Privacy Notice

Effective date: September 1, 2026
Version: 2.0
Applies to: the Muza mobile application, the website appmuza.com, our support channels and our social media pages

Company details. In this document, "Company", "we", "us" and "our" refer to:

Legal name: ONCREATE LTD, a limited liability company organized under the laws of Ukraine
Registered address: 31V Serhiia Podolynskoho Street, Dnipro, 49069, Ukraine
Privacy requests and data protection contact: [email protected]

Key points (summary)

1. Scope and who we are

1.1 This Privacy Notice explains how the Company collects, uses, shares and protects personal data when you use the Muza mobile application (the "App"), the website appmuza.com (the "Website"), our support channels and our social media pages (together, the "Service"). It also explains your rights and how to exercise them.

1.2 The Company is the controller of personal data processed through the Service, meaning that we decide why and how it is processed. Third parties that provide services to us (such as cloud hosting and AI providers) act as our processors, unless this Notice says otherwise. Certain third parties, such as Apple, Google and social media platforms, are independent controllers of the data they collect under their own terms. One exception: where a business user uploads materials containing personal data of its own customers, employees or other third parties (for example documents in a Knowledge Base), the business user is the controller of that data and we process it on the business user's behalf under the data processing terms in Section 11.4 of the Terms of Service.

1.3 This Notice does not apply to third-party websites, apps or services that you access through links in the Service, or to social media platforms on which you publish content created with Muza. Their privacy policies apply to them.

1.4 Capitalized terms not defined in this Notice have the meaning given in the Muza Terms of Service.

2. Information we collect

We collect information in three ways: you provide it to us, it is collected automatically when you use the Service, and we receive it from third parties. Below are the categories, with examples.

2.1 Information you provide

(a) Account information. Email address, name, profile picture (if you sign in with Apple or Google), sign-in method, password (stored by our authentication provider in hashed form; we never see it), and account settings. If you use Sign in with Apple's "Hide My Email", we receive a relay address.

(b) Profile and onboarding information. Your answers to onboarding questions and surveys (for example your goals, experience level, niche, audience, content language, brand name and style preferences), and settings such as the names, avatars and colors you assign to the SMM Team personas.

(c) Content you upload or create ("Your Content"). Photos, videos, audio, voice recordings, screenshots, text prompts, captions, notes, documents (for example price lists, service descriptions, brand guidelines), logos and brand images, links to your website and social profiles, chat messages with the AI Assistant and the SMM Team, and the projects, drafts, content plans and Outputs you create. Your Content may contain personal data about you and about other people who appear in it.

(d) Face and appearance data. When you use face-related features, we process images of faces and, for AI Characters, the photos and attributes you provide to describe a character (for example apparent age range, hair, eye and skin tone, and full-body reference photos) and a voice you select or record. See Section 5.

(e) Social media and business information. The social media handles you enter (yours and up to a limited number of public accounts you choose as Reference Accounts), your website address, and information about your brand and business that you enter or that we derive from your website at your request (for example a summary, design system and brand voice).

(f) Purchase information. Confirmation of purchases from the App Store Provider or our Payment Processor (transaction and receipt identifiers, product, price paid, currency, Subscription status and renewal dates), your Credit balance and usage, and promo codes you redeem. We do not receive full payment card numbers.

(g) Support and communications. Information you provide when you contact us (name, email, message, screenshots, device details and transaction identifiers), survey responses, ratings and feedback on Outputs.

2.2 Information collected automatically

(a) Device and app information. Device model, operating system and version, App version and build, language and locale, time zone, screen and hardware characteristics, whether the App is running on a Mac, number of days since installation, and Subscription status.

