Privacy Policy

Visxy Last Updated: September 17, 2026

1. Introduction

This Privacy Policy explains how Visxy ("we", "us", "our") collects, uses, and protects your information when you use the Service.

It is one of three documents that govern the Service, alongside our Terms of Service and our Refund Policy. This one covers data; those two cover the agreement and your money.

The Service is currently provided through our website at visxy.com. A mobile application is in development and has not been released; references below to app stores or in-app purchases describe how those channels would work once that application exists.

1.1 Who is responsible for your data

Visxy is operated from the Republic of Turkey and is the data controller for the personal data described in this Policy — meaning we decide why and how it is processed.

For any question about this Policy or about your data, contact support@visxy.com.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and/or username and authentication data via our authentication provider (Supabase Auth), including information from Google or Apple if you sign in using those services.

2.2 Usage Data

We collect data about how you interact with the Service, such as prompts viewed, copied, and favorited. Page and session counts, and how long public pages take to become usable on your device, are measured by Vercel Web Analytics and Vercel Speed Insights (no cookie, no identifier — see Sections 3.1, 4, and 5). If you accept analytics cookies, Google Analytics also records pages visited and similar usage events.

2.3 Subscription & Payment Information

If you buy a plan or a credit pack:

  • Web: Payment is processed by Paddle (acting as our Merchant of Record). We receive limited billing information (e.g., subscription status) but do not store your full card details.
  • iOS / Android, once a mobile app is released: Payment would be processed by Apple or Google. We would receive subscription status information from those platforms, but never your payment details.

Refund and dispute records. If you ask for a refund, we keep a record of the request, what it concerned, and what we decided — together with the correspondence it took. Where a refund is made, the purchase record is marked as refunded rather than deleted, because the record of a period is what makes its licence code verifiable (Section 2.4). The same applies to a payment dispute or chargeback raised through your bank or an app store. Our Refund Policy explains when a refund is due and how to ask for one.

2.4 License & Copy Records

If you hold or have held a Premium subscription, we generate and store license and usage records associated with your account:

  • License codes: for each active Premium period, we generate a unique license code (VISXY-XXXX-XXXX-XXXX) and store it, along with the plan, start and end dates, and status, as part of your subscription history. These records are retained permanently as part of your account (subject to account deletion — see Section 7).
  • Copy records: prompts you copy while a Premium period is active are recorded under that period's license code, so you can review the prompts you used during that period. Copies made outside an active Premium period are recorded without a license association.

License codes may be verified through our public verification page (visxy.com/license), which exposes only the plan, period, and status of a code — never the identity of the account holder or any personal information. See our Terms of Service, Section 6.3, for how these records relate to your usage rights.

2.5 AI Generator Data

If you use the AI Generator, we collect and store:

  • The prompts you write, and the settings you chose (model, size, duration, and so on);
  • Reference files you upload, until you delete them;
  • The media you generate, stored privately against your account;
  • Generation records — which model ran, whether it succeeded, any error the model returned, and the credits held and charged;
  • Credit ledger entries — every grant, hold, charge, refund and expiry, kept as the audit trail behind your balance;
  • Credit pack purchases — which pack, when, where it was bought (web, iOS or Android), the payment's transaction identifier, the credits it granted, what is left of them and when they end;
  • Credits we grant you, with a short internal note of why and which member of staff added them. The note is not shown in your account, but it is part of the data you can ask us for (Section 8);
  • Policy-refusal records, where a model provider refused a prompt. These are counted to detect repeated misuse, as described in the Terms of Service, Section 7A.

What leaves Visxy. Your prompt text and any reference files you attach are transmitted to the model provider that currently serves your selected model (fal.ai, Replicate, or kie.ai). They are processed under that provider's own privacy policy and content policy. We do not transmit your account identity, email address, or payment details to them. kie.ai is a reseller of other model vendors; a generation it runs may also be processed by the upstream vendor it uses to fulfil the request, under that vendor's own terms.

Generated media never leaves as public content. It has no public address, is not indexed, is not shown to other users, and is not used to train any model by us. Every view is an individually authorised, short-lived link.

2.9 AI Tools Data

AI Tools are covered separately because most of them collect nothing at all.

Tools that run in your browser. Your text and any file you open are processed on your own device. They are not uploaded, not transmitted, and not stored by us — we never receive them, so there is nothing for us to keep, disclose, or delete.

What we do receive is a count: that a given tool was used, on a given date. It is stored as one row per tool per day, with no user identifier and no content, so it cannot be traced to you or to what you were working on. We use it to tell which tools are worth keeping.

If you have consented to analytics cookies, an event recording the tool's name and whether the path was free or paid is also sent to Google Analytics. It carries none of your content. Section 4 covers analytics.

Tools with a free daily allowance. A few free paths run on a server. For these we store a counter of how many times the allowance has been used today:

  • Signed in, it is counted against your account;
  • Signed out, it is counted against a random identifier stored in your own browser. It is not linked to any account and tells us nothing about who you are. Clearing your browser storage clears it.

The counter holds a number and a date. It does not hold what you submitted.

