Privacy Policy

Last updated 1 August 2026 · Version 1.0
Plain summary. We hold your email, your briefs, and what was generated from them. Briefs go to the AI provider that generates your output — that is the whole point — and to nobody else. We don't sell data, don't run advertising, and don't use third-party analytics. You can export everything or delete everything yourself, immediately, from the Account page.

1. Who is responsible

Ali Abbas Rizvi, Flat 1603, Tower 27, Lotus Boulevard, Sector 100, Noida, 201304, is the data controller for the information described here. For anything about your data, write to hello@profferstudio.com.

Our merchant of record, Polar, is a separate controller for payment data. We never see your card details.

2. What we hold, and why

DataWhyLawful basis
Email addressYour login, and how we contact you about the accountContract
PasswordStored only as a bcrypt hash — never in readable formContract
Studio name, logo, brand colorsApplied to your exported documentsContract
Briefs and uploadsThe input generation runs onContract
Generated images and narrativesYour output, kept so you can return to itContract
Connected API keysEncrypted at rest (AES-256-GCM); used only for your own generationsContract
Plan, quota use, subscription statusEnforcing what your plan includesContract
Server logs (IP, timestamp, path, errors)Security, abuse prevention, and diagnosing faultsLegitimate interests

We do not ask for your date of birth, phone number, or address, and we have no use for them. We do not knowingly collect data from anyone under 18.

3. Who your data is shared with

Only these, and only for the purpose named:

That is the complete list. We do not sell or rent personal data, we run no advertising, and we do not use third-party analytics, tracking pixels, or session recording. There are no advertising cookies on this site because there is no advertising.

If you connect your own key

Your brief goes directly to that provider under your account and their terms with you. Their handling of it is between you and them.

4. International transfers

The AI providers listed above process data in the United States. Where you are in the UK or EEA, those transfers rely on Standard Contractual Clauses or an equivalent approved mechanism in each provider's data processing agreement.

5. Cookies

One cookie: pw_session, which signs you in and keeps you signed in. It is strictly necessary, so it needs no consent banner, and it carries no tracking identifier. Your theme preference is kept in your browser's local storage and never leaves your device.

6. How long we keep things

7. Your rights

If you are in the UK or EEA you have the rights below. We extend them to everyone, because operating two standards is worse than operating the stricter one.

We answer requests within 30 days. We never charge for them, and we do not require you to explain why.

Exports report a connected API key as present but never return its value. It is encrypted at rest and decrypted only in memory during a generation call — writing it into a downloadable file would be the least safe thing we could do with it, and you already hold the key, because you issued it.

8. Security

No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority within 72 hours of becoming aware of it.

9. Changes

If we change this policy materially we will email you at least 14 days before it takes effect. The version and date at the top always reflect what is current.

← Back to Proffer Studio