(b) Identifiers. A persistent, randomly generated installation identifier created by the App and stored in the device keychain (used to recognize your installation, to deliver cloud features if you have no account, and to prevent fraud and abuse); the Apple identifier for vendors (IDFV) or, on Android, the equivalent app set and device identifiers; the advertising identifier (IDFA on iOS, advertising ID on Android) only if you allow tracking in the App Tracking Transparency prompt or the corresponding Android setting, and only for advertising attribution and measurement; Firebase installation and analytics identifiers (which are also linked to your account on our servers so that we can relate usage to your account); push notification tokens (APNs and FCM) and Live Activity tokens; a user identifier assigned by our authentication provider; and App integrity tokens generated by Apple App Attest / DeviceCheck, Firebase App Check and, on Android, Google Play Integrity to confirm that requests come from a genuine copy of the App.

(c) Usage information. Events describing how you use the Service: screens viewed, buttons tapped, features and tools used, AI generations requested (feature, model, parameters and Credit cost, but not the content of your prompts or files in analytics tools), searches within the App, paywall views, purchases, onboarding progress, number of projects, whether you took a screenshot or screen recording in the App, session length and frequency, and interactions with notifications.

(d) Technical and diagnostic information. IP address (from which we derive an approximate country or region), request headers, timestamps, error and crash reports (including stack traces, device state and an identifier for your installation or account), performance metrics and logs of requests to our servers (including the type of AI operation, workflow and session identifiers, estimated Credit cost and status).

(e) Website information. When you visit the Website, we collect the information described in our Cookie Policy (for example pages visited, referrer, browser type, approximate location from IP, and cookie or similar identifiers, subject to your consent where required).

(f) Approximate location. We derive an approximate location (country or region) from your IP address and device settings. The App does not collect precise GPS location.

2.3 Information we receive from third parties

(a) Sign-in providers. If you sign in with Apple or Google, we receive your name, email address (or relay address) and profile picture as permitted by your settings with that provider.

(b) App Store Providers and Payment Processors. Purchase and Subscription confirmations, renewal, cancellation and refund status.

(c) Data Providers and platforms. Publicly available information about the social media accounts you ask us to analyze (yours and Reference Accounts): public profile details such as username, display name, biography, profile picture, follower and post counts, public posts and their public metrics, hashtags, sounds and links, and, for trend analysis, public posts and their authors. We obtain this through third-party data providers and, where available, official platform APIs. We never access private accounts or content, and we never ask for your platform password.

(d) Marketing and attribution partners. Information about how you found Muza (for example the campaign, ad network or link that led to the installation) from attribution partners such as AppsFlyer and advertising platforms such as Meta, which may match installation and event data with data they hold about you under their own policies.

2.4 Information about other people

Your Content, Reference Accounts, your Knowledge Base and your website may contain personal data about other people: people who appear in your photos, videos or recordings; the owners of Reference Accounts and the authors of public posts; your customers, employees or partners named in documents you upload; and people whose photos you use for AI Characters or SMM Team avatars. We process this information only to provide the Service to you, as described in this Notice. You are responsible for having the right to provide it, including the consent of people whose face or voice you use with AI features (see the Terms of Service, Section 5.6, and Section 6 of this Notice).

2.5 Processing that stays on your device

Many editing tools work entirely on your device using on-device machine learning: face detection and facial landmarks, iris and hair segmentation, body and background segmentation, face parsing, skin retouching, image labeling, speech recognition (where supported by Apple's on-device recognition for your language) and Apple Image Playground. Some on-device tools estimate visual attributes of a face (for example an apparent age range or gender presentation) solely to select suitable retouching or makeup parameters. Data processed this way is not transmitted to us or to third parties and is not stored beyond the editing session, unless you save the result as part of your project (some on-device SDKs may report anonymous usage metrics to their developers; see the Third-Party Services page). Speech recognition for languages or features that on-device recognition does not support is performed in the cloud by Apple or by our AI Providers, as described in Section 5.

2.6 Using Muza without an account

If you use the App without creating an account, your projects are stored only on your device. Data needed for cloud features (for example onboarding answers, files uploaded for AI processing and generation history on our servers) is linked to the installation identifier described in Section 2.2(b) instead of an account. You can remove it with "Clear app data" in the App (Settings > Personal Data), and we delete it after 12 months of inactivity. If you later create an account, this data is linked to your account.

