Privacy Policy
- Version
- 2.0.0-preliminary
- Effective
- Last updated
This is a preliminary version. It replaces an earlier document that described things imai.ge does not do. It is accurate about how the Service works today, but some sections are still short of detail and none of it has been reviewed by a lawyer yet. A reviewed version will follow. Questions: support@imai.ge.
1. Who we are and what this policy covers
The controller of that data is:
MASP Software B.V. Kerkstraat 19g 3581 RA Utrecht The Netherlands
Chamber of Commerce (KvK) number: 93109806 VAT (BTW) number: NL866279659B01 Privacy contact: privacy@imai.ge
Write to privacy@imai.ge about anything in this policy, including the requests described in your rights.
We have no Data Protection Officer
No Data Protection Officer is appointed. Data-protection questions go to privacy@imai.ge.
What this policy covers
The Service — our website, the web app and our mobile apps — and everything held for your Account: your Content, and the record of what you have bought and spent.
Capitalised words have the meanings given in our Terms of Service.
What this policy does not cover
Paying us. Credits and Subscriptions are bought through a Store, which is the seller and handles the payment under its own privacy policy, not this one. What reaches us from a Store is set out in what we collect.
Cookies and similar storage, which are covered by our Cookie Policy.
Deleting your Account is covered here in deleting it, and how long we keep it, and step by step at /account-deletion.
If you are not satisfied with how we handle your data, your rights, and complaints explains where to take it.
2. What we collect, and what we derive
What you give us
- Your Account — email address, first and last name, display name, username, the tokens we email you to confirm your address or sign you in, and the link to another service if you sign in through one.
- Uploads — the photographs you supply to train a Character model, and the images you supply as an input to a Generation.
- Prompts, and the settings recorded with each Generation.
- What you tell us about a Character — a subject type, and an age and ethnicity stored against the Character and its Character model.
- Tags you apply to your files.
You can sign in with an email address and password, with Google, or with Apple. Signing in with Google or Apple gives us an identifier for you at that service, your email address and your name — nothing else, and no access to anything else you hold there.
Your device
We use no crash reporting, no advertising tools and nothing that follows you between sites. There is no product analytics in the app at all. Three things are recorded, and all three are worth naming:
- A count of visits to www.imai.ge, our marketing pages — how many people arrive, where from, and which country and browser. It is run for us by Cloudflare, it puts nothing on your device, and it does not identify you or recognise you on a later visit. It is not used on the app.
- Web-server logs, which include the IP address of the device making each request. They rotate automatically as they fill, are not organised by user and are not analysed.
- App version reports. Our mobile apps update themselves, and to know which update to send, the app reports which version it is running, on which platform and operating-system version, together with an identifier the updater generates for the device. This is not connected to your Account, it goes to our own servers and not to the updater’s makers, and old reports are discarded automatically.
What the Service produces
Outputs — the images and video a Generation produces, including any audio generated with a video — and Character models, trained on the photographs you upload for a Character.
We train one thing: the Character model you ask for, for your Account, from your photographs. We do not use your Content to train, fine-tune or improve any model of our own.
What we derive from your photographs
Uploading an image also produces information you did not give us:
- Whether a person is present, and their apparent age. Every Upload is analysed by a model estimating this; images that appear to show a child are rejected, and the result is recorded against the Upload.
- A fingerprint used for child-safety checking, which cannot be turned back into the image — see checking uploads, and child safety.
- The Character model itself, learned from your photographs and able to reproduce the appearance of their subject.
We do not use any of this to identify you, to recognise you in other images, or to match you against anyone else.
Payments
We never receive your card or bank details. Everything is bought through a Store, which takes the payment. We hold a reference from the Store so a purchase can be matched to your Account, and the record of Credits granted, spent and deducted.
3. Why we use it, and our legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your Account | So you can use the Service | Performance of our contract with you — Art. 6(1)(b) |
| Store your Content | So the Service works and it is there when you return | Performance of our contract — Art. 6(1)(b) |
| Train a Character model you asked for | To produce Generations that show your Character | Performance of our contract — Art. 6(1)(b) [see the flag below] |
| Produce Generations | The core of the Service | Performance of our contract — Art. 6(1)(b) |
| Take payment and keep the Credit ledger | So you can buy and spend Credits | Performance of our contract — Art. 6(1)(b) |
| Keep financial records for 10 years | Required of us by tax and accounting law | Legal obligation — Art. 6(1)(c), with Art. 17(3)(b) against erasure |
| Keep records for a dispute or chargeback | To establish or defend a legal claim | Legitimate interests — Art. 6(1)(f), with Art. 17(3)(e) against erasure |
| Check uploads for child sexual abuse material and for images of children | To keep this material off the Service and to meet our legal duties | Being confirmed with our advisers |
| Suspend accounts and keep evidence after a match | To act on the material and preserve it for the authorities | Legal claims — Art. 17(3)(e) |
What we do not do
We do not use your personal data to train models of our own — see what we collect, and what we derive. We do not profile you for advertising, and we do not make decisions about you by automated means that produce legal effects for you.
