Privacy policy

How Rastock AI collects, uses and protects personal data across the website, the dashboard and the browser extension.

The Rastock AI browser extension signs you in to your existing Rastock AI account and reads the thumbnail of an image you select on a supported contributor site so that titles, descriptions and keywords can be generated for it. It does not read pages outside the contributor sites listed in its permissions, and it never asks you to paste an API key.

Images submitted for metadata generation are processed by Microsoft Azure OpenAI as a sub-processor and are not used to train models. This page also covers retention periods, your rights over your data, and how to export or delete an account.

Rastock AI (“Rastock,” “we,” “us,” or “our”) is committed to protecting your privacy and handling personal data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access our website, dashboard, browser extensions, and related services.

1. Information We Collect

We collect the following categories of information:

Name, email address, and authentication credentials when you register or log in.

Country selection, ambassador or affiliate participation, subscription settings, and interface preferences.

Images uploaded to generate AI-powered metadata (titles, descriptions, keywords). Uploaded images are processed only for the declared functionality.

Usage & Interaction Analytics

Anonymous or pseudonymous data such as time on site, navigation flow, button clicks, scroll behavior, and feature usage.

Device & Technical Information

IP address, browser type, operating system, device identifiers, language settings, and approximate location derived from IP.

Cookies & Tracking Technologies

Cookies, pixels, and similar technologies used for authentication, preferences, analytics, and performance optimization.

2. How We Use Your Information

We use collected information to:

Generate AI-powered metadata for stock photography and creative assets

Provide personalized features, recommendations, and onboarding flows

Authenticate accounts and manage token- or subscription-based access

Improve platform performance, usability, and reliability

Send transactional, operational, and service-related communications

Detect, prevent, and investigate fraud, abuse, or security incidents

Comply with legal, regulatory, and contractual obligations

We do not use personal data for automated decision-making that produces legal or similarly significant effects.

3. Browser Extension Disclosures (Chrome, Firefox, Apple Safari)

Rastock AI offers browser extensions for Google Chrome, Mozilla Firefox, and Apple Safari.

These extensions operate only on supported stock contributor platforms such as Adobe Stock, Freepik, Envato, and similar marketplaces.

The extensions are designed for a single, limited purpose:

Detect editable metadata fields on supported platforms

Insert AI-generated titles, descriptions, and keywords into those fields

Assist contributors in speeding up content preparation

Access login credentials or payment information

Read personal messages, emails, or unrelated page content

Track browsing activity outside supported domains

All extensions comply with Chrome Web Store policies, Mozilla Add-ons (AMO) policies, and Apple Safari Extension guidelines.

4. Use of Remote Code & APIs

Our extensions and dashboard securely communicate with our backend services hosted at

Remote code and API requests are used to:

Process metadata generation requests in real time

Maintain compatibility with supported platforms

Improve AI models and system reliability without forcing frequent client updates

All communications are encrypted via HTTPS. Remote scripts are sandboxed and never inject content into unrelated websites.

5. Cookies & Tracking Technologies

We use cookies and similar technologies for session management, feature performance monitoring, and UX analytics. Examples include session cookies, click analytics, and page engagement metrics.

Users are presented with a cookie consent banner where required by law and may manage preferences at any time. We do not collect sensitive personal data without explicit consent.

6. Payments & Token Usage

Payments are processed through trusted third-party providers such as Stripe.

We do not store full credit card numbers or sensitive payment credentials. We retain limited transactional metadata to validate subscriptions, associate purchases with user accounts, and prevent fraud.

7. Information Sharing & Disclosure

We do not sell or rent personal data. We may share information only:

With service providers under strict confidentiality agreements (hosting, analytics, payments)

When required by law, court order, or regulatory request

In connection with a merger, acquisition, or business restructuring

With explicit user consent for integrations or ambassador-related activities

We implement industry-standard safeguards, including encrypted data transmission (HTTPS/TLS), secure authentication, role-based permissions, and infrastructure monitoring.

While we take reasonable measures, no system can guarantee absolute security.

We retain personal data only for as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

You may request account deletion by contacting

10. User Rights (U.S., California, and International)

Depending on your location, you may have the right to access your personal information, request correction or deletion, opt out of certain data uses, receive a copy of your data, or close your account.

California residents have additional rights under CCPA / CPRA, including the right to know, delete, and limit the use of personal information.

Requests can be submitted to