STANDIN

Privacy Policy

Last updated: August 17, 2026

This policy describes Standin's primary website product and its separate Telegram interface. Inputs and results are private by default; Standin does not publish them or add them to a public gallery.

What the website processes

What the Telegram interface processes

The separate bot processes the Telegram account/chat identifier required to run its flow, versioned consent evidence, submitted media, render and delivery state, compact campaign attribution where present, and safe operational events. Website actors and Telegram actors are not merged, and website entitlements are not redeemable in Telegram.

Cookies, network controls, and attribution

The web creator uses a bounded-lifetime, server-generated session cookie. Sensitive state is not placed in the cookie. State-changing requests use CSRF protection. For short-lived abuse throttling, Standin can derive a keyed network identifier from a request address; raw IP addresses are not placed in growth analytics. Exact file digests may be kept briefly to stop duplicate submissions. Standin does not create face hashes, biometric embeddings, or cross-user face-identity matches.

Campaign attribution is normalized and allowlisted. Standin stores a landing route and broad referrer category rather than a full arbitrary referrer URL. Growth events do not contain selfies, source videos, private media URLs, object-storage paths, face hashes, embeddings, raw Stripe payloads, or payment secrets.

Why Standin processes this data

Standin uses this information to create and privately deliver the requested result, enforce explicit consent and safety rules, prevent abuse and uncontrolled rendering cost, operate support, confirm website payment, fulfill an entitlement, measure aggregate funnel health, and meet applicable operational obligations.

Media retention and deletion

Unpaid preview media and paid-result media use separate, deployment-configured retention periods. The applicable media-expiry deadline is displayed with the private result. Expired or user-deleted media is not recoverable through an old link, while order, consent, and safe operational records can survive media cleanup for their separately configured periods.

The web result flow provides a user-initiated media-deletion action where the result is still available. Cleanup is designed to be idempotent. A deletion removes the associated input and output media but does not rewrite a confirmed payment or consent record.

Payments

Website card checkout is handled by Stripe only when a website-specific offer is configured. Stripe collects payment details under its own privacy terms. Standin stores provider identifiers, authoritative amount and currency, payment and entitlement state, timestamps, and safe failure categories needed for durable order handling; Standin does not receive or store the full card number.

The Telegram bot does not offer Stripe, card, crypto, NOWPayments, or website-credit purchase buttons for digital renders in this phase.

Service providers and disclosure

Standin shares data only with providers needed to host the service, screen inputs, render media, store and deliver private results, and process configured website payments. Standin does not sell personal data. Safety and legal obligations may require preserving or disclosing limited records where applicable.

Your choices

You can decline consent without uploading media or queueing a render. You can use the web media-deletion control while a result remains available and request further access or deletion help by messaging @standinmebot. Do not post private media publicly merely to request support.