4. Who we share it with, and where it goes
We do not sell your personal data and we do not share it for advertising. We share it only with the companies that make the Service work, and only so far as they need it.
| Who | What they receive | Why |
|---|---|---|
| Runware, Replicate | The Content a Generation or a training needs | To train models and produce Generations |
| Cloudflare | Your Content | To store it |
| Microsoft | A fingerprint of an Upload, never the image itself | To check it against known child sexual abuse material |
| Apple, Google | Your purchase, and a reference id | To take payment and meet their own tax obligations |
| RevenueCat | A reference id generated for it, and what your Subscription entitles you to | To keep your plan in step wherever you use the Service |
If this list changes we update this policy. Ask us at privacy@imai.ge if you want to know who handled something specific.
We also share personal data where we are legally required to — with a court or a competent authority acting under a valid order. If our business were sold or reorganised, personal data could transfer with it.
Where it is stored, and where it is processed
These are different, and the difference matters. Your Content is stored in the Netherlands — files in Amsterdam, and the database on our own server. But generating an image or training a Character means sending the material to the companies that run the models, and they process in the United States, and in Germany and Romania. So your photographs are stored in the EU and sent outside it to be processed.
The child-safety check stays in the EU, and only the fingerprint is sent, never the image.
5. Deleting it, and how long we keep it
Deleting
You can delete anything held for your Account at any time, from the app. What you delete goes to Trash and stays recoverable for 30 days, unless you empty it sooner. After that it is removed automatically.
Deleting your Account — from your account settings, or by writing to privacy@imai.ge — ends your sessions immediately and makes the Account inaccessible. For 30 days you can change your mind by signing in again. After that we erase everything held for your Account: the content you gave us, the content the Service made for you, and the personal details on the Account itself. There is no way to recover it. Step-by-step instructions are at /account-deletion.
How long we keep it
| What we hold | How long | Why |
|---|---|---|
| Your Content | Until 30 days after you delete it, or your Account is erased | To provide the Service to you |
| Your Account details | Until your Account is erased | To operate your Account |
| Moderation results on your Uploads | Erased with your Account | So the safety checks can run |
| What you bought, what Credits you were granted and spent | Ten years from the end of the accounting year the transaction falls in | Tax and accounting law, and the window for disputing a payment |
| The stripped-down Account record those payment records attach to | As long as the payment records | The records would not be readable without it |
| Child-safety incident records and material preserved with them | Until the matter closes, then five years | Legal duty — see checking uploads, and child safety |
| A one-way code derived from a blocked account’s email address | Until the matter closes, then five years | So a blocked account cannot simply be made again |
We rely on Article 17(3)(b) of the GDPR for the tax and accounting records and Article 17(3)(e) for the period a payment can still be disputed.
The record that survives erasure is pseudonymised, not anonymised — still linked to a payment reference, so still your personal data.
What we cannot reach
One copy at our inference provider. What we send the companies that run the models does not persist there — with one exception. The model trained for your Character has to stay with the provider that applies it, and that provider gives us no interface to delete it, so removal is a request rather than an action. That copy stays locked to our own provider account: not published, not searchable, not usable by other users or the public. We cannot compel its deletion.
The Stores’ records. Apple and Google keep their own under their own legal obligations. Deleting your Account does not delete those.
6. Checking uploads, and child safety
Every image you upload is checked automatically before it can be used. The checks look for known child sexual abuse material, and for whether the image appears to show a child.
What is checked, and how
A check against known material. Your image is turned, on our own systems, into a fingerprint that cannot be turned back into it. Only that fingerprint leaves us, to a matching service in the EU that compares it against fingerprints of known child sexual abuse material.
Age and person-presence estimation. Models estimate whether a person appears in the image, and roughly how old that person looks. Images that appear to show a child are rejected. The estimate is kept on a moderation record attached to the upload — see what we collect, and what we derive.
If a check cannot complete, the upload is treated as not having passed.
If an image matches
A match is handled as block, preserve and alert — never block and delete.
- The upload is blocked before it is stored anywhere it could be served, and before a thumbnail is made from it.