3. How we use information and on what legal basis

We use personal data for the purposes below. Where the GDPR, the UK GDPR or a similar law applies, we rely on the legal bases indicated.

PurposeExamplesLegal basis (GDPR / UK GDPR)
Providing the ServiceCreating and managing your account; storing and syncing your projects; running editing tools; generating Outputs from your Inputs; delivering Social Growth Features; operating the AI Assistant and SMM Team; showing your Credit balance; providing supportPerformance of a contract (Terms of Service)
Face and voice featuresCreating AI Characters, face swap, lip sync, AI headshots, hairstyle changes, voice generation and cloning from your recordingsYour explicit consent (Article 6(1)(a) and, to the extent the data qualifies as special category data, Article 9(2)(a)), which you can withdraw at any time
Sharing content with AI ProvidersTransmitting your Inputs to third-party AI Providers to generate OutputsPerformance of a contract; your explicit permission where required by law or by the App Store Provider
PersonalizationUsing your onboarding answers, Brand Kit, Knowledge Base, brand voice and feedback to tailor strategies and Outputs; remembering your preferencesPerformance of a contract; legitimate interest in providing a relevant service
Social Growth Features involving other people's public dataAnalyzing Reference Accounts and public trends to benchmark your profile and generate ideasLegitimate interest (yours in receiving the analysis, ours in providing it), balanced against the interests of the people concerned (see Section 6)
Payments and CreditsVerifying purchases, unlocking features, crediting and deducting Credits, preventing fraud, handling refund inquiries, keeping accounting recordsPerformance of a contract; legal obligation (tax and accounting); legitimate interest in preventing fraud
CommunicationsSending service messages (receipts, security alerts, changes to terms), responding to support requests, push notifications about your generations, plans and reminders (which you control in your device and App settings)Performance of a contract; legitimate interest in communicating with users; consent for push notifications where required
MarketingSending news, tips and offers by email or push notification; measuring the effectiveness of our advertising; showing you Muza ads on other platformsConsent where required (for example for marketing emails and for tracking across apps on iOS); otherwise legitimate interest in promoting the Service. You can opt out at any time
Analytics and product improvementUnderstanding how features are used, measuring performance, testing changes, fixing bugs, analyzing crashes, improving prompts and quality controls using aggregated data and your feedbackLegitimate interest in improving the Service; consent for analytics identifiers where required by law
Safety, security and integrityDetecting and preventing abuse, fraud, bots, credential compromise and violations of the Terms; applying safety filters; verifying App integrity; enforcing usage limits; protecting users and third partiesLegitimate interest in protecting the Service and its users; legal obligation where applicable
Legal compliance and claimsComplying with laws, court orders and lawful requests; responding to rights requests; establishing, exercising or defending legal claims; handling copyright and likeness complaintsLegal obligation; legitimate interest in protecting our rights
Business operationsCorporate transactions, audits, insurance, reportingLegitimate interest in running our business

 

We do not use personal data for automated decision-making that produces legal or similarly significant effects on you.

4. AI processing and AI Providers

4.1 What happens when you use cloud AI features. When you request a cloud-based generation or transformation, the App uploads the necessary Inputs (for example a photo, video, audio clip, text prompt, and, for personalized features, a short description of your brand voice, relevant excerpts of your Knowledge Base or your AI Character data) to our servers or cloud storage. Our servers forward the request to one or more third-party AI infrastructure, model-hosting or model providers ("AI Providers"), which process it and return the result. The result is delivered to the App and, depending on the feature, stored in your project, your generation history or your account.

4.2 What AI Providers receive. AI Providers receive only the data needed to fulfill the request. They do not receive your email address, account credentials or payment information, and requests are made under our provider accounts rather than in your name; they may, however, see names and other details contained in the Inputs themselves (for example your public profile, documents or messages you ask the AI to work with). Where an AI Provider needs to fetch a file, it receives a link to that file in our cloud storage; such links are not publicly listed and expire after a short period.

