Skip to document

Privacy Policy

Menace • iOS, Android, and Web • Effective: August 11, 2026 • Version: 2026-08-11-v2

This Privacy Policy ("Policy") explains how OneClick Commerce LLC, a California limited liability company doing business as Menace ("Menace," "we," "us," or "our"), collects, uses, discloses, and retains personal information. OneClick Commerce LLC is the controller or business responsible for the practices described here, except where a third party acts independently under its own policy.

This Policy is a notice about our information practices. It does not create contractual rights beyond those provided by applicable law. Our Terms of Service govern use of the Service.

1. Scope

This Policy applies to the Menace iOS and Android applications, menaceai.app, and related generation, account, purchase, support, and online services (collectively, the "Service"). It does not apply to third-party services you independently visit or use.

In this Policy, photos, videos, prompts, and selections submitted to the Service are "Inputs"; generated or modified results are "Outputs"; and Inputs and Outputs together are "User Content."

A "Menace Device ID" is a pseudonymous identifier used to associate device-based app access with the relevant account state. A "Support ID" is a limited Menace identifier shown to you or included in an editable support draft so we can locate the relevant account or app installation when you ask for help. Neither is your device's hardware serial number.

The data practices for a particular platform or feature may differ. For example, mobile versions may use a device-based identifier, the website may use a third-party sign-in provider, and web Outputs may be stored in Menace cloud storage while mobile Outputs are generally downloaded to the device.

The Android app also sends a one-way hashed value derived from the app package name and an Android system identifier. It is used only to help restore access to an existing Menace account on the same device. Menace receives the hashed value and not the underlying system identifier, and the value is not an advertising identifier and is not used for advertising.

2. Information We Collect

Categories of personal information Menace collects
CategoryExamplesHow we receive it
Account and identifiersEmail address, third-party sign-in identifier, Menace Device ID or Support ID, account identifier, sign-in and session records, and account status. Menace identifiers help provide account or device-based access, protect account integrity, and respond to support requests.From you, your device, or your chosen sign-in provider.
User Content and AI requestsPhotos, videos, prompts, selections, template identifiers, generated Outputs, media details such as file type, size, and duration, and reports about Outputs. Content may include a person's face, voice, or likeness.When you choose, capture, upload, generate, recover, save, share, or report content.
Purchases and entitlementsProduct and plan, transaction identifier, purchase date, price and currency, subscription or refund status, store-verification records, credits, and purchase-access status. We do not receive full payment-card numbers.From you, app stores, payment processors, and subscription service providers.
Device, network, and diagnosticsIP address, device and browser type, operating system, app version, language, time zone, approximate IP-based location, crash information, performance data, security signals, and request timestamps.Automatically from your device, browser, the software used by the Service, and providers that support it.
Use and interaction dataScreens or pages viewed, buttons or templates used, onboarding and paywall events, generation state, credit activity, feature usage, session timing, share/save completion, and attribution or campaign information where enabled.Automatically from the Service and analytics or measurement providers.
Communications and requestsSupport messages and editable support-request details, privacy or deletion requests, rights complaints, safety reports, attachments you choose to send, and our responses.Directly from you or someone authorized to act for you.
Website storageAuthentication cookies, fraud/security cookies, local storage for preferences, onboarding, active generations, and history, and checkout/session state.Through your browser when you use the website.

Support Diagnostics

If you choose Contact Support, a Menace client may prepare a visible, editable draft containing a Menace identifier, platform, basic app and device or browser details, locale, subscription and credit status, and support context. The draft is not sent automatically. You decide whether to edit, copy, paste, or send it.

Acceptance Records

When Menace asks you to accept an identified version of its Terms or this Policy, we may keep a record of that acceptance. The record may include the policy version, date and time, platform, app version, and relevant account or device identifier.

Information About Other People

User Content may contain personal information about someone who does not use Menace, including a face, voice, or likeness. We receive that information from the person who submits it and process it as described in this Policy. If you believe that information about you or your child was submitted without authority, use our Report Content page or email hey@menaceaiapp.com. We may verify identity, authority, and the content at issue before acting on a request.

The age rules in Section 10 govern who may use Menace. Content submitted by an eligible user may still contain information about a child. We treat that information as User Content about another person and apply the permissions, safety rules, and reporting processes described here and in our Terms.

You are not required to provide User Content, but generation cannot work without the Input you choose to submit. Please do not submit more personal information than needed.

