Content updated ·
Who to contact
Pumio is operated by Kitta ai. Contact support@pumio.app about this notice, your information or a privacy request.
What the waitlist records
When you ask to join, we collect your email address, your consent, the page and recipe associated with your request, and submission, confirmation and unsubscribe times. We use this information to verify your address and notify you about the generation feature you requested.
We keep hashed identifiers for rate limiting and encrypted mail records for reliable delivery. Our hosting and anti-abuse providers may process technical information, including your IP address.
Your files and prompts
The public editorial website does not accept images or prompts for generation. Reading a guide does not send its examples to a model provider. The waitlist form collects your email and consent, not creative files.
Consent and your choices
Joining is optional. You can browse without leaving an email address. Confirming your email records your permission to receive the requested launch notification.
You can withdraw that permission through the unsubscribe link or by contacting support@pumio.app. We keep a suppression record so that another form submission does not silently re-subscribe you.
Service providers
Pumio uses Vercel for hosting, Supabase for the waitlist database, Resend for confirmation emails and Cloudflare for domain services and Turnstile form protection. PostHog provides the limited analytics described below. These providers process data to operate their services, and may process it outside your country.
We do not load third-party video embeds on the current editorial pages. The generation waitlist does not send your email or creative material to APIMart or fal.
Minimal analytics
On the public site, PostHog receives predefined page and waitlist events with registered page paths and recipe names. We do not send your email, prompts, images, URL queries or email-link tokens. A random identifier lasts only for the current page session; no analytics cookies or browser storage are used.
We disable person profiles and geographic enrichment, configure PostHog to discard client IP data, and honor Do Not Track and Global Privacy Control. PostHog still receives network requests to operate its service. Local development does not send analytics to PostHog.
Retention and requests
Unconfirmed requests become eligible for removal after 30 days without a new confirmation request. Encrypted confirmation mail becomes eligible after 24 hours, expired or consumed confirmation tokens after seven days, rate-limit records after 48 hours, and delivery records after 90 days. A daily cleanup processes eligible records in batches and skips active sends, so removal may occur later than these thresholds. We retain confirmed subscriptions while needed to administer the list and keep suppression records to honor opt-outs.
Contact us to request access, correction or deletion, or to object to processing. We may need to verify that the request concerns your own information. You may also raise a concern with the data protection authority where you live.