Privacy

Effective September 3, 2026

This describes what Highlander Systems, Inc. (“Highlander”) collects when you use highlander.sh and the Highlander API, who else touches that data, and how long we keep it.

The short version: we do not train models on your prompts, your uploads, or the video we generate for you, and we never see your card number. We keep what is needed to run an account, bill it accurately, and stop abuse — not more.

What we collect

Account data. When you sign up, our identity provider gives us a user identifier and your email address. We store those alongside your credit balance. We do not store your password — we never receive one.

API keys. A key is shown to you once, at creation. What we keep is a SHA-256 hash of it plus a short display prefix and last four characters, so a reader of our database cannot recover a working key. We also record when a key was last used, and when it was revoked.

Generation data. For every generation we store the prompt and negative prompt you sent, the generation parameters (frames, steps, seed, dimensions), the resulting timing and cost, and any error. This is what makes your dashboard history, your billing, and our debugging possible.

Uploads. Reference images, audio, and video you upload for conditioning are stored as files under a prefix scoped to your account.

Payments. Our payment processor handles the transaction and tells us that it succeeded. Card numbers never reach our servers. We store the resulting ledger entry: an amount, a timestamp, and the processor’s identifiers, so a replayed webhook can never double-credit you.

Operational logs. Our host records ordinary request logs — IP address, user agent, timestamp, path, status. We use them to diagnose failures and detect abuse.

We do not run advertising trackers, and we do not sell or share personal information for cross-context behavioural advertising.

What we use it for

  • Running the service: authenticating you, queueing generations, returning video.
  • Billing: metering generated seconds against your prepaid balance and refunding failures automatically.
  • Support and debugging: when a generation fails, its stored parameters and error are how we find out why.
  • Safety and abuse prevention: rate limits, detecting a leaked or abused key, and enforcing the acceptable-use rules in our terms.
  • Service email: receipts, key notifications, and material changes to these documents. We do not send marketing email you did not ask for.

We do not use your prompts, uploads, or outputs to train, fine-tune, or evaluate any model, ours or anyone else’s, and we do not sell them.

Who else processes it

Highlander is a small service built on other people’s infrastructure. These are the vendors that handle your data on our behalf, and what each one sees:

  • Clerk — authentication. Holds your login credentials, email, and session.
  • Stripe — payments. Holds your payment method and billing details directly; we receive only the outcome.
  • Vercel — application hosting, request logs, and blob storage for your conditioning uploads.
  • Neon — the managed Postgres database holding accounts, hashed keys, generation records, and the credit ledger.

Each processes data only to provide its service to us. We may add or change vendors as the service evolves; material changes are reflected here. We may also disclose data where legally required, or to protect our rights, users, or the service.

These vendors operate in the United States. If you use Highlander from outside the US, your data is transferred to and processed there.

How long we keep it

Conditioning uploads are scratch space, not storage. They are pruned on a rolling 7-day retention window. Keep your own copy of anything you care about.

Generated video is streamed to you on request. It is retained for at least 30 days and may be deleted at any time after that. Highlander is not durable storage — download what you want to keep.

Generation records and ledger entries — prompt, parameters, timing, charge — are retained for as long as your account exists, and afterwards for as long as we need them for tax, accounting, and dispute-resolution purposes.

Request logs are retained on our host’s ordinary schedule, which is measured in weeks, not years.

One caveat worth stating plainly: uploads are stored at public-but-unguessable URLs. The GPU worker has to be able to fetch them, so they are not access-controlled — anyone holding the exact link can read the file until it is pruned. Do not upload anything that must stay private.

Security

API keys are stored only as SHA-256 hashes; a database leak does not yield a working key. All traffic runs over TLS. Because credit is prepaid, a leaked key can never spend more than the balance behind it — which is the main reason the billing model works that way. You can revoke any key from your dashboard immediately.

No system is perfectly secure. If you believe your key or account is compromised, revoke the key and contact contact@highlander.sh.

Your rights

Wherever you are, you can ask us to show you the data we hold about you, correct it, delete it, or send you a copy. Email contact@highlander.sh and we will act within 30 days. We will not degrade your service for asking.

If you are in the EU, UK, or Switzerland (GDPR): our lawful bases are performance of a contract for running your account and generations, legitimate interest for security and abuse prevention, and legal obligation for financial records. You have the rights of access, rectification, erasure, restriction, portability, and objection, and you may complain to your local supervisory authority.

If you are in California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and we do not offer financial incentives for data.

Deleting your account removes your generation history, uploads, and keys. Ledger entries tied to a completed payment are retained where the law requires it.

Children

Highlander is not directed to children. You must be at least 13 to hold an account, and at least 18 — or the age of majority where you live — to buy credit. We do not knowingly collect data from children under 13; if we learn we have, we delete it.

Changes

If we change this policy in a way that materially affects how we handle your data, we will update the effective date above and email account holders before it takes effect. Continuing to use Highlander afterwards means the new version applies.

Questions about this document? contact@highlander.sh reaches us.