4.3 Who the AI Providers are. We use, or may use, providers including Replicate, fal.ai, OpenAI, Google (Gemini API), ElevenLabs, Stability AI, Luma AI, Segmind, MuAPI and others, which host or provide models developed by companies such as Black Forest Labs, Google, OpenAI, ByteDance, Kuaishou, MiniMax, Alibaba, Runway, Ideogram, Recraft, Bria, Stability AI, Luma AI, Meta and ElevenLabs. The categories of AI Providers, the principal providers used or that may be used, the categories of data they process and links to their privacy terms are maintained at appmuza.com/info/third-party-services. Providers, models and routing change regularly as the Service evolves; we update that page periodically, and the consent screens in the App show the categories of providers involved in a feature at the time you enable it. Which provider handles a particular request depends on the feature and model you choose and on our routing at the time.

4.4 Retention by AI Providers. AI Providers process Inputs and Outputs under their service terms. Most delete the data shortly after the request is completed or retain it for a limited period (typically up to 30 days) for abuse monitoring and reliability, after which it is deleted. Some providers apply shorter periods. Links to each provider's terms are available on the Third-Party Services page.

4.5 No training on Your Content. We do not use Your Content to train, fine-tune or improve generative AI models that serve other users. We use AI Providers under service terms that prohibit them from using customer content to train their models, or we disable such use where a provider offers that setting. If we ever want to use Your Content for AI training, we will ask for your separate, explicit consent first.

4.6 Personalized representations. Features such as AI Characters create a personalized representation (for example an embedding or a small personalized model) from the photos and voice you provide, used only for your account, and deleted when you delete the character or your account.

4.7 Your permission. Where required by applicable law or by the App Store Provider, the App asks for your explicit permission before Your Content is shared with AI Providers for the first time, and explains what will be shared. You can withdraw this permission in the App (Settings > Personal Data); cloud AI features will then be unavailable.

4.8 Provenance information. Outputs may contain machine-readable provenance information (such as content credentials, metadata or an imperceptible watermark) indicating that the content was generated or modified with AI, and may include a timestamp, the name and version of the system, and a unique identifier of the Output. This information does not include your name or account details.

5. Face and voice data

5.1 What we process. Some features process images of faces or recordings of voices in the cloud: AI Characters (which create a reusable representation of a person from face and body photos and a chosen or recorded voice), face swap, lip sync, AI headshots, hairstyle changes, restoration and upscaling of portraits, voice generation, and cloud transcription of voice recordings for subtitles and voice input. This processing may involve estimating the position, shape and characteristics of facial features or the characteristics of a voice so that the AI model can produce a result that resembles the person, or converting speech to text.

5.2 What we do not do. We do not use face or voice data to identify, verify or authenticate anyone, we do not build a database that could be used to recognize people, we do not sell, lease or trade face or voice data, and we do not use it for advertising.

5.3 Consent. Before you use these features for the first time, the App asks for your explicit consent (a written consent by electronic means where required by law, including for residents of Illinois, Texas and Washington in the United States and for residents of the EU, EEA and UK). You can withdraw consent at any time by deleting the relevant characters or content, by disabling the features in the App (Settings > Personal Data), or by contacting [email protected]. Withdrawal does not affect processing that took place before it.

5.4 Other people. You may use these features on another person's face or voice only with that person's explicit consent, and never on persons under 18. We rely on your confirmation of that consent and may suspend accounts that misuse these features.

5.5 Retention and destruction. Face and voice data processed for a one-off edit (for example face swap or restoration) is deleted from our cloud storage within 30 days after the request is completed; AI Providers delete it as described in Section 4.4. Data that forms part of an AI Character (photos, attributes, voice and the personalized representation) is kept for as long as the character exists in your account, and is deleted within 30 days after you delete the character or your account, and in any event no later than three years after your last interaction with the Service (or one year after the purpose of collection has been satisfied for residents of Texas). Copies in backups are deleted within 90 days.

