Second Layer, Inc. API Privacy Policy
Effective Date: Aug 11, 2025
This Privacy Policy describes how Second Layer, Inc. ("Napkin," "we," "us," or "our") processes personal information in connection with the Napkin AI API (the "API"), our developer preview text-to-visual generation service. This Privacy Policy applies specifically to the API and is separate from our main platform Privacy Policy.
Information We Collect
Personal Information You Provide
To access the API, you must have an account registered on our platform Napkin.ai. We use only the following information from your existing Napkin account to create your API token:
- Email address - for account identification, support, and communication
- Name - for account management and support purposes
Information We Collect Automatically
API Usage Data
When you use the API, we automatically collect following data:
- Account identification: User ID associated with API requests
- Request data: Number of API requests, request timestamp, creation date, number of visuals requested, and processing times
- Technical parameters: Output format, language, style preferences, dimensions, background settings, inverted color settings, visual query and visual ID requested
- Error information: Debugging data and error logs that may contain fragments of request data and may be linked to your account for troubleshooting purposes
Input and Generated Content Processing
- Input Data: Text and other content you submit to generate visuals
- Temporarily stored during processing (typically seconds to minutes) but not permanently retained
- Processed through secure queues and may be cached in memory and temporary files during generation
- Generated Content: Visual outputs created by the API
- Made available for download for up to one hour after processing
- Automatically deleted from our servers after one hour
Information from Third Parties
We do not collect personal information about API users from third parties, beyond what is already in your existing Napkin account.
How We Use Your Information
We use the information we collect for the following purposes:
API Service Provision
- Authenticate and authorize API access
- Process your requests and generate visual content
- Provide support and troubleshooting
- Monitor API performance and availability
Service Improvement and Analytics
- Analyze usage patterns and API performance
- Debug issues and optimize system performance
Communication
- Send service-related notifications and updates
- Respond to support requests and technical issues
How We Share Your Information
Third-Party Service Providers
We share data with the following service providers solely for processing purposes:
- AI Processing Services: OpenAI and Gemini for AI-powered visual generation
- Input data is shared only for processing and generation
- These providers do not store or use the data for training purposes under our agreements
- Error Monitoring: Sentry for error tracking and performance monitoring
- May receive error logs and technical data for debugging purposes
Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal processes, subpoenas, or court orders
- Protect our rights, property, or safety, or that of others
- Investigate fraud or security issues
Business Transfers
In the event of a merger, acquisition, or sale of our business, user information may be transferred as part of the transaction.
Data Retention
Input and Generated Content
- Input Data: Temporarily stored during processing (typically seconds to minutes) and not permanently retained
- Generated Content: Available for download for up to one hour, then automatically deleted
Analytics and Usage Data
- API usage analytics: May be retained indefinitely for service improvement and performance monitoring
- Account information: Retained as long as your Napkin account remains active
- Error logs: Retained for 30 days for debugging and system improvement purposes
Data Deletion
Upon account termination or API access revocation:
- Account-related data can be manually removed upon request
- Some analytics data may be retained indefinitely for legitimate business purposes
- Error logs are automatically deleted after 30 days
- Input and generated content are not permanently stored, so no deletion is necessary
Data Security
We implement robust security measures to protect your information:
- Encryption: All data is encrypted in transit using HTTPS/TLS protocols
- Storage security: All temporarily stored data is encrypted at rest using industry-standard encryption
- Access controls: Strict access controls limit data access to authorized personnel only
- Monitoring: Our systems are actively monitored for security threats and suspicious activity
We are committed to maintaining the highest security standards, while recognizing that no internet-based service can guarantee complete security.
International Data Transfers
The API is operated from the United States. If you use the API from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
Access and Correction
- Request access to the personal information we hold about you
- Request correction of inaccurate or incomplete information
Data Deletion
- Request deletion of your account information (some analytics data may be retained and can’t be deleted)
- Note: Input and generated content are not permanently stored and hence no need to delete them
Data Portability
- Request a copy of your account information and relevant analytics data in a portable format
To exercise your data rights, you can contact us at contact@napkin.ai anytime and our team will assist you promptly.
Children's Privacy
The API is not intended for use by individuals under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, or if a parent/guardian contacts us about such collection, we will promptly delete the information.
Changes to This Privacy Policy
We may update this Privacy Policy at any time by posting the revised policy. Continued use of the API after such posting constitutes acceptance of the updated Privacy Policy.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
- Email: contact@napkin.ai
- Data Protection Officer: Erwan Martin — dpo@napkin.ai
- Mail: Second Layer, Inc., 626 Jay Street, Los Altos, CA 94022
Last Updated: Aug 11, 2025