3. How We Use Information

We use personal information to:

  • Provide, authenticate, personalize, and maintain the Service.
  • Upload Inputs, create Outputs, deliver or recover results, and keep generation history where the feature supports it.
  • Process purchases, maintain credits and access, prevent duplicate charges or credits, restore transactions, and handle refunds or chargebacks.
  • Operate onboarding, paywalls, settings, support, and account or device-based access.
  • Detect, block, investigate, and document fraud, security incidents, prohibited content, payment abuse, and violations of our Terms.
  • Diagnose errors, measure reliability and feature performance, understand aggregated product use, and improve safety and usability.
  • Measure campaign performance where an attribution feature is enabled and permitted.
  • Respond to support, legal, privacy, deletion, and rights requests.
  • Comply with law, valid legal process, app-store requirements, and protect the rights, safety, and property of users, Menace, and others.
  • Establish, exercise, or defend legal claims and enforce our agreements.

4. AI Processing, Faces, and Training

Third-Party AI Processing

When you submit a generation request, you instruct Menace to transmit the Inputs, prompts, settings, and generation instructions needed to perform that request to third-party cloud and AI-processing providers. A provider may route the request to an underlying image or video model. These providers may process the information to create and deliver the requested Output, secure and troubleshoot the Service, prevent fraud or abuse, provide support, and comply with law.

Provider retention, logging, safety review, and model-training practices vary by provider, model, contract, settings, and legal obligation and may change. We do not represent that every provider offers zero retention or a universal no-training commitment. Providers process information under applicable contracts, our instructions when they act on our behalf, and their independent legal obligations.

Faces and Biometric Information

Menace processes images and videos as visual content and AI models may locate or transform facial features to create an Output. A face, likeness, or face-related measurement may be personal, sensitive, or biometric information under some laws even when it is not used to identify someone; this Policy does not characterize every face or every processing operation the same way. OneClick Commerce LLC does not currently use the ordinary generation flow to authenticate a person or maintain a persistent face-recognition identification database. If a feature requires separate biometric notice or consent, we will provide it before that feature's covered processing.

Menace Use and Provider Practices

OneClick Commerce LLC does not itself use private photos, videos, or prompts to train a generalized AI model as part of ordinary Service use. We use the substance of private User Content to fulfill the generation you request, investigate suspected abuse or security incidents, respond to support, or comply with law. We do not use that private content for Menace advertising or unrelated product analytics. AI processors operate under their own terms, policies, and available service settings, so their training and retention practices may differ.

5. How We Disclose Information

We disclose personal information only for the purposes described below, subject to contracts, instructions, platform controls, or legal duties where applicable. The vendors we use may change as the Service evolves.

Categories of recipients and reasons for disclosure
Recipient categoryPurpose and information
Hosting, database, authentication, and cloud-storage providersAccount access, secure cloud operations, generation records, credits, and cloud storage for supported features. Data can include identifiers, account status, transaction details, prompts, result links, and stored media.
AI processing and content-safety providersCloud media handling and AI generation through the providers selected for a requested feature, including any underlying image or video model. Data may include Inputs, prompts and instructions, feature settings, request identifiers, Outputs, and logs needed to perform, secure, and troubleshoot the request.
App stores, sign-in providers, and device-service providersApp distribution, sign-in where chosen, device services, subscription and purchase processing, transaction verification, refunds, integrity checks, and store compliance.
Payment and subscription providersCheckout, subscription billing, paywall presentation, transaction verification, fraud prevention, refunds, entitlement status, app version, and purchase-flow interactions. Payment details may be collected directly by the provider; Menace receives limited billing and transaction information.
Analytics providersProduct analytics in supported app versions, including a Menace identifier, app or device information, and records of onboarding steps, generation activity, shares, and saves. Menace is designed not to send prompts, source media, Output links, or generation-request identifiers with these records.
Attribution providersSome current or legacy mobile app versions may send device and app identifiers, campaign and install data, subscription or purchase status, and limited onboarding, generation, sharing, checkout, trial, subscription, and purchase events to attribution providers for campaign measurement, subject to applicable consent and opt-out requirements. Menace is designed not to send prompts, source media, Outputs, or contact information to those providers. Newer mobile versions may remove particular attribution software, but users may remain on older versions and providers may retain information under their own policies. Some Android versions may also receive Google Play install referrer information through subscription-screen management software, and that provider's own terms and policy govern what it keeps and how it uses it. The website does not use this attribution technology.
Website hosting and security providersWebsite hosting, delivery, request logs, IP address, browser/device information, cookies, and security/performance data.
Communications and support providersSupport email, privacy and legal requests, safety reports, attachments you send, and related message metadata.
Professional advisers and authoritiesLawyers, accountants, auditors, insurers, courts, regulators, app stores, law enforcement, or child-safety organizations where reasonably necessary to comply with law, protect people or the Service, investigate abuse, or establish and defend claims.
Business transaction recipientsActual or prospective buyers, investors, lenders, advisers, or successors in a financing, reorganization, merger, acquisition, or asset transfer, subject to appropriate confidentiality and applicable law.