5.6 More information. Our Face & Voice Data (Biometric) Notice at appmuza.com/info/biometric provides additional detail, including the retention schedule required by certain US state laws.

6. Social Growth Features and information about other people

6.1 Your own profile. When you enter your social media handle and website, we collect publicly available information about them through Data Providers and platform APIs, and we may refresh it periodically while the feature is active to update your analysis and strategy. We store your profile analysis, strategy, content plan and related settings in your account.

6.2 Reference Accounts and trends. When you select Reference Accounts, or when we analyze public trends for your niche, we process publicly available information about those accounts and posts and about their authors. These people are not users of Muza and are not informed by us, because providing individual notice to them would involve disproportionate effort and would not change the public nature of the data. We rely on our and your legitimate interests in benchmarking and content research, we process only information the account owners have made public, we do not analyze faces in that content for identification, we do not combine it with data from other sources to build profiles of those individuals, and we cache it for no more than 30 days per analysis.

6.3 Limits. The Service may be used only to analyze your own accounts and public business, creator, brand or public-figure accounts. It must not be used to monitor or profile private individuals or minors. We may restrict the feature where a platform or law requires it.

6.4 If you are a person whose public data has been processed. If you believe that your public profile information has been processed by the Service and you object to that processing, or you want it deleted, contact [email protected]. We will remove cached data about you, subject to our legal obligations, and we will take reasonable steps to prevent it being re-collected where technically possible.

7. How we share information

We do not sell personal data, and we do not share personal data with third parties for their own marketing. We share personal data only as follows:

7.1 Service providers (processors). With companies that process data on our behalf and under our instructions, in these categories:

The categories and principal providers are listed at appmuza.com/info/third-party-services. Providers within a category may be added, replaced or removed at any time; we update that page periodically, and the App shows, where required, the categories of providers involved in a feature when you enable it.

7.2 Content and platform providers. When you use Third-Party Content features (for example stock photos from Unsplash or Pexels, or GIFs from GIPHY), your search terms and technical data are sent to those providers under their own privacy policies. When you sign in with Apple or Google, those providers process your sign-in under their policies.

7.3 Legal reasons. With courts, law enforcement, regulators and other authorities, and with our professional advisers, where we believe disclosure is required by law or legal process, or is necessary to protect the rights, property or safety of the Company, our users or the public, to enforce our Terms, to investigate fraud, abuse or security issues, or to respond to copyright and likeness complaints. We may report content that sexually exploits minors to the relevant authorities.

7.4 Business transfers. In connection with a merger, acquisition, financing, reorganization, sale of assets or similar transaction, or in the event of insolvency, personal data may be transferred to the acquiring or successor entity, which will be bound by this Notice or will notify you of any material changes.

7.5 Affiliates. With our affiliated companies, where they help us provide the Service, under this Notice.

7.6 With your direction or consent. When you export or share content to other apps or platforms, or when you ask us to share information with a third party, or otherwise with your consent.

7.7 Aggregated or de-identified data. We may share aggregated or de-identified information that cannot reasonably be used to identify you, for example statistics about usage of features.

8. Analytics, advertising measurement and tracking

8.1 Analytics. We use Google Analytics for Firebase and Firebase Crashlytics, and we use or may use product and subscription analytics tools such as Amplitude and RevenueCat, to understand how the App is used, to measure Subscriptions and purchases, and to fix problems. Crash and performance reporting runs on the basis of our legitimate interest in keeping the App stable and secure; analytics identifiers are used with your consent where the law requires it (see Section 8.4). These tools collect usage and device information and identifiers described in Section 2.2. We configure them to avoid collecting the content of your files and prompts.

