Privacy Policy
1. Who is responsible
Ali Abbas Rizvi, Flat 1603, Tower 27, Lotus Boulevard, Sector 100, Noida, 201304, is the data controller for the information described here. For anything about your data, write to hello@profferstudio.com.
Our merchant of record, Polar, is a separate controller for payment data. We never see your card details.
2. What we hold, and why
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Your login, and how we contact you about the account | Contract |
| Password | Stored only as a bcrypt hash — never in readable form | Contract |
| Studio name, logo, brand colors | Applied to your exported documents | Contract |
| Briefs and uploads | The input generation runs on | Contract |
| Generated images and narratives | Your output, kept so you can return to it | Contract |
| Connected API keys | Encrypted at rest (AES-256-GCM); used only for your own generations | Contract |
| Plan, quota use, subscription status | Enforcing what your plan includes | Contract |
| Server logs (IP, timestamp, path, errors) | Security, abuse prevention, and diagnosing faults | Legitimate interests |
We do not ask for your date of birth, phone number, or address, and we have no use for them. We do not knowingly collect data from anyone under 18.
3. Who your data is shared with
Only these, and only for the purpose named:
- AI providers — Anthropic, OpenAI, Google, and fal.ai, depending on the model used. Your brief text, and any reference image you upload, is transmitted to them so output can be generated. They act as processors under terms that exclude training on submitted content.
- Our merchant of record (Polar) — your email and subscription status, to take payment and issue invoices.
- Our hosting provider — which necessarily stores the database on our behalf.
- Authorities — only where we are legally compelled, and we will tell you unless we are prohibited from doing so.
That is the complete list. We do not sell or rent personal data, we run no advertising, and we do not use third-party analytics, tracking pixels, or session recording. There are no advertising cookies on this site because there is no advertising.
If you connect your own key
Your brief goes directly to that provider under your account and their terms with you. Their handling of it is between you and them.
4. International transfers
The AI providers listed above process data in the United States. Where you are in the UK or EEA, those transfers rely on Standard Contractual Clauses or an equivalent approved mechanism in each provider's data processing agreement.
5. Cookies
One cookie: pw_session, which signs you in and keeps you signed
in. It is strictly necessary, so it needs no consent banner, and it carries no
tracking identifier. Your theme preference is kept in your browser's local
storage and never leaves your device.
6. How long we keep things
- Account, briefs, and output — until you delete them, or delete your account.
- Deleted accounts — removed immediately, including generated image files. Backups roll off within 30 days.
- Server logs — 30 days.
- Invoices — held by our merchant of record for the period their tax obligations require, typically 6–10 years. We cannot delete those, and neither can they.
7. Your rights
If you are in the UK or EEA you have the rights below. We extend them to everyone, because operating two standards is worse than operating the stricter one.
- Access and portability — Account page → Export my data. A complete JSON file, immediately, no request needed.
- Erasure — Account page → Delete account. Immediate and permanent.
- Rectification — edit your details on the Account page, or write to us.
- Objection and restriction — write to us and we will act on it.
- Complaint — you can complain to your data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
We answer requests within 30 days. We never charge for them, and we do not require you to explain why.
Exports report a connected API key as present but never return its value. It is encrypted at rest and decrypted only in memory during a generation call — writing it into a downloadable file would be the least safe thing we could do with it, and you already hold the key, because you issued it.
8. Security
- HTTPS everywhere, with HSTS.
- Passwords stored as bcrypt hashes; we cannot read them.
- Connected API keys encrypted with AES-256-GCM under a key held outside the database.
- A Content-Security-Policy that permits no inline or dynamically evaluated script.
- Rate limiting on sign-in, and generated files that are only readable by the account that owns them.
No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority within 72 hours of becoming aware of it.
9. Changes
If we change this policy materially we will email you at least 14 days before it takes effect. The version and date at the top always reflect what is current.
← Back to Proffer Studio