The New Black AI

Last updated · September 2026

Security

Everything we disclose about how The New Black AI protects your designs, your photos and your account. If a question is not answered here, it is not something we share; write to admin@thenewblack.ai and we will tell you so directly.

1. Your content stays yours

Everything you upload and everything you generate is private to your account. It is never shown to other users, never published anywhere without an action of yours, and never used to train or fine-tune any model, on any plan.

You keep full ownership of what you create. Our terms of service say so, and nothing in the platform claims otherwise.

Our team can open a creation of yours only to answer a support request you made, and only for that. There is no browsing of customer galleries.

2. Where the platform runs

The application, the API and the background jobs run on Vercel. The database and the file storage (your uploads and your generated images and videos) run on Supabase, on Amazon Web Services infrastructure in the United States. Both providers are SOC 2 certified and publish their own security documentation.

Data is encrypted in transit (TLS on every connection, including between our services) and at rest (AES-256 on the database and on the storage volumes).

There is one production environment. Staging and development environments do not hold customer data.

3. The path of an image through a generation

When you upload a picture, it is written to your account's storage. When you start a workflow, our servers send the picture and your instructions to the AI system that runs that workflow. It produces the result; our servers copy it into your gallery; your browser reads it from there. The input is used for that generation and nothing else.

Generation runs on dedicated inference infrastructure, separate from the application servers and reached through private API calls. It receives what a generation needs, for the time a generation takes, and is bound by the same rule as everything else on this page: nothing it receives is kept, and nothing it receives is used for training.

We do not publish which models and systems run our workflows, nor how they are built, trained or operated. That changes as the field moves, and it is part of what we build. What does not change is the rule above: your content is never training material, here or anywhere along the way.

Visual DNA is the one place where your images shape a model: it learns your brand's style from the pictures you give it, for your account only. It is never shared with another account and it is deleted with your account.

4. Access to your account

You sign in with an email address and a password, or with your Google account. Passwords are stored as one-way hashes and are never visible, to you or to us; the only way to change one is the reset link on the sign-in page.

A team member gets their own login. Nobody shares a password; the account leader invites members by email and removes them at any time. Billing, API keys and connected platforms belong to the leader alone.

Every table in our database enforces account isolation at the database level (row-level security): a request can only ever read and write the rows of the account it is signed in as, whatever the application code does.

API keys are shown once, at creation, and stored as hashes: a leaked database would not reveal them. Each key carries the scopes you give it and can be revoked from your account at any time. Connected platforms (Shopify, Instagram, TikTok, Pinterest, YouTube, X) are linked through their own OAuth authorisations, which you can revoke on our side or on theirs.

5. Payments

Payments are processed by Stripe. Card numbers are entered on Stripe's own pages and never reach our servers; we store a customer reference and the invoices Stripe issues. Stripe is PCI DSS Level 1 certified.

6. Deletion and retention

When you delete a creation, it leaves your gallery at once. For 30 days it can still be restored on request; after that, an automatic sweep removes the file, its thumbnail and every file the creation referenced, then the record itself.

When you delete your account, your creations, your uploads, your Visual DNA profiles and your profile data are removed. Invoices are kept for the period accounting law requires, nothing else.

The inference infrastructure does not keep your inputs beyond the generation; the copy of a result that we keep is the one in your gallery.

7. Monitoring and continuity

The platform is monitored continuously: generation failures, unusual traffic, payment anomalies and broken integrations raise alerts that our team reads every day.

The API is rate-limited per account, and public forms are protected against automated abuse.

The database is backed up daily by our provider, and we rehearse restoring it ourselves.

8. GDPR and data transfers

The New Black Kft., Budapest, Hungary, is the data controller. Our privacy policy describes what personal data we collect and why; this page describes how it is protected.

The platform is hosted in the United States. Transfers of personal data outside the European Union are covered by the data processing agreements we hold with each of our providers.

You can access, correct or delete the personal data we hold about you by writing to admin@thenewblack.ai.

9. Questions and vulnerability reports

This page is our answer to security questions. We do not complete third-party security questionnaires: everything we disclose is here, and we keep it current.

If you believe you have found a vulnerability, write to admin@thenewblack.ai with the steps to reproduce it. We read every report and answer the ones that describe something real.