coMeMenity

Privacy Policy

Last updated 18 August 2026.

coMeMenity is operated by Decentralyne Company Limited. This page describes what we collect, who else sees it, and what we keep after you delete something.

Three disclosures on this page are more consequential than the rest, and we have put them first rather than at the bottom:

  1. Your prompt is sent to third-party AI companies, and we name every one of them.
  2. *One of those companies takes a perpetual, irrevocable, sublicensable licence over your prompt and the picture it produces, and uses both to train its models.* We quote the clause.
  3. No picture produced here carries an intellectual-property indemnity that reaches this product or you. Not one, on any route, for four different reasons.

1. The third-party model providers, named individually

When you generate a meme, the text you typed — and any caption text you supplied — is transmitted to model providers outside this company. "Third-party AI services" is not a disclosure, so here they are.

WhoWhat they receiveWhat they do with itWhich requests go there
Google (Gemini, via the Gemini Developer API)your situation textreads it and returns a picture; separately classifies itrequests with no style chip, and the illustrated chip
Black Forest Labs (FLUX 2 Pro, reached through fal.ai)your situation text, expanded into an image promptreturns a picture — and keeps both, see § 2the cursed and photoreal chips
Ideogram (Ideogram v3, reached through fal.ai)your situation text, expanded into an image promptreturns a picturethe poster chip
fal.aithe same requests, as the host for the two providers abovehosts and routes themcursed, photoreal, poster
OpenAIyour situation text, your caption text, and the generated picture itselfclassifies both for policy violations; returns no pictureevery generation — the text before dispatch, the picture after it

Two things that table does not make obvious and that you should know anyway:

  • Google sees your text more than once, and for two different jobs. Besides image generation, a small Google text model reads every situation before dispatch to decide whether it names a real person, and another Google text model writes the caption and the alt text. So even a request that routes its picture to Black Forest Labs or Ideogram has had its text read by Google.
  • OpenAI is on every single generation, twice. We use OpenAI only for content moderation — it never produces an image here — but that means your prompt reaches OpenAI before dispatch, and the picture that comes back is then sent to OpenAI as well, so that we check the output and not only the input. So an OpenAI service sees your text and your picture on every generation, on every route.

We do not send these providers your email address, your account id, or your IP address. They receive the text and nothing that identifies you to them.

Our own infrastructure providers

These are processors: they hold data on our behalf, under contract, and they do not use it for their own purposes.

WhoWhat they hold
Neonthe database — accounts, memes, prompts, refusal records, cost records
Cloudflare R2the image bytes: every generated picture and every composite
Trigger.devthe generation job queue. A job payload carries your situation text verbatim while the job runs
Upstashrate-limit counters, keyed by a hashed IP address or session id — never a raw address

There is no advertising network and no third-party product-analytics service in this release.


2. Black Forest Labs takes a perpetual licence over your input and your output

This is the disclosure we would most want to read if we were you, so we quote it rather than summarise it. From the FLUX API Service Terms, last revised 4 August 2026, § 2(b) License to the Company:

Developer grants the Company a fully paid, royalty-free, perpetual, irrevocable, worldwide, non-exclusive, and fully sublicensable right and license to use, sub-license, distribute, reproduce, modify, adapt, publicly perform, and publicly display Developer's Input and Output for the purpose of operating the FLUX Services, improving the Company's products and services, and developing new products and services. Developer acknowledges that the foregoing means the Company may use Inputs and Outputs to train and improve its artificial intelligence models, algorithms, and related technology, products, and services.

"Developer" there is us. "Input and Output" is your prompt and your picture.

*Which requests are affected: the cursed chip and the photoreal chip. Those two route to FLUX 2 Pro. If you would rather Black Forest Labs did not receive and retain a request, do not use those two chips — the default route, the illustrated chip and the poster* chip go elsewhere.

We read that clause from Black Forest Labs' own published terms on 16 August 2026. We are not relaying somebody's summary of it.


3. No output carries an IP indemnity that reaches this product

Every picture stored by this service is recorded internally with an indemnity posture, and the only value that field has ever held is none.

That is not a formality. Several AI companies advertise that they will defend and indemnify customers against copyright claims arising from their models' output. None of those protections reaches this product, and the reason is different for each of the four companies above. A single sentence saying "third parties may offer indemnities" would flatten four distinct facts into a reassurance, so:

