← Back to Lemonade Studio
Privacy Policy
Last updated: September 18, 2026
1. Information We Collect
When you use Lemonade Studio, we collect:
- Account information: Email address, password (stored as a salted hash, never plaintext)
- Usage data: Projects you create, commands sent to the AI, credits used
- Technical data: IP address (for rate limiting and abuse prevention), browser type, connection timestamps
- Payment data: Payment is processed through third-party providers. We do not store credit card numbers.
2. How We Use Your Information
- To provide and maintain the Lemonade Studio service
- To authenticate your account and prevent unauthorized access
- To process AI code generation requests
- To enforce rate limits and prevent abuse
- To communicate with you about your account (verification emails, password resets)
3. Data Storage
Your data is stored on Cloudflare's infrastructure, which is distributed globally for performance and reliability. Data is encrypted in transit (HTTPS) and at rest.
4. Data Sharing
We do not sell or share your personal data with third parties, except:
- AI providers: Your code generation prompts are sent to AI model providers (Google Gemini, Grok, or others) to process your requests. These providers have their own privacy policies.
- Email service: We use Resend to send verification and password reset emails.
- Authentication: If you sign in with Google, Google provides your email and profile ID for authentication purposes only.
5. Cookies
We use essential cookies for:
- Session management: To keep you signed in (
ls_session)
- CSRF protection: To prevent cross-site request forgery (
ls_csrf)
We do not use tracking cookies or third-party analytics cookies.
6. Data Retention
- Account data: Retained until you delete your account
- Session data: Automatically expires after 90 days
- AI chat history: Stored locally in your browser; not on our servers
- Rate limit logs: Automatically deleted after the rate limit window expires
7. Your Rights
You can:
- View your account data by signing in
- Delete your account and all associated data from the settings page
- Request a copy of your data by contacting us
8. Security
We implement industry-standard security measures including:
- HTTPS encryption on all connections
- CSRF token protection on state-changing requests
- Rate limiting on authentication and API endpoints
- Content Security Policy headers
- Password hashing with PBKDF2-SHA256 (100,000 iterations)
- Session tokens stored as SHA-256 hashes
9. Children's Privacy
Lemonade Studio is not directed at children under 13. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
11. Contact
For privacy-related inquiries, contact us at lemonadestudiopages@gmail.com.