Privacy Policy

Last updated: February 19, 2026

1. Introduction

namegen ("we", "us", "our") operates the website namegen.dev (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please do not use the Service.

2. Data Controller

The data controller responsible for your personal data is namegen, reachable at [email protected].

3. Data We Collect

We collect the following categories of personal data:

  • Account information — When you sign up, authentication is handled by our third-party provider Clerk. This includes your email address, name, and profile picture as provided by your authentication method (e.g. Google, GitHub, or email/password).
  • User-generated content — Project descriptions, prompts, and refinement messages you submit to generate names.
  • Generated results — Name suggestions, scores, and domain availability data produced by the Service and stored in your account.
  • API keys — If you create API keys for programmatic access, we store a hashed representation and associated metadata (name, creation date, last used date).
  • Technical data — IP address, browser type, and device information collected automatically through server logs.

We do not currently use cookies or any client-side tracking technologies.

5. Third-Party Data Processors

We share personal data with the following third-party processors, each acting under a Data Processing Agreement:

  • Clerk (clerk.com) — Authentication and user management. Clerk processes your account information (email, name, profile picture) and authentication tokens. Clerk acts as a data processor on our behalf.
  • OpenRouter (openrouter.ai) — AI model routing. Your project descriptions and prompts are sent to OpenRouter, which forwards them to large language model providers (including OpenAI and others) to generate name suggestions. These providers process your prompts as sub-processors.
  • LLM providers (via OpenRouter) — Your prompts may be processed by third-party LLM providers such as OpenAI. These providers receive only the project descriptions and prompts necessary to generate results, not your account information.
  • Infrastructure providers — Hosting and database services that store your data in encrypted form.

We do not sell your personal data to any third party.

6. International Data Transfers

Some of our third-party processors (including Clerk, OpenRouter, and LLM providers) may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or the processor's participation in recognized data protection frameworks.

7. Data Retention

We retain your personal data as follows:

  • Account data — Retained for as long as your account is active. Deleted upon account deletion request.
  • Projects and generated results — Retained until you delete them or delete your account.
  • Server logs — Retained for up to 90 days for security and debugging purposes.

Prompts sent to LLM providers via OpenRouter are not stored by us beyond the generated results. Refer to OpenRouter's and the respective LLM provider's privacy policies for their retention practices.

8. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

  • Right of access (Art. 15) — Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — Request correction of inaccurate personal data.
  • Right to erasure (Art. 17) — Request deletion of your personal data. You can delete your projects at any time through the Service. For full account deletion, contact us.
  • Right to restrict processing (Art. 18) — Request that we limit how we use your data.
  • Right to data portability (Art. 20) — Request your data in a structured, machine-readable format.
  • Right to object (Art. 21) — Object to processing based on legitimate interests.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection supervisory authority.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

12. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

[email protected]