Data processing addendum
Last updated 2026-10-02. This addendum is part of the terms of service between you and Jun Zhang, a sole proprietor trading as ImageStep, based in California, United States. It applies to every account without a signature; if your procurement needs a countersigned copy, write to support@imagestep.dev and we will sign this same text.
1. What it covers
The images and other content you send through the API, the SDKs, the CLI, the MCP server, the n8n node or the console can contain personal data of people other than you: faces, licence plates, names, the location and camera serial number in a file's metadata. For that data (“customer personal data”) you decide why and how it is processed, and we process it on your behalf: you are the controller, or the “business” under the California Consumer Privacy Act, and we are your processor, or “service provider”. Your own account data is different: for that we are the controller, and the privacy policy describes it.
ImageStep is not offered in the European Economic Area, the United Kingdom or Switzerland (terms §2), so this addendum carries no GDPR or UK GDPR article 28 terms and no standard contractual clauses.
2. Your instructions
We process customer personal data only to provide the service: to run the operations you call, store their inputs and outputs for your plan's retention period, deliver them where you ask (publishing an asset included, when you publish it) and keep the service secure. The calls you make, your settings and these terms are your complete instructions. If we believe an instruction breaks the law, we tell you and do not follow it.
You are responsible for having the right to process what you send (terms §4) and for telling the people in it what their privacy law requires you to tell them.
3. Service provider commitments
We do not:
- sell or share customer personal data, as the California Consumer Privacy Act defines both;
- retain, use or disclose it for any purpose other than providing the service to you, or outside our direct business relationship with you;
- combine it with personal data we receive from anyone else, except where the law permits a service provider to;
- train models on it, or let anyone else do so.
We meet the obligations the law places on us as a service provider and give customer personal data the level of protection it requires of you. If we can no longer meet them, we tell you, and you may take reasonable steps to stop and remediate any use you did not authorise. We certify that we understand these restrictions and will comply with them.
4. Confidentiality and security
ImageStep is operated by one person, who is bound by this addendum; no employee or contractor has access to customer personal data. Anyone given access in future is bound to confidentiality before they get it.
- Every request between your client and the service travels over HTTPS.
- Assets are private until you publish them. The files are stored in Cloudflare R2, which encrypts them at rest, and a private read is a signed link that expires within minutes.
- API keys are stored as hashes and shown once; every request is authenticated and confined to its own account.
- Account-level actions and refused sign-ins are recorded in an audit log.
- An AI provider receives the image only for the call it serves: a provider that fetches its input reads a temporary copy we delete within the hour, and OpenRouter is told
data-collection: deny.
5. Sub-processors
The companies that process customer personal data for us, and what each one does, are listed in the privacy policy under Who processes it; that list is the current one. Generation and editing run through OpenRouter, which picks the model's upstream provider per request, so that part is not a fixed list: it is limited to upstreams that do not store or train on the request.
We email the address on your account 30 days before a new sub-processor starts receiving customer personal data, and as soon as we can when one has to be replaced to keep the service running. You may object: we will try to offer a way to keep working without it, and if we cannot, you may stop using the operations it serves, or close your account and receive the refund the terms give when we end the service (§5). We remain responsible to you for the processing a sub-processor does for us.
6. Requests from the people in your images
The API finds, downloads and deletes any asset you hold, so a request made to you can be answered by you directly. A request made to us about customer personal data is passed to you rather than answered by us, and we help you answer it when you ask.
7. Deletion
Customer personal data is deleted when you delete it, when its retention period ends, or when you delete your account; database backups, kept encrypted in Cloudflare R2 in Europe, keep a copy for up to 56 days before it ages out. Before you leave, the API and the console download everything you stored.
8. Security incidents
If we become aware of a breach of security that leads to customer personal data being lost, altered, disclosed or accessed without authorisation, we tell you by email without undue delay and within 72 hours: what happened, what data it touched as far as we know, and what we are doing about it. We keep you informed as we learn more.
9. Showing that this is met
Once a year, on written request, we answer your reasonable security and privacy questionnaire and give you the information you need to show that this addendum is met. Self-serve plans include no on-site audit.
10. Liability and precedence
Liability under this addendum is subject to the limits in the terms (§8). Where this addendum and the terms disagree about customer personal data, this addendum wins.
Questions: support@imagestep.dev