builds are not shown to other users unless Myrlin features one in the public gallery. A featured build shows the model, its texture, preview images, its name and its prompt, without your name or account. To have a featured build removed, email arthur@myrlin.io.
Payments
Payments are handled by Stripe on its own checkout page, so Myrlin never receives your full card number. Myrlin keeps records of your purchases, subscription status, credit balance and credit history, including bonuses, spending and refunds of credits.
Usage measurements and error reports
The site records a small set of its own events, such as page views, how long a page was visible, clicks on named buttons and whether a build was attempted. They are sent to Myrlin's API with a random session ID kept in your browser tab's session storage. Page addresses are reduced to the section name, for example /pricing, so search terms and other values in the address are not kept. When you are signed in, these events can be linked to your account.
When you arrive from a link with campaign tags (such as utm_source or utm_campaign) or an ad click ID (such as gclid or fbclid), or from another website, the site keeps those tags, the click ID, the other website's domain name (not the full address) and the first page you landed on in your browser's local storage for up to 90 days. If you create an account, they are sent once with your first signed-in visit, so Myrlin can tell which links and ads bring new accounts. Once sent, they are removed from your browser, which keeps only a short one-way code of the account so they are not sent twice.
If your browser sends Do Not Track or Global Privacy Control, these events are not sent, and a sign-up source already kept in your browser is removed.
When something breaks in the website, an error report goes to Sentry so it can be fixed. Session replay is turned off.
Messages to Myrlin
Messages you send through the contact form are emailed to Myrlin and stored so they can be answered.
Cookies and browser storage
Clerk sets cookies to keep you signed in. Studio and the editor keep some settings and unfinished work, such as a draft prompt, in your browser's local storage. The site also keeps how you first arrived there for up to 90 days, as described under usage measurements.
Services that handle your data
- Clerk: sign-in and account management
- Stripe: payments and subscriptions
- AI model providers: turning your prompt and reference pictures into a build
- Cloudflare R2: storage for uploaded pictures and generated files
- Vercel: hosting for this website
- Fly.io: hosting for the Myrlin API
- Sentry: error reports from the website
- Resend: delivering contact form messages to Myrlin
Deleting your data
To delete your account and the data stored with it, email arthur@myrlin.io. When an account is deleted, its models, pictures and other files are erased. Payment and credit records are kept with your personal details removed.
Contact
Questions about your data go to arthur@myrlin.io. The terms of service explain credits, payments and the gallery.