Legal

Privacy Policy

Last updated 26 August 2026

Latent is an AI image studio for social media, built by Silverthread Labs. This policy explains what we collect, why, who we share it with, and what you can ask us to do about it.

Introduction

Latent is pre-launch. Today there are two ways to give us data: joining the waitlist at latentpowered.com, and using the studio if you have been invited into it.

  • Latent is operated by Silverthread Labs. This policy covers the Latent website and the Latent studio application.
  • It does not cover the social platforms you connect Latent to. Once a post is published, that platform’s own privacy policy governs it.
  • By joining the waitlist or using the studio, you agree to the practices described here.
  • Questions, or a request about your own data: privacy@latentpowered.com.

The Waitlist

If the only thing you have done is join the waitlist, this is the entire list of what we hold about you.

  • Your email address, the date and time you submitted it, and which page you submitted it from.
  • Nothing else. We do not store your IP address, your browser, or any identifier from the page you submitted on.
  • We use it for one thing: to tell you when Latent opens, and to invite you in.
  • We do not sell it, rent it, or share it with anyone outside the processors named below.
  • The form answers the same way whether or not your address is already on the list, so nobody can use it to test whether a given person signed up.
  • To be removed, email privacy@latentpowered.com and we will delete the entry.

Account And Sign-In Data

When you have a Latent account, we hold the identity data needed to sign you in and keep the account secure.

  • Your name, email address, whether that address is verified, and a profile image URL if your sign-in provider supplies one.
  • How you sign in: an email address and password, or a GitHub or Google account. Passwords are stored only as a hash. We never hold the plaintext.
  • For social sign-in, the access and refresh tokens that provider issued us, plus the scope granted. We ask for identity scopes only.
  • Sessions: a session token, its expiry, and the IP address and browser user agent the session was created from. These exist to end a session and to spot a stolen one.
  • Short-lived tokens for email verification and password resets, which expire on their own.
  • Your account role, and whether the account is suspended together with the reason. See the Terms for what suspension means.

What You Make In The Studio

The studio stores your work so it is there on your next visit and on your other devices. It is private to your account.

  • The prompts you write, including the ones the assistant writes on your behalf.
  • Generation settings: the aspect and style you chose, the model, quality and size the run actually used, and the mode. A mode is a fresh generation, an inpaint, an outpaint or a style adaptation.
  • The images Latent generates for you, and the images you upload as references or assets, together with their original filename, format and dimensions.
  • Publications and posts: captions, first comments, the platforms and accounts you targeted, and scheduling times with the timezone you set them in.
  • Assistant conversations. The transcript is durable and stored with the draft it belongs to, so reopening that draft restores the conversation.
  • Timing and token-usage figures for each run, which is how we account for what a generation cost.
  • Your images live in a private storage bucket. There are no public image URLs. The browser is handed a link that expires within an hour, and only inside a response we already checked you were entitled to.

Billing Data

Payments are handled by Polar, our merchant of record. Latent never sees your card.

  • Polar collects and processes your payment details, billing address and any tax information. We do not receive, store or have access to your card number.
  • What we store is the link to Polar and the state of your plan: a Polar customer id, a subscription id, your plan, its status, and when the current period ends.
  • Your credit balance and a ledger of every movement in it: what was spent, granted, refunded or purchased, when, and against which generation.
  • Records of generated work you delete are kept in a reduced form so that lifetime spend stays accurate. They no longer show you the work; they still count the money.
  • Failed billing webhooks are parked with their payload so a payment cannot be silently lost. These are retried automatically, and reviewed by us if the retries fail.

Connected Social Accounts

To publish for you, Latent connects to your social accounts through a third-party publishing provider. We hold almost nothing about those accounts ourselves.

  • You authorise the connection on the platform’s own screen, whether that is Meta, LinkedIn or another. That screen, and the permissions it lists, come from the platform.
  • We store one identifier linking your Latent account to your account set at our publishing provider. We do not copy or cache your social account details, tokens, follower counts or health status; they are read live each time.
  • When you publish, the images and captions in that publication are sent to the provider, which posts them to the platforms and accounts you chose.
  • Post performance figures are fetched from the platform on demand when you open a publication. We do not poll them in the background.
  • Disconnecting an account in Latent, or revoking Latent’s access from the platform’s own settings, stops this.

Content Screening

Prompts are screened before anything is generated. This is a safety measure, and it means your prompt text leaves us.

  • Prompt and caption text is sent to OpenAI’s moderation service before a generation runs. If it is flagged, the generation is refused and you are told.
  • The image model applies its own filters as a backstop. A refusal from either point is not a judgement about you and is not recorded against your account.
  • Screening is not a guarantee. See the Terms for what you remain responsible for.

Who We Share Data With

We use the processors below to run Latent. We do not sell your data, share it with data brokers, or use it for advertising.

