LEGAL SYSTEM

Privacy Policy

Last updated: July 22, 2026

1. Information We Collect

We collect information to provide high-quality AI-driven advertising assets to our clients. This includes:

  • Account Data: Email address and credentials provided during registration.
  • Access Registry Data: If you request access or register for our waitlist, we log your email address and request/approval status in our invitation database.
  • Media Assets: Product images, branding assets, and generated images/videos that you upload or produce using our service.
  • Usage Details & Telemetry: IP addresses, browser logs, device configurations, screen resolutions, and details of API execution times, strictly for security enforcement, error debugging, and rate limiting.

Information from Third Parties:

  • Authentication Providers: If you sign in via Google, GitHub, or other OAuth providers, we receive profile information (like email and name) from those services.
  • Payment Processors: Transaction status and billing details from our third-party payment processors (when billing features are active; we do not store or process full credit card numbers directly).

2. Cookies, Local Storage & Product Analytics (PostHog)

We use cookies, local storage, and third-party tracking services to manage your login sessions, secure our endpoints, and analyze platform performance.

  • Session Cookies: Placed by NextAuth.js or Clerk to maintain authenticated dashboard sessions.
  • Local Storage tokens: Used by Supabase Client SDK to manage database request authorization.
  • Product Analytics & Recording (PostHog): We use PostHog to analyze platform engagement (e.g., ad generation actions, clicks, and pageviews) and record visual sessions to diagnose user-interface failures. This is strictly opt-in and can be declined via the cookie consent banner.

Cookie Categories:

CategoryPurpose & ProviderDefault Status
Strictly NecessaryAuth session management (Supabase / NextAuth), CSRF security tokensAlways Active
Performance & AnalyticsProduct usage analytics, session recordings & click tracking (PostHog)Blocked by default (Opt-in required)
FunctionalUser preferences, UI layout state, theme & language settingsActive

You can manage cookie settings using our consent banner or by configuring your browser options. Disabling required authentication cookies will prevent log-in access to the dashboard.

3. How We Protect Your Data

Security is our priority. We employ industry-standard mechanisms to secure your data:

  • All user data is encrypted in transit using standard HTTPS and TLS 1.3 protocols.
  • Critical account credentials and secrets are encrypted at rest using industry-recognized cryptographic hashing algorithms (Bcrypt) and AES-256 cloud encryption.
  • Media processing relies on ephemeral sandboxed pipelines that clean up assets immediately post-generation.

4. AI Subprocessors & Infrastructure Partners

We do not sell, rent, or trade your personal information or media assets to third parties. To execute image and video generation requests, we securely share input parameters (such as uploaded product images, color profiles, and prompt instructions) with downstream AI partners, including:

  • Kie.AI & Google Gemini / Veo: Used for prompt synthesis, vision analysis, and video generation clip pipelines.
  • ByteDance (Seedance) & Kling AI: Downstream models for rendering advanced cinematic transitions and video animations.
  • Flux & Nano Banana: Used for high-fidelity product image synthesis and photo enhancements.
  • PostHog Inc.: Cloud product analytics and user session telemetry (opt-in only).
  • Supabase Inc. & Vercel Inc.: Cloud database storage, file storage infrastructure, and edge application hosting.

We contractually require that downstream processors do not store, distribute, or utilize your uploaded media assets or generated outcomes to train, adjust, or refine their public foundational models.

5. Legal Basis for Processing (GDPR Compliance)

For users in the European Economic Area (EEA), our legal basis for collecting and using the personal data described above depends on the context of the collection:

PurposeLegal Basis (GDPR)
Create and maintain user accountPerformance of a contract
Process payments and subscriptionsPerformance of a contract
Generate AI images and commercial videosPerformance of a contract
Detect, prevent, and debug platform errors or abuseLegitimate interests of the business
Product analytics and user experience recording (PostHog)Consent (User opt-in via banner)
Send product updates and announcementsLegitimate interests (with opt-out option)
Direct marketing communicationsConsent (user opt-in)

6. Data Storage & International Transfers

LiquidAds is hosted on cloud infrastructure in the United States. Your data is stored on servers provided by **Supabase** (running on AWS datacenters) and deployed via the **Vercel** edge hosting network.

If you access our Service from the EEA, United Kingdom, or Switzerland, please note that your information will be transferred to, stored, and processed in the United States. We ensure appropriate safeguards are in place through **Standard Contractual Clauses (SCCs)** approved by the European Commission, guaranteeing an equivalent level of protection for your personal information.

7. Data Retention, Breach Notification & Your Rights (GDPR & CCPA / CPRA)

We retain account data and generated media assets until you delete them or close your account. When you delete a generated asset or upload from your history dashboard, the system permanently purges the database records and deletes the physical files from our cloud storage buckets within 24 hours. Server execution logs and security rate-limiting data are automatically purged after 24 hours.

Data Breach Notification:

In the unlikely event of a security breach resulting in unauthorized access, alteration, or loss of your personal information, we will notify affected users and the relevant supervisory authorities within **72 hours** of discovering the incident, in compliance with GDPR regulations.

Your Privacy Rights (GDPR & CCPA):

Depending on your location, you hold the following statutory rights regarding your data:

  • Access & Portability (Subject Access Request): You can request a copy of all information and media assets stored in our database.
  • Rectification & Erasure ("Right to be Forgotten"): You can correct incomplete details or request the permanent erasure of your account, history, and generated outputs.
  • Withdrawal of Consent: You may revoke permission for analytics or downstream AI processing at any time.
  • CCPA "Do Not Sell or Share My Personal Information": LiquidADS does not sell your personal data to third parties. California residents have the right to opt-out of cross-context behavioral advertising and request data disclosures.
  • Non-Discrimination: We will never discriminate or alter service pricing because you exercised your statutory privacy rights.

We will respond to all verified privacy requests within **30 days**. To execute any of these rights, please adjust your account settings or contact our privacy team.

8. Children's Privacy (COPPA)

Our Service is not directed to individuals under the age of 13. We do not knowingly collect personal identifiable information from children under 13. If we discover that a child under 13 has provided us with personal data, we will immediately delete it from our servers.

9. Contact Information & Data Protection Officer

If you have questions about this Privacy Policy, your rights under GDPR or CCPA, or our data handling practices, please contact us:

Email: Photographygkreations@gmail.com