  • Google. Google's two-part generative-AI IP indemnity is a Google Cloud / Vertex AI contract term. Our key is a Gemini Developer API (AI Studio) key, which is a different agreement. We verified which surface our key authenticates against on 12 August 2026. The Vertex term does not reach us. Moving to Vertex would not fix it either, because of the compositing point below.
  • Black Forest Labs. Their FLUX API Service Terms contain no indemnity provision at all — the word does not appear in the document. Their incorporated Developer Terms of Service run in the opposite direction: we indemnify them. They do disclaim ownership of outputs, which is a different thing from standing behind them, and they say so expressly: their disclaimer of ownership is not any clearance, warranty of non-infringement, or representation that outputs are free of third-party claims.
  • fal.ai. We have not been able to read fal.ai's terms of service. Every attempt, on multiple URLs, returned an HTTP 429 behind an automated bot check requiring JavaScript. We therefore make no statement about what fal's terms say, in either direction, and we rely on nothing in them. What we can tell you is the operative fact: we have no indemnity from fal, because we have not obtained one. This gap is recorded in our own engineering notes as unresolved rather than quietly assumed away.
  • OpenAI. OpenAI's Copyright Shield covers OpenAI-generated output. No picture on this service is produced by an OpenAI model — we use OpenAI only for moderation — so there is nothing here for it to cover. And if we did route pictures there, it still would not apply: the Shield is excluded where output is modified, transformed, or combined with non-OpenAI products and services, and compositing a caption onto the picture is exactly that modification. It is also the one step this product cannot skip.

What this means for you. If a meme you made here attracts a copyright claim, there is no vendor behind it and no vendor behind us. That is stated in the Terms of Use too, because it is the single most commercially significant fact on either page.


4. What we collect

If you have no account. A signed session cookie (cmm_anon) so your work is yours to see, claim and delete. It contains no name and no address. Plus the things below that every request produces.

If you have an account. Your email address, and — if you signed in through Discord or Google — the account identifier that provider returned to us. Nothing else from them.

From every generation. The situation you typed; the style chip; the caption text you supplied or the caption the model wrote; the language the model detected you wrote in; which model produced each candidate; which candidate you picked; the alt text; and a per-candidate cost record with the money we spent.

From every request that touches a rate limit or a refusal. A keyed hash of your IP address — HMAC-SHA256 under a secret key, never the address itself and never a plain digest of it. A plain SHA-256 of an IPv4 address is not anonymisation: the whole address space can be enumerated in seconds, so an unkeyed digest is functionally the address. We key it.

Nothing about you goes to a model provider. The prompt goes; the account does not.


5. What we keep after you delete something

Deleting a meme removes it from every page and every link. It is a soft delete: the row survives with a deletion timestamp, and the following survive with it. This is the section most privacy policies leave vague, so read it as the complete list.

  • The meme's record and both image fingerprints — a cryptographic hash and a perceptual hash. The perceptual hash is what lets us recognise a re-upload or a re-crop of something already removed. A removal that could be defeated by cropping the picture 5% would not be a removal.
  • The cost record, so we can answer what was spent and by whom during an incident.
  • Refusal records. When a request is refused, we write a row containing the text of the prompt that was refused and the keyed IP hash. Repeated refusals from one person are the strongest early abuse signal there is, and it cannot be reconstructed after the fact. These rows are an abuse record. They are not deleted when you delete a meme, and there is no path by which you can delete them.
  • The quarantine access log. If our own output check holds a generated picture back, that picture is stored undeliverable and can be viewed only by one named person, and every viewing is logged — who, which asset, when. That log survives deletion too. It exists so that looking at withheld material is a deliberate, attributable act rather than an unrecorded one.
  • Report records. A report somebody filed about a meme survives the meme, so that a 48-hour removal commitment can be shown to have been kept.

We are not going to describe this as "data minimisation". It is the opposite: it is deliberate retention, and the reason for each item is written above.


6. Your rights, and which law applies

We operate from Nigeria with a global audience, so more than one regime reaches this service. Our posture is to satisfy the strictest duty that applies rather than to pick the most convenient one.

Nigeria's Data Protection Act 2023 (NDPA) applies to us directly, on top of whatever applies to you by where you are. Under it you can ask us what we hold about you, ask us to correct it, ask us to delete it, object to processing, and complain to the Nigeria Data Protection Commission.

Where a request would reach the retained records in § 5, we will tell you plainly which items we are refusing to delete and why, rather than quietly deleting the easy parts. An abuse record and an access log exist precisely so that they cannot be removed on request by the person they record.

Write to abuse@comemenity.com to exercise any of this.


7. Provenance and watermarks

Every composite we produce carries a Content Credentials (C2PA) manifest stating that a caption was composited by coMeMenity over an AI-generated base, and naming the model that produced the base.

That manifest is self-signed and every verifier will report our signer as untrusted. It is not verified, certified or authenticated by anybody, and we will not describe it as any of those things. See the Terms of Use for the longer explanation.

Some providers embed their own invisible watermark in the pixels of the pictures they return. We do not add one, we cannot detect one, and we make no claim about whether one survives our compositing step.


8. Children

This service is not for children. We refuse any request involving a minor, and we do not knowingly create or retain accounts for people under the age at which they can consent to this processing where they live.


9. Contact

abuse@comemenity.com — one address for privacy requests, abuse reports and copyright notices — monitored by a named person rather than routed into a queue nobody owns.