We may also disclose information at your direction, such as when you choose to share an Output using your device's share sheet. Sharing outside Menace is controlled by you and the receiving service's policy.

6. Sale, Sharing, Tracking, and Advertising

Menace does not exchange personal information for money and does not currently display third-party behavioral advertisements inside the Service. Some current or legacy mobile app versions may use an attribution provider for campaign measurement as described above. Newer mobile versions may remove particular attribution software, but users may remain on older versions and providers may retain information under their own policies. Depending on the jurisdiction and how its definitions apply, disclosing mobile device/app identifiers and limited onboarding, generation, sharing, checkout, trial, subscription, or purchase event data for that measurement may be considered "sale," "sharing," or targeted advertising even though no money is exchanged for the information. The website does not use this attribution technology.

You may opt out of covered sale, sharing, or targeted advertising through Privacy Choices, applicable device or platform tracking controls, or by emailing hey@menaceaiapp.com. We do not knowingly sell or share the personal information of users under 16. If we learn that covered processing involves a user under 16, we will take the steps required by law.

Platform privacy or tracking controls may limit future collection but do not necessarily delete information already processed.

7. Cookies, Local Storage, and Browser Privacy Signals

The website uses cookies or similar browser storage that are necessary for sign-in, security, checkout, account access, and preferences. It may also use local storage for onboarding, active generation, credit, subscription, and history state. Blocking necessary storage can prevent parts of the website from working.

Where required, we will request consent before using non-essential analytics or advertising technologies. Menace does not currently display third-party behavioral ads or use website activity for cross-context behavioral advertising, so there is no such website processing for a browser opt-out signal to disable. Where applicable law requires us to treat a browser opt-out preference signal as a request, we will do so for covered website processing. You may also submit a request through the Privacy Choices page. Because there is no universal standard for other Do Not Track signals, we do not currently respond to them unless legally required.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes below, then delete, de-identify, or isolate it unless law permits or requires longer retention. Exact periods can vary by feature, account status, legal hold, safety issue, and processor.

Data-retention categories and criteria
DataTypical retention or criteria
Mobile source media and OutputsSource media selected in the app may be stored locally long enough to submit or restore a generation. Completed Outputs and history are generally kept on the device until you delete the item or account, uninstall, or the device removes local data.
AI-provider media and logsRetention varies by provider, model, contract, settings, and purpose. It may include transient media, task logs, safety records, or information preserved for support, security, disputes, or law.
Web Outputs and supported cloud mediaStored until you delete the item or account, the feature's stated retention period ends, or we remove it under an inactivity, safety, storage, or legal rule. Download content you need to keep.
Generation and abuse recordsRequest identifiers, feature settings, timestamps, status, credit changes, error details, and limited safety signals are kept while needed for history, recovery, billing integrity, fraud or abuse prevention, dispute resolution, security, and legal compliance.
Account and device identifiersWhile the account or device identity is active and afterward as needed to complete deletion, prevent fraud or evasion, resolve disputes, and meet legal duties.
Purchases, subscriptions, credits, and refundsFor the period required for entitlement, accounting, tax, chargeback, anti-fraud, app-store, audit, and legal purposes. These records may outlast account deletion.
Analytics and diagnosticsFor the period configured with the provider and needed for product measurement, reliability, security, or trend analysis, after which we delete or aggregate it where practicable.
Support, privacy, safety, and legal recordsUntil the request or issue is resolved and for a reasonable period afterward to document the response, prevent repeated abuse, comply with law, and establish or defend claims.

Deletion from active systems may not immediately remove encrypted backups, provider processing queues, or information lawfully preserved for security or legal reasons. We restrict use of retained information to the reason it remains.

9. Account and Content Deletion

Platform-specific deletion instructions are at menaceai.app/delete-account. Use the authenticated Delete Account control when it is available. If the control is unavailable, fails, or does not confirm submission, email us using the instructions on that page. Clearing browser or app data, signing out, or uninstalling alone does not delete server-side data. After a verified request is accepted, deletion or de-identification from active systems, backups, and service providers may continue after local sign-out. Deleting an account does not cancel an app-store or web subscription.

A deletion request ordinarily covers eligible account/profile data and generation content in active systems. We may retain purchase, credit, transaction, fraud, security, abuse, deletion-request, and legal records as described above. We may ask for the Menace Device ID, account email, or other limited information to verify that the requester controls the relevant data.

We respond to verified requests and complete eligible first-party deletion steps within the period required by applicable law. Timing varies with the platform, verification, data location, service-provider or backup cycle, and any permitted legal, security, fraud, accounting, safety, or dispute exception. An in-product confirmation may confirm submission or local sign-out without guaranteeing that every processor or backup cycle has completed. Where we have a verified email or support channel, we provide status information as required or reasonably available.

