Privacy

What we collect, why we collect it, and how we protect it.

A short, plain-language summary of how Aimprint Studio handles the account, brief, payment, and AI data you share with us — paired with the rights you have and the contact path to use them.

Data we collect

We collect only what we need to run the studio for you. Three buckets:

Account information. When you sign up, our auth provider stores your email address and display name; passwords are hashed by the provider and never reach our servers.

Brief inputs. The brand description, audience notes, style direction, references, and any attached files you submit are stored against your account — they are the work product we generate against and that you need to download later.

Payment metadata. Our payment processor returns a subscription identifier, the billed amount and currency, and the last four digits of the card you used. Card numbers and CVVs never touch our servers — those stay with the processor.

Cookies & analytics

A small set of cookies keeps you signed in and remembers your theme and locale preferences. We do not use advertising cookies, we do not run retargeting, and we do not sell browsing data to data brokers.

Google Analytics 4 is wired to give us an aggregate, non-identifying view of traffic. If your browser sends a Do-Not-Track signal, analytics is disabled on page load — the gate runs before the first hit is queued, so no event is ever sent for opted-out visitors.

AI processing

The brief inputs above are sent to our AI provider to generate the assets in your kit. Generated outputs carry provenance metadata inside the bundle so the AI origin is transparent without changing what the artwork looks like in market.

Your briefs are not used to train new models, and the AI provider sees only the brief content needed to produce the assets you requested — not your full account history or any unrelated profile data.

Third-party services
  • Payment processor (Stripe). Subscription IDs, billed amounts, and card last-four — handles all PCI-sensitive data.
  • AI provider. Receives brief content only, for the purpose of generating the assets you ordered.
  • Email proxy. Routes transactional mail (receipts, delivery notices, security alerts) so messages actually arrive.
  • Analytics (GA4). Aggregate, non-identifying traffic data; disabled automatically when Do-Not-Track is on.
Data retention

Accounts.Kept while active. On closure, deleted within 30 days, except records we're legally required to retain — tax invoices are kept for around 7 years, fraud-prevention logs for around 90 days.

Generated assets. Kept while your subscription is active. Once you download an asset, it remains yours; closing the account removes our copy on the schedule above.

Contact correspondence. Kept for 24 months so we have continuity when you come back, then anonymised.

Your rights

You can access the personal information we hold, correct anything that's wrong, delete your account and associated data, export a portable copy of your briefs and assets, and opt out of any non-essential processing.

Email aimprint-studio@polsia.app from the address on your account to exercise any of these. We respond within 30 days.

Changes to this policy

We update this page when our practices change. The “Last updated” date on the long-form Privacy Policy reflects the most recent revision. For material changes — anything that expands what we collect or how we use it — we email active account holders and give 30 days' notice before the change takes effect.

Contact

Questions, complaints, or data requests: aimprint-studio@polsia.app. We read every message.

Read the Terms of Service →

Read the long-form Privacy Policy →

We've written this in plain language because legalese helps no one. If anything is unclear, the contact line above reaches a person who can answer directly.