- A copy is preserved as evidence in a separate write-once store, filed by the content itself rather than under your account, so the sweep that clears your files when an account is deleted does not reach it.
- The account is suspended, and an identifier derived from the email address is kept so that the same address cannot be used to register again. That record does not point at your account, and it survives the account’s deletion.
- Deletion of that account is paused entirely while the matter is open. Not partly, and not for some categories only — nothing is erased until the hold is lifted. See deleting it, and how long we keep it.
- A person is alerted to look at it.
Child safety contact
For anything concerning child safety, write to trust-safety@imai.ge.
Our child-safety standards are documented internally. We make them available to authorities and to the app stores on request.
7. Your rights, and complaints
Write to privacy@imai.ge, saying which right you are using and what you want. We may need to check who you are first. You can start deleting your Account yourself, at the bottom of your account settings; for everything else, write to us.
- Access — a copy of the personal data we hold about you, and how we use it. That includes who has received it: if you ask, we will name the specific companies, not only the kind of company.
- Rectification — data that is wrong or incomplete corrected or completed.
- Erasure — your personal data deleted. Deleting your Account starts that.
- Restriction — a pause on how we use your data while something about it is resolved.
- Portability — a machine-readable copy of data you gave us, or its transfer to another provider where that is technically possible.
- Objection — to processing we carry out on the basis of a legitimate interest. We stop unless there are compelling grounds that override you.
Which processing each right covers depends on its legal basis — see why we use it and our legal basis.
Erasure has limits, and you should know them before you ask. Four things survive: the financial records we must keep for ten years, an open child-safety case (which pauses erasure entirely), one copy of a Character model at a provider we cannot compel, and your payment provider’s own records. All four are in deleting it, and how long we keep it.
Automated checks
Uploads are checked automatically and some are refused without a person seeing them. If a decision goes against you, write to support@imai.ge. Data-protection requests still go to privacy@imai.ge.
Complaints
If you are unhappy with how we handle your personal data, tell us at privacy@imai.ge — You do not have to come to us first, and doing so takes nothing away from the rights below.
You can complain to a data protection supervisory authority. We are established in the Netherlands, so ours is the Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl, or Postbus 93374, 2509 AJ Den Haag. You can also complain to the authority where you live, where you work, or where you think the problem happened. You can also go to court, and complaining to an authority does not stop you.
8. People under 18
imai.ge is for adults — see the Terms of Service. We do not check your age, so we hold no record of how old you are.
We do not seek personal data from anyone under 18. If you believe a person under 18 has an account with us, write to privacy@imai.ge and tell us. When we learn that an account holder is under 18 we close the account and delete the content in it.
Age estimation runs on the people shown in uploaded images, not on you — see checking uploads, and child safety.
9. Security
- Access to your account is through a signed-in session. When you ask us to delete your account, every live session ends at once, so anything still signed in loses access immediately.
- Your files are kept in a storage area of their own, keyed to your account and separate from other users’ files. They are delivered to your device through links we generate for your request, not from a public address.
- When your account is erased, your password is made permanently unusable, and your email address and name are removed from the account record. What is erased and what is kept is set out in deleting it, and how long we keep it.
- Material quarantined under our child-safety process is held separately — see checking uploads, and child safety.
Where your data is stored is set out in who we share it with, and where it goes.
What we do not claim
We hold no security certification and publish no audit or test result. Nothing in this policy states an encryption standard, and nothing here should be read as promising one. No online service can be made completely secure.
10. Changes to this policy
We update this policy when what we do with your data changes.
Why we would change it. We change this policy when the service changes, when the providers that handle data for us change, or when the law changes.
Every version is dated. Each version of this policy carries a version number and an effective date at the top. A version applies from its effective date and does not change what we did with your data before it. This page always shows the current version, and earlier versions stay available.
Small changes. Corrections, clarifications and changes we are required by law to make take effect when we publish them.
Material changes. We tell you at least 30 days before a material change takes effect. A change is material if it changes what we collect, what we use it for, who we share it with, where it is processed, or how long we keep it.
We tell you the same way we tell you about a change to the Terms of Service: by showing a notice in the app the next time you open it, and by publishing the new version here with a new effective date.
Being told is not the same as agreeing. Accepting a change to the Terms of Service is dealt with in those terms. Consent under this policy is a separate thing: where we rely on your consent for something, we ask you for it, and continuing to use imai.ge is not it.
If you do not want a change to apply to you. You can exercise your rights at any time, including asking us to delete your data — see your rights and deleting it, and how long we keep it.
If you have a question about a change, write to us at privacy@imai.ge. Our full contact
details are in who we are and scope.