10. Children and Teen Users

Menace is not directed to children under 13. A person under 13 may not create an account, use the Service, or submit content. If we learn that a person under 13 has used the Service, we will take appropriate steps to suspend the account and delete personal information as required by law. A parent or guardian may contact hey@menaceaiapp.com.

Users aged 13 through the age of legal majority may use Menace only with parent or guardian permission and supervision where required. Some countries require a higher minimum age or parent or guardian authorization for online data processing. The higher local rule applies. Ordinary account creation does not request or store your date of birth. Eligibility relies on the age and guardian representations in our Terms, subject to any additional age assurance or parent or guardian consent required by law.

We do not knowingly use a minor's personal information for targeted advertising, sell it, or share it for cross-context behavioral advertising without the authorization required by law.

11. Your Privacy Rights

Depending on your location, you may have rights to access, know, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denied request.

Submit a request through Privacy Choices or email hey@menaceaiapp.com. Describe the right and identify the relevant account email or Menace Device ID. Do not send a password, full payment-card number, government ID, source photo, or Output unless we specifically and securely request it.

We will verify requests proportionately, respond within the period required by law, and explain any lawful limitation. You may use an authorized agent; we may request proof of authority and direct verification from you. We will not discriminate against you for exercising a privacy right, though deleting data needed for a feature can make that feature unavailable.

12. California and Other U.S. State Notices

In the preceding 12 months, depending on the platforms and features used, we collected the categories described in Section 2: identifiers; customer/account records; commercial information; internet or electronic-network activity; approximate geolocation; audio, electronic, and visual information; and inferences about feature or purchase preferences. We collect these from you, your device, app stores, sign-in and payment providers, service providers, and our operations for the business and commercial purposes in Section 3.

We may disclose these categories to the recipient categories in Section 5. We do not sell personal information for money. Attribution disclosures may qualify as sale, sharing, or targeted advertising in some states; use Privacy Choices to opt out. We do not use or disclose sensitive personal information to infer characteristics beyond purposes permitted without a right to limit, unless we provide a separate notice.

We do not offer a financial incentive in exchange for selling personal information. Credits, referrals, discounts, or promotions are governed by their own terms and are not payment for a right to sell your data unless a separate notice expressly says otherwise.

We do not use automated decisionmaking technology to make legal or similarly significant decisions about you. Generation safety filters, purchase-risk checks, abuse controls, and entitlement checks may automatically allow, delay, reject, or limit a request for service, safety, fraud prevention, or legal compliance. If California or another state requires cybersecurity audits, risk assessments, or automated-decision disclosures for a specific Menace processing activity, we will maintain those records and provide the legally required notice or choice.

13. EEA, UK, and Switzerland

Where applicable, we rely on the legal bases below. Ordinary generation requests and the provider transfers needed to perform them are processed to provide the Service you request, not under an optional tracking consent.

  • Contract: to authenticate you, process generation requests and the provider transfers needed to perform them, provide Outputs, maintain credits and access, and deliver requested support.
  • Legitimate interests: to secure, diagnose, measure, and improve the Service; prevent fraud and abuse; protect users; and establish or defend claims, balanced against your rights.
  • Consent: for optional tracking or another distinct feature where consent is required. You may withdraw consent prospectively.
  • Legal obligation and vital interests: to comply with law, valid process, accounting, safety, and urgent protection duties.

You may object to legitimate-interest processing, request restriction, withdraw consent, and complain to your local data-protection authority. We do not use solely automated decisions that produce legal or similarly significant effects about you. Safety filters or purchase-risk checks may automatically allow, delay, or reject a request, but you may contact support.

14. International Transfers

Menace is operated from the United States and uses providers that process information in the United States and other countries. Those countries may have different privacy laws. Where required, we use contractual protections, adequacy decisions, approved transfer mechanisms, or another lawful basis. You may contact us for information about applicable safeguards.

Residents of Canada, Australia, New Zealand, Brazil, and other jurisdictions may have additional local access, correction, deletion, objection, withdrawal, complaint, or appeal rights. Rights, exceptions, legal bases, and response periods differ by location. Nothing in this Policy waives a non-waivable local right; if this Policy conflicts with mandatory local law, that law controls to the extent of the conflict.

15. Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted connections, access controls, authentication, checks designed to detect tampered app activity, restrictions on internal and provider access, media size and format checks, and monitoring. No service is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect your device and credentials and contact us if you suspect compromise.

16. Changes to This Policy

We may update this Policy to reflect new features, providers, laws, or practices. We will post the revised Policy with a new effective date and provide additional notice or obtain consent when required. Material changes will apply prospectively to the extent required by law.

17. Contact

Controller: OneClick Commerce LLC, a California limited liability company. Privacy contact: hey@menaceaiapp.com. Use Your Privacy Choices to exercise a right.