Tools with a paid path. These run on the AI Generator's pipeline, and Section 2.5 applies to them without change: your input is transmitted to the model provider serving that model, the result is stored privately against your account, and the credit movements are recorded.

What your browser stores for itself. Some conveniences are kept in your browser and never sent to us: the tools you opened most recently, the filters you last chose, whether you have seen the short introduction, and — where a tool offers it — references to your own recent results. You can clear all of it through your browser's site-data controls. Losing it costs you a convenience and nothing else.

2.10 Creator Partnership data

If you apply to, or take part in, the Creator Partnership Program (Terms of Service, Section 6D):

  • Your application — the display name you publish under, the links to your channels, the channel type, your audience size band, how you intend to promote Visxy, your country, any note you add, your confirmation that you are 18 or over, and when you accepted the Creator Partnership Agreement and which version of it. We also record our decision and, for a rejection, the reason we show you. Our staff may add an internal note that is not shown to you; you may request it under Section 8.
  • Your partnership — your referral code and any shorter link name we assign, its status, any commission rate set for your partnership, and each change to it — approval, suspension, ending, a rate or link-name change or a balance correction — with when, the reason and which member of staff made it.
  • Devices you used on your own link — if you open your own referral link, we keep that device's random identifier for 180 days, so that a referral later made from the same device can be flagged for our review as possible self-referral.
  • Your balance — every commission, reversal, spend, adjustment and forfeiture, with the date, the amount in US dollars and, for a commission, the type of product that earned it. For a commission we also keep the payment processor's transaction reference, so that a refund of that payment can reverse it.
  • Traffic statistics — daily counts of how many times your link was opened, by how many distinct devices, how many sign-ups and first purchases followed, and how many referrals expired unused.

We do not collect bank details, tax identification numbers, identity documents, subscriber lists or passwords for the Program.

If you opened a partner's link. We record the click against a random identifier for your device. While the 30-day referral window is open we keep one record per partner and device: the partner, the time you arrived, the page you landed on (without its query string) and whether it was the website or the app. We do not store your IP address or any hash of it. On the website, the identifier is remembered in a first-party cookie and browser storage only if you have accepted cookies; otherwise nothing is stored on your device, and if you sign up during that visit the identifier travels with the sign-up itself — in the address Google or Apple returns you to, or in your new account's details, from which it is removed once used. In the app it is kept in secure on-device storage after you open a partner's link. If you sign up or sign in during the window, we link the referral to your account. We never give the partner your name, email address, account or payment details — they see aggregated counts, the day (never the time) a visit to their link began and the page it landed on, and, if you make a first purchase, its day, the type of product, whether it was on the website or in the app, and the commission. So that we can review possible abuse, a referral is flagged when your email address shares a domain with the partner's (other than common email providers), which is only a prompt for a person to look. A referral made from a device the partner used on their own link is treated as the partner referring themselves, so the partner earns nothing from it. Neither changes anything about your account, your purchase or your price, and nothing about you is decided automatically. When a window ends without a purchase, the per-device record is deleted and only an anonymous daily count remains.

Visxy operates a comment-triggered marketing automation feature on its own Instagram Business account and Facebook Page, using the Meta Graph API. In connection with this feature, the following data is processed:

  • Comment content and commenter identifiers: When a comment on a tracked post matches a trigger keyword, the comment text and the commenter's Meta user identifier are ingested and stored to classify the comment and enforce deduplication rules.
  • DM delivery logs: A minimal log entry (commenter identifier, timestamp, and associated post/comment reference) is stored upon each successfully sent DM, solely to enforce the 1 DM per user per 24-hour deduplication rule and applicable rate limits.

We do not collect or store Meta user profile information (name, profile photo, follower data, or other profile fields) beyond the opaque user identifier needed for deduplication. This data is not linked to any Visxy account and is not used for advertising profiling or shared with any third parties.

2.8 Account Enforcement Records

If we suspend your account (Terms of Service, Section 11.2), we record:

  • when the suspension started, and when it ends if it is time-limited;
  • the reason shown to you — the same text you see in the Service and receive by email;
  • an internal note explaining the decision, written for our operators;
  • which administrator applied it, and which lifted it;
  • when it was lifted, and any note on that.

These records are the account's enforcement history. They are what lets us review a decision we are asked to reconsider, answer a complaint about it, and defend it if it is challenged. The internal note is not displayed to you inside the Service, but it is personal data about you: you may request a copy of it as described in Section 8.

If you ask us to delete your account, we record the date of the request and the date deletion is scheduled to run, so that the recovery window works and so we can show when a request was made.

2.11 Email subscription data

If you consent to marketing email, we record your email address, whether you are subscribed, when and where you consented (for example: from account settings, from the app, or from the form on our website), the frequency you chose, and when you unsubscribed if you did. We keep the record of a withdrawn consent alongside the consent it withdrew, because the pair is what evidences that we were permitted to write to you at the time and stopped when you asked.