8.2 Attribution and marketing measurement. We advertise Muza on platforms and networks such as Meta (Facebook and Instagram), Google Ads, Apple Ads (Apple Search Ads), TikTok, AppLovin, Unity, Snap, X and others, and we use attribution platforms such as AppsFlyer to measure which campaigns lead to installations and purchases and to power deep links. For this purpose, installation, session, paywall, content view (with the identifier of the content viewed), purchase (including purchase amounts) and uninstall events, and identifiers (such as the IDFA where permitted, the IDFV, a hashed installation identifier, the push notification token used by the attribution platform to measure uninstalls, and IP-derived location) may be shared with the attribution platform and with the advertising networks whose tools are integrated in the App. Those networks may use the data under their own privacy policies, including to match you to their users and to measure or optimize our advertising. On iOS we also use Apple's SKAdNetwork and AdAttributionKit, and on Android the equivalent privacy-preserving attribution frameworks, which provide aggregated results without identifying you.

8.3 Your choices on iOS (App Tracking Transparency). The App asks for your permission before accessing the advertising identifier (IDFA) to track your activity across other companies' apps and websites. If you do not allow tracking, the IDFA is not used, and attribution is limited to privacy-preserving methods and to identifiers within the App. You can change your choice at any time in Settings > Privacy & Security > Tracking on your device.

8.4 Your choices in the EU, EEA, UK and Switzerland. Where the law requires consent for analytics or marketing identifiers and for storing or accessing information on your device, we ask for it in the App and on the Website, and we set the analytics and advertising signals of our tools to "denied" until you consent. You can change your choices in the App (Settings > Personal Data) and in the cookie settings on the Website.

8.5 US "sharing" for cross-context behavioral advertising. The sharing of identifiers and events with advertising platforms described in Section 8.2 may be considered "sharing" for cross-context behavioral advertising, or "targeted advertising", under some US state privacy laws. You can opt out by (a) declining tracking in the App Tracking Transparency prompt; (b) using the "Do Not Sell or Share My Personal Information" control in the App (Settings > Personal Data); (c) enabling a Global Privacy Control signal in your browser when visiting the Website; or (d) emailing [email protected] with the subject "Do Not Sell or Share". We do not knowingly share the personal data of persons under 16.

8.6 Marketing communications. We send marketing emails only with your consent where required by law, and every marketing email includes an unsubscribe link. You can manage push notifications in your device settings and in the App. Service messages (such as receipts and security notices) are sent regardless of your marketing preferences.

8.7 Website cookies. Cookies and similar technologies used on the Website are described in our Cookie Policy at appmuza.com/info/cookies.

9. International data transfers

9.1 Where we process data. The Company is established in Ukraine, and our team accesses data from Ukraine and other countries where our staff and contractors are located. Our cloud infrastructure is provided by Google (with primary data storage currently in the United States) and by hosting providers such as OVHcloud and others, whose data centers are located in the European Union, the United States and Asia. AI Providers and Data Providers are located mainly in the United States and the European Union, and some infrastructure and model providers operate in other countries, including Asia; where a model developer processes data outside the infrastructure of our AI Provider, this is disclosed on the Third-Party Services page.

9.2 Safeguards. Where personal data protected by the GDPR, the UK GDPR or the Swiss data protection law is transferred to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum or Agreement), the EU-US, UK and Swiss-US Data Privacy Framework where the recipient is certified, and supplementary measures where needed. You may request a copy of the relevant safeguards at [email protected]

9.3 Ukraine. Transfers of personal data of Ukrainian residents abroad are carried out in accordance with the Law of Ukraine "On Protection of Personal Data", on the basis of your consent to the processing described in this Notice and the contractual safeguards we have in place.

