privacy
in force from 18 September 2026
The short version: what you file on the wall is public on purpose, with the name you chose. Everything else we keep small, we do not sell, and we delete when you ask.
who runs this
PhotoPrompting is run by Matthew Clary, an individual in the United States. There is no company behind it yet. When this page says “we”, it means him and the software.
what is public
A take is a public line. When you file one, the line, the song it is on, the part of the song it is about, your display name and the date are shown to everyone. Public lines also travel: on take and song pages, on picture cards and printable pages, in embeds, through the public API, in the Discord bot, in the daily post on social networks and in the weekly letter. Votes are counted in public; who cast each vote is not shown.
Filed lines are also read together, weekly, to distil the house voice, the writing style the site’s API answers in. You can delete any line you filed and it leaves the wall, the API and the next distillation. Copies that already travelled, such as a posted card, a cached page or a printed sheet, can outlive the deletion.
what we collect
- An account, if you make one: your email and display name, and if you sign in with Google or Spotify, the basic profile they hand over (name, email, picture). Passwords are handled by our sign-in provider; we never see them.
- What you do with the account: lines filed, votes, credits bought and spent, API keys issued to you.
- A linked Discord identity, if you run
/link: your Discord user id and handle, so lines you file from Discord are credited to you. A server admin who runs/keystores that server’s API key with the bot. - Your email, if you ask for the daily take or the weekly letter, until you unsubscribe.
- Purchases: Stripe takes the payment. We never see your card number. We keep what Stripe reports back: your email, the amount and what you bought. Tips sent in crypto are on a public blockchain by their nature.
- Requests to the server: like every website, ours logs the IP address, browser and page for each request. Those logs are kept for about two weeks for security and debugging. Short-lived counters keyed by IP enforce the API’s rate limits and are never written to disk.
analytics, cookies, tracking
We measure visits with Umami, running on our own server, and with Cloudflare Web Analytics. Both are cookieless and neither builds a profile of you or follows you to other sites. There are no advertising cookies and no ad networks here.
The cookies we set are functional: one keeps you signed in, and one remembers that you have already seen the front page. Your browser’s local storage holds small preferences. Spotify’s player, once you press play, is Spotify’s and follows Spotify’s own cookie rules.
the voice and ai
The house voice is generated by Anthropic’s Claude through its API. What is sent: the song’s title and artist as the open music encyclopedia MusicBrainz lists them (or, when MusicBrainz does not know the song, the public lines people wrote on it), a handful of public lines as examples of the voice, and, when you use the audition or the prose booth, the text you typed into it. What is never sent: your email or account details, and anything from Spotify — not its song titles or artist names, cover art, lyrics, audio or video. Anthropic handles this under its commercial terms, which say API inputs are not used to train its models by default.
Nothing the voice writes is filed on the wall as if a person wrote it. Generated lines are labelled as the house read.
who else handles data
- Supabase: the database and sign-in.
- Cloudflare: delivers the site and filters abusive traffic, so it sees request data including IP addresses.
- A rented virtual server: runs the site, the bot and the analytics.
- Stripe: payments. Anthropic: the voice. Resend: sends the letter. Discord: if you use the bot there.
- Spotify: cover art loads straight from Spotify’s servers into your browser. When you press play, Spotify’s own player loads inside the page and plays the 30 seconds; from that moment Spotify sees the request the way it would on any site that embeds its player, and may set its own cookies. Nothing loads from Spotify’s player until you press play.
We do not sell personal data, and we do not share it with anyone beyond the handlers above, unless the law requires it.
your choices
- Delete a line: open it while signed in and remove it.
- Unsubscribe: every email carries a one-click link.
- Remove a Discord link, close your account, or get a copy of what we hold: write to the address below. We answer within 30 days, and deleting an account removes the account, its lines if you ask, its keys and its balances.
People in the EU, the UK and California have these rights by law. We extend them to everyone.
age
PhotoPrompting is not for children under 13, and we do not knowingly keep data about them. If you believe a child has made an account, write to us and it will be removed.
changes
When this page changes in a way that matters, the date at the top changes and the wall says so. The terms cover the rules for using the site and the API.
Questions, requests, or anything that looks wrong: [email protected]. A person reads it.