Data we process
FoxCut processes account details such as email, name, plan, authentication records, and credit ledger entries. It also processes prompts, settings, source media URLs or uploads, generated jobs and assets, reusable characters and moodboards, and support messages you choose to send.
Connected apps
When you connect an MCP client or the CLI, FoxCut stores hashed OAuth access and refresh credentials, client registration details, scopes, consent records, and security timestamps. The client does not receive your FoxCut password. You can disconnect a client by revoking its credentials or signing out through the CLI.
How data is used
Data is used to authenticate you, run requested generations, calculate and debit credits, return and organize outputs, maintain identity consistency, prevent abuse, troubleshoot failures, and secure the service. FoxCut does not use a guessed user identifier from a tool call; private data is scoped from the authenticated session or OAuth token.
Product analytics
FoxCut uses PostHog to understand visits, signup and creation funnels, feature adoption, generation reliability, retention, and page performance. Analytics identifies signed-in users by an internal account ID, not by email or name. FoxCut does not intentionally send prompts, scripts, uploaded filenames, media URLs, generated media, passwords, payment details, or raw provider errors to PostHog. Automatic click and form capture is disabled. If privacy-restricted session replay is enabled, input values are masked and image, video, audio, and canvas content is blocked. Browser Do Not Track signals are respected by browser analytics.
Service providers
Generation inputs may be sent to configured model and storage providers needed to fulfill your request. PostHog processes the limited product-analytics data described above. Infrastructure, database, and monitoring providers may process operational data. Provider selection can vary by the model or feature you choose and the region in which infrastructure is available.
Retention and deletion
Account data is retained while the account is active and as needed for security, billing, legal, and dispute obligations. You can delete your account from the authenticated deletion page. Deletion removes database records controlled by FoxCut; provider backups, legally required records, and already-exported copies may follow separate retention cycles.
Your choices
You can avoid connecting an external agent, revoke a connection, remove individual characters or moodboards in supported product surfaces, export outputs, disable browser analytics, or request account deletion. The browser control does not disable the limited server-side product events created when an authenticated action succeeds or fails. Contact support for access, correction, deletion, or privacy questions.
Children and sensitive media
Do not use FoxCut to process media without the necessary rights and consent. Do not train or clone a real person’s identity or voice without authorization. The service is not directed to children, and users must meet the minimum age applicable where they live.
Changes and contact
Material policy changes will be dated on this page and may be communicated through the service. Contact hello@foxcut.ai for privacy questions or requests so account ownership can be verified safely.