10. How long we keep information

We keep personal data only for as long as necessary for the purposes described in this Notice, unless a longer period is required by law. Typical periods:

DataRetention
Account information and settingsFor the life of your account, then deleted within 30 days after deletion (backups within 90 days)
Projects stored only on your deviceUnder your control; deleted when you delete them or the App
Projects and Knowledge Base synced to the cloudWhile your account exists and Sync is available to you; cloud copies are deleted within 90 days after the Subscription that includes Sync ends, unless you delete them earlier
Inputs uploaded for cloud AI processing (one-off edits and generations)Deleted from our cloud storage within 30 days after processing
Outputs and generation historyUntil you delete them or your account; temporary server copies of results are deleted within 90 days
AI Characters, face and voice data and personalized representationsWhile the character exists; deleted within 30 days after deletion of the character or account, and no later than 3 years after your last interaction with the Service
Brand Kit, brand voice, onboarding answersUntil you change or delete them or delete your account
Chat history with the AI Assistant and SMM TeamUntil you clear it or delete your account
Your social profile analysis, strategy and content planWhile the feature is active and your account exists
Cached public data about your profile, Reference Accounts, trends and websitesUp to 30 days per analysis; public information about businesses, brands and social media accounts, and analyses derived from it, is not deleted on account deletion and may be collected again from public sources (see the Account Deletion Policy, Section 4.1)
Data held by AI ProvidersTypically deleted immediately after processing or within up to 30 days, according to each provider's terms (see the Third-Party Services page)
Purchase and Credit recordsFor the life of your account and thereafter for the period required by tax and accounting law
Support communications3 years after the last contact
Consent records (for face and voice features, marketing, tracking)For the life of your account and 3 years thereafter
Analytics and attribution dataUp to 2 years, then deleted or aggregated
Crash and diagnostic reportsUp to 90 days
Server logs including IP addressUp to 12 months, longer only for security investigations
Device and installation identifiers used for fraud and abuse preventionUp to 2 years after last activity
Unfinished generation runs (for example in AI Video Studio)Deleted, together with their files, after 7 days of inactivity
Data needed for legal claims, disputes or legal obligationsFor the duration of the relevant limitation period or obligation
Cloud data of users without an account (linked to an installation identifier)Deleted after 12 months of inactivity or when you use "Clear app data"

 

Inactive accounts: if you have not signed in for 3 years, we may delete your account and Your Content after notifying you at your registered email address; we do not delete for inactivity accounts that hold unused Credit Packs.

11. Security

We protect personal data with technical and organizational measures appropriate to the risk, including encrypted connections to our services and encryption at rest for cloud storage, access controls and authentication for our systems, App integrity checks, logging and monitoring, and contractual obligations for our processors. No system is completely secure; you are responsible for keeping your credentials confidential and for the security of your device. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify you and the competent authorities as required by law.

12. Your rights and choices

12.1 Rights available to everyone. Regardless of where you live, you can: access the personal data we hold about you; correct inaccurate data; delete your account and Your Content in the App (see the Account Deletion Policy); export your projects from the App; manage push notifications, tracking and marketing preferences in your device and App settings; and unsubscribe from marketing emails.

12.2 Residents of the EU, EEA, UK and Switzerland. You have the right to request access to your personal data and information about its processing; rectification; erasure; restriction of processing; data portability (in a structured, commonly used, machine-readable format); and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Right to object. You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (including any profiling based on those interests), and we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms. You also have the right to object at any time to the processing of your personal data for direct marketing, in which case we will stop that processing. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (for the UK, the Information Commissioner's Office, ico.org.uk). We would appreciate the chance to address your concerns first at [email protected]

12.3 Residents of the United States. Depending on your state of residence (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia), you may have the right to: confirm whether we process your personal data and access it; correct inaccuracies; delete personal data; obtain a copy of your data in a portable format; opt out of the sale of personal data, of sharing or processing for targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects; limit the use of sensitive personal data; and appeal a decision we make on your request. We do not sell personal data. We may "share" identifiers and usage data for advertising measurement as described in Section 8; you can opt out as described in Section 8.5, and we honor Global Privacy Control signals on the Website where required. We do not process sensitive personal data for purposes other than those permitted by law without your consent. We will not discriminate against you for exercising your rights. If we deny your request, you may appeal by replying to our decision or emailing [email protected] with the subject "Privacy appeal"; if the appeal is denied, you may contact your state attorney general.

