Legal

Security

Last updated 30 August 2026

Latent holds your product photos, the pictures it makes from them, the accounts you publish to, and a link to the card you pay with. This page says what happens to each one. It describes what the product does today, and where Latent does not do something, it says so.

Your Photos And Pictures

Everything you upload and everything Latent makes for you lands in a private library. You can see it, and no one else can, until you publish.

  • Your reference photos and your generated pictures live in a private storage bucket. There are no public image URLs, so there is no address to guess, share or leak.
  • To show you a picture, your browser is handed a short-lived signed link. It is minted only inside a response that has already checked the picture is yours.
  • Every read of your work is checked against your account. There is no shared workspace and no cross-account visibility.
  • There is no public gallery and no shared feed. Nothing you make is browsable by anyone else, and nothing is published anywhere by default.
  • Nothing goes out to a platform until you send a post yourself.
  • We do not use your prompts or your images to train models.
  • When you delete a picture, the file is removed from storage. Image bytes left with no record pointing at them are removed by a sweep that runs on its own.

Your Account

The studio is behind a sign-in. It does not render without a session, and the server checks your account again on every request it answers.

  • Sign in with an email address and a password, or with a Google or GitHub account.
  • A new account has to verify its email address before it can be used. Passwords are at least eight characters, and we never hold the password itself.
  • Sessions expire on their own after a week. The cookie that carries one is scoped to the Latent API and is not sent anywhere else.
  • The sign-in and sign-up endpoints are rate limited: ten attempts from one address in a fifteen-minute window.
  • A second sign-in method joins an existing account only when the provider vouches for the same verified email address.
  • A signed-out browser is sent to the sign-in page rather than shown an empty studio. A failed check is treated as a connection problem, not as a sign-out.
  • There is no self-serve delete button today. Ask us to close your account and we delete it.

Payments

Latent never sees your card. Payment is taken by Polar, our merchant of record.

  • Your card details are typed into a form the payment provider draws inside its own frame. They go to the provider and never touch a Latent server.
  • What our server receives is a one-time confirmation token and the billing address you entered. Neither one is a card number.
  • Where your bank asks for a 3-D Secure check, that exchange runs between your browser, the payment provider and your bank.
  • What we store is the state of your plan, your credit balance and its ledger, and an id that identifies you to the payment provider.
  • The billing and checkout pages send no referrer, so the short-lived token that can ride in their address is never handed to anything else the page loads.
  • The payment secret is deliberately kept out of our logs. Holding it is authority to confirm the payment, so it is not something to write down.

Publishing Connections

Latent posts to Instagram, Facebook and LinkedIn, and only through accounts you connect yourself.

  • You authorise the connection on the platform’s own screen. That screen, and the permissions it lists, come from the platform.
  • Latent does not hold your platform password, and it does not store or cache your platform tokens. We keep one identifier linking your Latent account to its connections, and the rest is read live each time.
  • Publishing goes through a third-party publishing provider, which receives the images, captions and scheduling details of the publications you choose to publish. We do not name that provider publicly.
  • The connections page sends no referrer, because the hand-off back from a platform carries a single-use token in the address.
  • You can disconnect an account at any time in Latent, or revoke Latent’s access from the platform’s own settings. Disconnecting asks you to confirm, and says what it does to posts you have already scheduled.
  • A post can still be delayed, altered or rejected by the provider or by the platform. That part is not ours to promise.

Spending And Consent

Nothing spends credits without asking you first.

  • You are quoted the cost before a paid run and charged when it runs. If a run fails, the credits go back to your balance.
  • The assistant cannot spend on its own. A step that would spend credits is held until you answer it, and the question states how many images you are paying for.
  • Declining is a real answer, offered beside the one that spends. Nothing quietly retries it afterwards.
  • The server is the authority on every charge. The browser can ask for a run; it cannot spend.
  • Composing and saving a draft never spends anything, and publishing does not spend credits.

The Beta And Your Work

Latent is beta software, and the honest description of that is short.

  • Your prompts, your uploads and the pictures generated for you are yours. We claim no ownership of them.
  • A short list of pages is public: the ones you are reading now. Everything else, the whole studio included, sits behind the sign-in.
  • While Latent is in beta the site can also be closed behind an access key, and signing up can be gated the same way. Both are switches an operator holds.
  • The cookies those gates set are named so that a browser will only accept them over an encrypted connection, and only for Latent’s own address.
  • We make no certification or compliance claims, on this page or anywhere else on this site. What is written here is behaviour, and behaviour is what you can hold us to.
  • Latent comes with no uptime commitment and no service level agreement at this stage.
  • No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority, as the law requires.

Reporting A Problem

If you have found something wrong, tell us. A person reads these.

  • Security concerns and data-protection requests: privacy@latentpowered.com.
  • Account, billing and everything else: support@latentpowered.com.
  • Tell us immediately if you think someone else has access to your account.
  • We do not run a bug bounty programme. Email is the way to reach us, and we would far rather hear it than not.