Skip to main content

Second Layer, Inc. API Privacy Policy

Effective Date: Aug 11, 2025

This Privacy Policy describes how Second Layer, Inc. ("Napkin," "we," "us," or "our") processes personal information in connection with the Napkin AI API (the "API"), our developer preview text-to-visual generation service. This Privacy Policy applies specifically to the API and is separate from our main platform Privacy Policy.

Information We Collect

Personal Information You Provide

To access the API, you must have an account registered on our platform Napkin.ai. We use only the following information from your existing Napkin account to create your API token:

  • Email address - for account identification, support, and communication
  • Name - for account management and support purposes

Information We Collect Automatically

API Usage Data

When you use the API, we automatically collect following data:

  • Account identification: User ID associated with API requests
  • Request data: Number of API requests, request timestamp, creation date, number of visuals requested, and processing times
  • Technical parameters: Output format, language, style preferences, dimensions, background settings, inverted color settings, visual query and visual ID requested
  • Error information: Debugging data and error logs that may contain fragments of request data and may be linked to your account for troubleshooting purposes

Input and Generated Content Processing

  • Input Data: Text and other content you submit to generate visuals
    • Temporarily stored during processing (typically seconds to minutes) but not permanently retained
    • Processed through secure queues and may be cached in memory and temporary files during generation
  • Generated Content: Visual outputs created by the API
    • Made available for download for up to one hour after processing
    • Automatically deleted from our servers after one hour

Information from Third Parties

We do not collect personal information about API users from third parties, beyond what is already in your existing Napkin account.

How We Use Your Information

We use the information we collect for the following purposes:

API Service Provision

  • Authenticate and authorize API access
  • Process your requests and generate visual content
  • Provide support and troubleshooting
  • Monitor API performance and availability

Service Improvement and Analytics

  • Analyze usage patterns and API performance
  • Debug issues and optimize system performance

Communication

  • Send service-related notifications and updates
  • Respond to support requests and technical issues

How We Share Your Information

Third-Party Service Providers

We share data with the following service providers solely for processing purposes:

  • AI Processing Services: OpenAI and Gemini for AI-powered visual generation
    • Input data is shared only for processing and generation
    • These providers do not store or use the data for training purposes under our agreements
  • Error Monitoring: Sentry for error tracking and performance monitoring
    • May receive error logs and technical data for debugging purposes

We may disclose your information if required by law or to:

  • Comply with legal processes, subpoenas, or court orders
  • Protect our rights, property, or safety, or that of others
  • Investigate fraud or security issues

Business Transfers

In the event of a merger, acquisition, or sale of our business, user information may be transferred as part of the transaction.

Data Retention

Input and Generated Content

  • Input Data: Temporarily stored during processing (typically seconds to minutes) and not permanently retained
  • Generated Content: Available for download for up to one hour, then automatically deleted

Analytics and Usage Data

  • API usage analytics: May be retained indefinitely for service improvement and performance monitoring
  • Account information: Retained as long as your Napkin account remains active
  • Error logs: Retained for 30 days for debugging and system improvement purposes

Data Deletion

Upon account termination or API access revocation:

  • Account-related data can be manually removed upon request
  • Some analytics data may be retained indefinitely for legitimate business purposes
  • Error logs are automatically deleted after 30 days
  • Input and generated content are not permanently stored, so no deletion is necessary

Data Security

We implement robust security measures to protect your information:

  • Encryption: All data is encrypted in transit using HTTPS/TLS protocols
  • Storage security: All temporarily stored data is encrypted at rest using industry-standard encryption
  • Access controls: Strict access controls limit data access to authorized personnel only
  • Monitoring: Our systems are actively monitored for security threats and suspicious activity

We are committed to maintaining the highest security standards, while recognizing that no internet-based service can guarantee complete security.

International Data Transfers

The API is operated from the United States. If you use the API from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.

Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

Access and Correction

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information

Data Deletion

  • Request deletion of your account information (some analytics data may be retained and can’t be deleted)
  • Note: Input and generated content are not permanently stored and hence no need to delete them

Data Portability

  • Request a copy of your account information and relevant analytics data in a portable format

To exercise your data rights, you can contact us at contact@napkin.ai anytime and our team will assist you promptly.

Children's Privacy

The API is not intended for use by individuals under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, or if a parent/guardian contacts us about such collection, we will promptly delete the information.

Changes to This Privacy Policy

We may update this Privacy Policy at any time by posting the revised policy. Continued use of the API after such posting constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

Last Updated: Aug 11, 2025