12.4 California: additional disclosures. In the preceding 12 months we have collected the following categories of personal information (as defined in the CCPA): identifiers; personal information categories listed in Cal. Civ. Code § 1798.80(e) (such as name and email); commercial information (purchase records); biometric information (face and voice characteristics processed with your consent for the features described in Section 5); internet or other electronic network activity information (usage and device data); geolocation data (approximate, from IP); audio, electronic, visual or similar information (photos, videos, recordings); professional or employment-related information (business and brand information); inferences drawn from the above (such as preferences and style); and sensitive personal information (account credentials, biometric information processed with your consent, and the contents of messages you exchange with the AI Assistant and SMM Team). Sources, purposes and recipients are described in Sections 2, 3 and 7. We disclose categories of personal information to service providers for business purposes, and we may "share" identifiers, commercial information and internet activity information with advertising and attribution partners for cross-context behavioral advertising. We do not sell personal information, and we have no actual knowledge that we sell or share the personal information of consumers under 16. We use sensitive personal information only to provide the Service and for the purposes permitted by the CCPA regulations. We do not offer financial incentives in exchange for personal information. You may designate an authorized agent to make requests on your behalf; we will require proof of the agent's authority and may require you to verify your identity directly.

12.5 Residents of Ukraine. You have the rights provided by Article 8 of the Law of Ukraine "On Protection of Personal Data", including the right to know the sources of collection, the location of your personal data, the purpose of processing and the location or place of residence of the controller; to receive information about the conditions for granting access to your personal data; to access your personal data; to receive a response as to whether your personal data is processed and its content, no later than 30 calendar days from receipt of your request; to submit a reasoned demand to object to processing; to submit a reasoned demand to change or destroy your personal data if it is processed unlawfully or is inaccurate; to protection from unlawful processing and accidental loss, destruction or damage; to apply for protection of your rights to the Ukrainian Parliament Commissioner for Human Rights or to court; to apply legal remedies in case of violation of data protection legislation; to make reservations regarding the restriction of the right to process your personal data when giving consent; to withdraw consent to the processing of personal data; to know the mechanism of automatic processing of personal data; and to protection from an automated decision that has legal consequences for you.

12.6 Other countries. If you live elsewhere, you may have similar rights under your local law, and we will honor them to the extent required.

12.7 How to exercise your rights. Use the tools in the App (Settings > Personal Data) or email [email protected]. We may ask you to verify your identity, for example by responding from the email address associated with your account or by confirming details of your account or purchases, before acting on a request. We respond within one month (EU, EEA, UK), 45 days (US states) or 30 days (Ukraine), and we will tell you if we need more time as permitted by law. Requests are free of charge unless they are manifestly unfounded or excessive.

13. Children

The Service is intended for adults. We do not knowingly collect personal data from anyone under 18 (or under the age of majority in their country). If we learn that an account belongs to a person under 18, we will terminate it and delete the associated data. If you believe a person under 18 has provided us with personal data, contact [email protected]. Do not use face, voice or AI Character features with images or recordings of minors.

14. Changes to this Notice

We may update this Notice from time to time. The effective date at the top shows when it was last revised. If we make material changes, we will notify you in the App, on the Website or by email before they take effect, and where required by law we will ask for your consent. We encourage you to review this Notice periodically.

15. Contact and complaints

Questions, requests and complaints about personal data: [email protected], or by post to the address in the Company details block. Where we appoint a representative in the EU or the UK under Article 27 of the GDPR or the UK GDPR, or a data protection officer, we will publish their details in this Notice, and they may be contacted on data protection matters in addition to us. If you are not satisfied with our response, you may complain to the supervisory authority in your country (for the EU and EEA, your national data protection authority; for the UK, the ICO; for Ukraine, the Parliament Commissioner for Human Rights; for US states, your state attorney general).