RO THUMBNAIL / PRIVACY & SOURCES
Your draft stays in this browser until you choose a network action.
Effective October 9, 2026. This policy separates local project editing from product sign-in, optional Roblox connection, AI generation, billing, and share links so you can decide when data leaves the browser.
Project data stored in the browser
The brief, uploaded references, imported previews, composition settings, variants, generation history, and export state are stored in this browser using IndexedDB. They remain until you clear this site’s browser data or replace the project. Downloaded exports remain wherever you save them. Browser storage is not an online backup and does not follow you to another device.
Public Roblox lookups
When you explicitly look up a game or Avatar, the entered URL, ID, or username is sent to this application’s server, which requests public information and preview images from Roblox. A public preview provides source context; it does not grant reuse, AI-training, or redistribution rights.
Ro Thumbnail account and sign-in
You can use local editing features without a product account. Spending account credits, checkout, or an optional Roblox connection requires a Ro Thumbnail account. During the controlled migration, an invited beta access code may separately unlock protected AI and hosted-share services; it is not a customer account and is not silently merged into one. Draft projects remain in that browser unless you explicitly create a hosted share; this release does not provide cloud project history or cross-device draft restore. If Google sign-in is enabled and you choose it, Google provides a stable account identifier, verified email address, and basic profile information such as name and profile image. Ro Thumbnail does not receive your Google password.
If email-code sign-in is enabled and you choose it, the service processes the email address you enter and Cloudflare Email Sending delivers a six-digit, one-time code from mail.thumbnail-maker.net. The server stores a protected representation of the challenge rather than the plain code. The code expires after ten minutes and is limited to five attempts. A random internal user ID, account creation/update times, linked sign-in methods, and security events are stored to operate and protect the account.
Essential session cookies
After sign-in, the service sets an essential HTTP-only session cookie so the server can recognize the account and protect account-owned actions. The standard session expires after 30 days. The cookie is not an advertising identifier and is not available to page scripts. Signing out revokes the current session; “sign out everywhere” revokes all product sessions but does not disconnect Roblox. Revoked and expired session records are pruned under the service’s retention process.
Optional automatic generation
When automatic generation is enabled and you choose Generate, New Take, or Refine, the application first sends the bounded text prompt to Waffo Prompt Sift for a pre-generation safety decision. Waffo states that this check is stateless and does not retain the prompt text after returning its decision. Only an allow decision continues. A review, block, rate limit, service degradation, missing configuration, or audit-storage failure stops generation. Prompt Sift checks text; it does not inspect uploaded references or the generated image.
After an allow decision, the prompt and enabled reference images are sent through the application server to Alibaba Cloud Model Studio (Bailian). The configured image model is wan2.7-image. Service credentials remain on the server. Alibaba Cloud handles submitted data under its own terms, privacy policy, region, and account agreement. Do not include personal or confidential information in a prompt or reference.
Prompt moderation records
For security, abuse review, appeals, and compliance evidence, the application stores the safety action, reason code, matched policy categories, Waffo request ID, semantic-check status, operation, time, retry metadata, and keyed SHA-256 hashes of the prompt, application request ID, and internal account identifier. The audit record does not contain the prompt text, raw application request ID, raw internal account identifier, or reference images. Production retains these audit records for 180 days and then deletes them through scheduled cleanup. The isolated test deployment is configured for 30 days.
Region and AI-credit eligibility
The service may receive a country code from its trusted hosting edge to decide whether a free AI trial is available and whether trial credits may be used. The standard policy does not issue or spend free AI credits in India; paid AI credits and features that do not call a third-party AI processing service remain available. The application does not accept a browser-supplied country value for this decision.
Optional checkout and billing
If a deployed service enables paid plans or credit packs and you choose checkout, the product selection, an application account identifier, optional checkout email, and order metadata are sent to Waffo Pancake, the hosted checkout and merchant-of-record provider. Waffo processes payment and billing details under its own terms and privacy policy. Ro Thumbnail uses signed payment notifications to grant or revoke credits; returning to the site after checkout does not itself grant paid access.
Generation files on the application server
The standard deployment stores generated images and AI job records temporarily so interrupted work can recover. The default application retention is 24 hours, with automatic expiry and a storage cap. Production object storage also expires orphaned generated/ files after two days as a cleanup safety net. Expiry removes the server copy, not an export you already downloaded or a copy retained by a third-party AI processor.
Share links
Creating a share link uploads a serialized project copy, which can include embedded references and generated results. Anyone with the link can open and copy it; the link is a bearer secret rather than an account permission. The standard application expiry is seven days, with an eight-day object-storage lifecycle as a cleanup safety net. The share response includes its expiry and a separate deletion token. Keep that token private; it authorizes early deletion of the hosted share.
Optional Roblox account connection
A Roblox account is not your Ro Thumbnail login. If Roblox OAuth is enabled and you choose to connect after signing in, the service receives the Roblox account information and permissions shown on Roblox’s authorization screen. One account-indexed connection is stored at a time; its tokens are encrypted on the server, are not written into the browser project, and expire after 30 days by default. Signing out everywhere does not disconnect Roblox. Explicit disconnect removes the local tokens even if provider revocation fails; Roblox may provide separate controls to revoke the provider grant.
Account retention and deletion
Account and linked-identity records are kept while the account exists. An authenticated deletion request immediately disables the account, revokes every product session, removes account-owned generated AI files/jobs and credits, and clears the encrypted Roblox connection. Provider revocation is attempted where supported. Scheduled cleanup finalizes user and identity removal after a 30-minute operational grace period. A deletion tombstone blocks a late payment event from restoring credits. Billing webhook receipts may retain an opaque former account identifier for reconciliation. Deletion does not mean that local browser data, a bearer share, an already downloaded export, a recipient’s copy, or data retained by a third-party provider was deleted.
Isolated test deployment
The controlled environment at waffo-test.thumbnail-maker.net uses shorter limits than the standard deployment: product sessions and Roblox connections expire after one day, generated files and jobs after one hour, hosted shares after 24 hours, and account deletion has a five-minute operational grace period. Test prompt-moderation audit records are retained for 30 days. These limits do not describe the production service.
Other deletion boundaries
Clear this site’s browser storage to remove the local project from that browser. Revoke a shared copy using its deletion token before expiry when that control is available. Temporary generation files and AI job records expire under the server policy described above. Clearing browser data or deleting an account does not automatically delete a hosted share unless the deletion receipt says it did, an already downloaded export, data already sent to Roblox, or data already processed by a configured third-party service.
Operational data and security
Cloudflare provides the application’s hosting, storage, network security, country signal, and sign-in email delivery. The service may process ordinary request metadata needed to deliver and protect the product, such as time, route, response status, network address, and hashed device/security signals in hosting logs and account-session records. This source build does not include advertising trackers or claim a cross-site analytics profile. No online system is risk-free, so avoid uploading secrets and use share links only for material you are prepared to disclose to the recipient.
Source and rights policy
Upload only material you own or have permission to use. Public Roblox examples remain linked to their source and are used as attributed composition references, not bundled stock. You are responsible for reviewing the final Avatar, artwork, marks, and gameplay claim before publication.
Privacy and deletion questions
Contact support@thumbnail-maker.net about a privacy request, account deletion, moderation record, hosted share you can no longer revoke, or another server-side deletion question. Include the account email, share URL, moderation request ID, or application request ID only when relevant, but never send a password, one-time code, session cookie, service credential, OAuth token, or share-deletion token by email.
Acceptable use → · Terms · How it works · Creator guide · Return home