  • Image and text generation, and content screening: OpenAI. It receives your prompts, your reference and uploaded images, and the caption text it is asked to write or screen.
  • Payments: Polar, as merchant of record. It receives your payment and billing details directly.
  • Image storage: Hetzner Object Storage, in a private bucket. It holds your generated and uploaded image bytes.
  • Transactional email: Resend. It receives your email address in order to deliver verification and password-reset messages.
  • Social publishing: a third-party publishing provider, which receives the images, captions and scheduling details of publications you choose to publish, and the account authorisations you grant. We do not name the provider publicly; it is a processor acting on our instructions and no more.
  • Our own servers and database, which we operate. Your account, work and ledger live there.
  • We have no advertising partners and no analytics vendor. There is no third-party tracking on this website.
  • We may also disclose data where the law requires it, or where it is necessary to investigate abuse or protect someone’s safety.

How We Use Your Data

Every use below is either running the product you asked for, keeping it safe, or meeting an obligation.

  • Generating, editing and storing images, captions and publications on your instruction.
  • Publishing to the accounts you connected, at the times you set.
  • Metering and billing: quoting a run, charging credits, refunding a failed one, and keeping the ledger accurate.
  • Keeping accounts secure: session management, rate limiting, and detecting abuse of the public waitlist form.
  • Sending transactional email. We do not send marketing email to studio members; the waitlist address is used for the launch invitation described above.
  • Improving Latent using aggregate figures: how long generations take, how often they fail, what a run costs us. This does not involve reading your images or prompts.
  • We do not use your prompts or images to train our own models, and we do not grant our processors the right to train on them.

How Long We Keep It

We keep each kind of data for as long as it is doing a job, and no longer.

  • Waitlist entries: until launch invitations have gone out, or until you ask us to delete yours.
  • Account data: while your account is open. When you close it, we delete it.
  • Your images, prompts and publications: until you delete them, or until you close the account.
  • Deleted work: the images are removed from storage; a reduced record is kept where it is needed to keep billing history accurate.
  • Image bytes with no surviving record are quarantined and removed by a routine sweep.
  • Billing records: retained as long as tax and accounting law requires, which is longer than your account lives.
  • Sessions and verification tokens: they expire on their own.
  • Administrative audit records of significant account actions, such as a suspension, are retained for security.

Security

The measures below are the ones actually in place, not a list of intentions.

  • All traffic between your browser, our servers and our processors is encrypted in transit with TLS.
  • Generated and uploaded images are held in a private bucket with no public URLs. Access is granted as a link that expires within an hour, minted only inside a response already scoped to your own account.
  • Every read of your work is checked against your account. There is no shared workspace and no cross-account visibility.
  • Passwords are stored hashed. Sessions expire, and can be ended from your account.
  • Rate limiting on public and authenticated endpoints, with a dedicated tighter limit on the public waitlist form.
  • While Latent is pre-launch, everything except this website sits behind an access wall.
  • No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.

Your Rights

If you are in the EU, the EEA or the UK, the GDPR gives you the rights below. We extend them to everyone who uses Latent. To exercise any of them, write to privacy@latentpowered.com.

  • Access: ask for a copy of the personal data we hold about you.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: ask us to delete your personal data. Some billing records must be retained by law, and we will say so if that applies.
  • Restriction: ask us to limit how we use your data while a question about it is resolved.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing we carry out on the basis of legitimate interests.
  • Withdraw consent: where we rely on consent, withdraw it at any time. This does not affect processing already carried out.
  • We respond to requests within 30 days. You may also complain to your local data protection authority.

Cookies

Latent uses cookies only to keep you signed in and, before launch, to remember that you have access. There are no advertising or analytics cookies.

  • A session cookie, set when you sign in, which identifies your session to the Latent API. It is scoped to the API host and is not sent anywhere else.
  • A staging-access cookie while Latent is pre-launch, which records that you passed the access wall.
  • This website, the public pages you are reading now, sets no cookies at all and does not need to.
  • Blocking the session cookie will prevent you from signing in. Nothing else here depends on cookies.

Where Your Data Is Processed

Not all of your data is processed in one place. This is where it goes.

  • Image storage is in the European Union.
  • Generation, screening, payments, email delivery and social publishing are provided by companies that may process data in the United States and elsewhere.
  • Where a transfer leaves the EEA or the UK, it is made under the transfer mechanisms those processors offer, such as Standard Contractual Clauses.

Children

Latent is a tool for people running marketing, and it is not built or intended for children.

  • You must be at least 16 to join the waitlist or hold a Latent account.
  • We do not knowingly collect data from anyone under that age. If you believe we have, write to us and we will delete it.

Changes To This Policy

We will update this policy when what we do changes. We will not update it quietly.

  • The date under the title is the date of the most recent revision.
  • A material change is a new category of data, a new processor, or a new purpose. For one of those we will email account holders, or place a notice on the site, before it takes effect.
  • Continuing to use Latent after a change takes effect means you accept the revised policy.

Contact Us

A person reads these. Write to us about anything in this document.

  • Privacy and data-rights requests: privacy@latentpowered.com.
  • Everything else, including your account and billing: support@latentpowered.com.