1. Introduction and Data Controller
This Privacy Policy explains how Photor.ai ("Photor.ai", "we", "us", or "our") collects, uses, shares, and protects personal information when you use https://photor.ai and our AI image generation, editing, enhancement, billing, support, and related services (the "Service").
Photor.ai is the data controller for the personal information we collect directly through the Service. For payment processing, Waffo Pancake acts as our payment processor and may also act as an independent controller for information it must process to complete payments, prevent fraud, comply with card network rules, and meet legal obligations.
2. Information We Collect
We collect information you provide directly, information generated when you use the Service, and information from service providers.
- Account information: email address, display name, avatar, login provider identifiers, account settings, subscription status, and credit balance.
- User content: prompts, uploaded images, reference images, generated images, edit instructions, output history, and other content you choose to submit or create.
- Billing records: product or plan purchased, checkout/session IDs, local order or request IDs, transaction status, amount, currency, tax information where applicable, renewal or cancellation status, refund status, and customer support records.
- Payment card data: card number, CVC, and full payment credentials are collected and processed by Waffo Pancake. We do not collect or store full card numbers or CVC on our servers.
- Usage and device data: IP address, browser type, device identifiers, operating system, pages viewed, feature usage, timestamps, generation job status, errors, logs, referral URLs, and approximate location derived from IP address.
- Communications: messages you send to support, refund requests, cancellation requests, survey responses, and any attachments you provide.
- Security and fraud data: login activity, payment risk signals, rate limit events, abuse reports, moderation results, and other data used to protect users, our Service, and payment systems.
3. How We Use Information
- Provide, operate, personalize, and improve the Service.
- Create and manage accounts, authenticate users, and maintain sessions.
- Process AI generation and editing jobs, store history, calculate credit usage, and deliver outputs.
- Process subscriptions, one-time credit purchases, renewals, cancellations, refunds, chargebacks, invoices, and payment status checks through Waffo Pancake.
- Provide customer support, respond to legal, privacy, billing, and security requests, and communicate service notices.
- Detect, investigate, and prevent fraud, abuse, policy violations, security incidents, and unauthorized access.
- Monitor service performance, debug errors, analyze product usage, and develop new features.
- Comply with legal, tax, accounting, sanctions, consumer protection, payment network, and regulatory obligations.
4. Legal Bases for Processing
Where laws such as the GDPR or UK GDPR apply, we process personal information under the following legal bases:
- Contract: to provide the Service, manage accounts, deliver paid features, and process purchases.
- Legitimate interests: to secure the Service, prevent abuse, improve features, respond to support requests, and maintain business records.
- Consent: where we ask for consent, such as optional marketing communications or optional use of content for model improvement.
- Legal obligation: to comply with tax, accounting, consumer protection, payment, and lawful request obligations.
5. Payment Processing by Waffo Pancake
Paid subscriptions and one-time credit purchases are processed by Waffo Pancake. During checkout, Waffo Pancake may collect and process payment method details, billing details, device and risk signals, and transaction information needed to authorize, settle, refund, dispute, and secure payments.
- We send Waffo Pancake information needed to create and manage checkout sessions, such as product ID, app ID, customer email, currency, success URL, checkout/session ID, and local request/order tracking ID.
- Waffo Pancake returns payment status, checkout/session IDs, transaction status, and related records so we can activate credits, subscriptions, cancellations, or refunds.
- Full card numbers, CVC, and sensitive payment authentication data are handled by Waffo Pancake and are not stored by Photor.ai.
- Waffo Pancake may process payment data for fraud prevention, card network compliance, chargeback handling, tax, accounting, and legal compliance.
6. AI Content and Model Processing
To provide image generation and editing features, your prompts, uploaded images, and generated outputs may be processed by our systems and by third-party AI infrastructure providers. We use this processing to generate results, moderate unsafe content, troubleshoot issues, calculate credit usage, and maintain service quality.
We will not use your private uploaded content to train AI models without your explicit consent. Some third-party model providers may process content under their own security and retention practices when needed to deliver the requested feature.
7. How We Share Information
We do not sell your personal information. We share information only as needed to provide, secure, bill, support, and improve the Service, or as required by law.
- Payment processor: Waffo Pancake for checkout, subscriptions, payment status, cancellations, refunds, fraud prevention, and chargebacks.
- Authentication providers: third-party login providers such as Google when you choose to sign in with them.
- Cloud, storage, and infrastructure providers: hosting, databases, file storage, content delivery, logging, and security monitoring.
- AI model and processing providers: to perform requested AI generation, editing, moderation, and related processing.
- Support and operations providers: tools we use to answer support requests, manage incidents, and communicate service notices.
- Legal and safety: regulators, courts, law enforcement, professional advisers, or other parties when necessary to comply with law or protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
8. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to keep you signed in, remember preferences, secure sessions, measure performance, understand feature usage, and prevent abuse. You can control cookies through your browser settings, but disabling some cookies may prevent account or checkout features from working correctly.
9. Data Retention
- Account data is retained while your account is active and for a reasonable period after deletion to complete security, backup, legal, and dispute processes.
- Billing, transaction, tax, refund, and chargeback records may be retained for up to 7 years or longer if required by law.
- Support communications are generally retained for up to 3 years unless a longer period is needed for legal, safety, or dispute reasons.
- Security logs, fraud signals, and abuse prevention records are generally retained for up to 24 months, unless needed longer for investigation or legal compliance.
- User content and generated history may be deleted or anonymized after account deletion, subject to backups, legal obligations, fraud prevention, and unresolved disputes.
10. Data Security
We use reasonable technical and organizational safeguards designed to protect personal information, including encrypted transport, access controls, authentication, logging, backup controls, and least-privilege access. Payment card information is handled by Waffo Pancake using payment industry security controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. International Data Transfers
We and our service providers may process personal information in countries other than where you live. Where required, we rely on appropriate safeguards such as standard contractual clauses, adequacy decisions, contractual commitments, and other lawful transfer mechanisms.
12. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal information, withdraw consent, opt out of certain processing, and lodge a complaint with a supervisory authority.
To make a request, contact us at vip.photor.ai@gmail.com from the email associated with your account. We may need to verify your identity before responding. We aim to respond within 30 days unless a different period is required or permitted by law.
13. Marketing Communications
We may send service-related emails such as receipts, account notices, security alerts, payment status updates, renewal notices, cancellation confirmations, and policy updates. These are not optional while you use the Service. If we send marketing emails, you may unsubscribe using the link in the email or by contacting us.
14. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.
15. Third-Party Links and Services
The Service may link to third-party websites, checkout pages, documentation, or services. Their privacy practices are governed by their own policies, not this Privacy Policy. Please review their policies before providing information to them.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by website notice, in-product notice, or email where practical or required by law. The "Last Updated" date above shows when this Privacy Policy was last revised.
17. Contact Us
For privacy requests, billing privacy questions, security reports, or other questions about this Privacy Policy, contact: