Privacy notice

How Kitta ai handles your Pumio waitlist information and website visits.

Content updated ·

Who to contact

Pumio is operated by Kitta ai. Contact support@pumio.app about this notice, your information or a privacy request.

What the waitlist records

When you ask to join, we collect your email address, your consent, the page and recipe associated with your request, and submission, confirmation and unsubscribe times. We use this information to verify your address and notify you about the generation feature you requested.

We keep hashed identifiers for rate limiting and encrypted mail records for reliable delivery. Our hosting and anti-abuse providers may process technical information, including your IP address.

Your files and prompts

The public editorial website does not accept images or prompts for generation. Reading a guide does not send its examples to a model provider. The waitlist form collects your email and consent, not creative files.

Consent and your choices

Joining is optional. You can browse without leaving an email address. Confirming your email records your permission to receive the requested launch notification.

You can withdraw that permission through the unsubscribe link or by contacting support@pumio.app. We keep a suppression record so that another form submission does not silently re-subscribe you.

Service providers

Pumio uses Vercel for hosting, Supabase for the waitlist database, Resend for confirmation emails and Cloudflare for domain services and Turnstile form protection. PostHog provides the limited analytics described below. These providers process data to operate their services, and may process it outside your country.

We do not load third-party video embeds on the current editorial pages. The generation waitlist does not send your email or creative material to APIMart or fal.

Minimal analytics

On the public site, PostHog receives predefined page and waitlist events with registered page paths and recipe names. We do not send your email, prompts, images, URL queries or email-link tokens. A random identifier lasts only for the current page session; no analytics cookies or browser storage are used.

We disable person profiles and geographic enrichment, configure PostHog to discard client IP data, and honor Do Not Track and Global Privacy Control. PostHog still receives network requests to operate its service. Local development does not send analytics to PostHog.

Retention and requests

Unconfirmed requests become eligible for removal after 30 days without a new confirmation request. Encrypted confirmation mail becomes eligible after 24 hours, expired or consumed confirmation tokens after seven days, rate-limit records after 48 hours, and delivery records after 90 days. A daily cleanup processes eligible records in batches and skips active sends, so removal may occur later than these thresholds. We retain confirmed subscriptions while needed to administer the list and keep suppression records to honor opt-outs.

Contact us to request access, correction or deletion, or to object to processing. We may need to verify that the request concerns your own information. You may also raise a concern with the data protection authority where you live.

Your next scene is on its way.

Online generation is coming soon. Join the waitlist and we’ll email you when it opens.

Privacy notice