You can subscribe without an account. If you do, we hold your email address and the confirmation state of that subscription, and nothing else — no profile, no account, no browsing history tied to it. We send one message asking you to confirm, and an address that is never confirmed is not subscribed and receives nothing further. Subscribing this way does not create an account. If you later create an account with the same address, we link the two so you do not appear on the list twice; if the two records disagree about whether you want marketing email, the unsubscribe wins.

Every marketing message carries a link that unsubscribes you without signing in. Section 3.1 gives the legal basis, Section 5 names the provider that delivers it, and Section 6 says how long we keep it.

2.7 Device & Technical Data

We may automatically collect device information, IP address, browser type, and operating system for security and analytics purposes. Additionally:

  • Cloudflare processes network traffic (including IP addresses and HTTP request metadata) as part of our CDN, DDoS protection, and security infrastructure. This processing occurs at the network level before requests reach our servers.
  • Vercel measures public pages with Web Analytics and Speed Insights: route, URL, device and browser type, country, a coarse network-speed class, and (for Speed Insights) the web-vital value and a CSS selector of the measured element. No cookie is set and no identifier is stored, so a visit cannot be tied to your account or reconstructed as a session across pages.
  • Google reCAPTCHA may collect behavioral signals, IP address, and browser/device information to distinguish human users from bots. This data is processed by Google under Google's Privacy Policy and Terms of Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Service (account management, favorites, history);
  • Process subscription payments and manage premium access;
  • Generate license codes, maintain license and copy records for your Premium periods, and enable public verification of license codes (see Section 2.4);
  • Display sponsored placements to Guest and Free Account users, and count impressions and clicks in aggregate so sponsors can be reported to (Premium subscribers do not see them);
  • Analyze usage trends to improve the Service (Vercel Web Analytics and Speed Insights on every public visit; Google Analytics only if you accept analytics cookies);
  • Communicate with you (e.g., account verification, security notices, support);
  • Detect and prevent fraud or abuse;
  • Enforce our Terms of Service — including suspending an account, recording why, and reviewing that decision if you contest it (see Section 2.8);
  • Operate our comment-triggered marketing automation on Instagram and Facebook, including sending automated DMs and public replies to users who comment trigger keywords on tracked posts, deduplicating messages, and enforcing rate limits (see Section 2.6);
  • Operate the Creator Partnership Program — reviewing applications, attributing referrals, calculating and reversing commissions, keeping each partner's balance, and detecting self-referral and fraudulent traffic (see Section 2.10).

Where the GDPR, the UK GDPR, or Turkey's KVKK applies to you, we rely on the following bases. "Legitimate interests" means we have weighed our interest against your rights and concluded the processing is proportionate; you may object to any of it as described in Section 8.

What we processWhyLegal basis
Account and authentication dataTo create and run your accountPerformance of a contract
Subscription and billing statusTo give you the access you paid forPerformance of a contract
Transaction and invoice recordsTax, accounting and audit obligationsLegal obligation
Generator prompts, reference files, generated mediaTo run the generation you asked for and keep the result available to youPerformance of a contract
Credit ledger and generation recordsTo operate your balance, and to show you and us an accurate record of what was chargedPerformance of a contract; legitimate interests (accurate billing records)
License and copy recordsTo evidence the commercial rights attached to a Premium periodPerformance of a contract
Usage analytics (Google Analytics)To understand how the Service is used and improve itConsent, given through the cookie banner
Cookieless site measurement (Vercel Web Analytics and Speed Insights)To count public visits and to see how fast the Service is for real visitorsLegitimate interests (running and improving the Service)
Sponsored placement impression and click countsTo report performance to a sponsor, in aggregateLegitimate interests (running a funded free tier)
Security, fraud prevention, rate limiting, bot protectionTo keep the Service and its users safeLegitimate interests; legal obligation where applicable
Policy-refusal records and Generator abuse thresholdsTo detect and stop repeated misuseLegitimate interests; legal obligation where content law requires it
Account enforcement records (suspensions)To enforce the Terms, to review a suspension we are asked to reconsider, and to defend the decision if it is challengedLegitimate interests; establishment, exercise or defence of legal claims
Deletion request and scheduleTo operate the recovery window and evidence when a request was madePerformance of a contract; legal obligation (responding to an erasure request)
Error monitoring (Sentry)To find and fix faultsLegitimate interests
Transactional emailTo send account, security and billing messagesPerformance of a contract
Marketing email, and the record of your consent to itTo send product news, new prompts and models, and offers — and to evidence that you asked for themConsent, given separately from creating an account and withdrawable at any time
Marketing delivery and engagement events (delivered, bounced, complained, opened, clicked)To know a message arrived, to stop mailing an address that rejects us, and to see whether what we send is worth sendingLegitimate interests (deliverability and sender reputation); consent for the underlying send
Suppression list (addresses that hard-bounced or reported us as spam)To make sure we never write to that address againLegitimate interests; legal obligation (honouring an objection)
Meta comment automationTo operate our own social accountsLegitimate interests
Creator Partnership application and partnership recordsTo decide an application and run the partnership you asked to joinPerformance of a contract (the Creator Partnership Agreement)
Partnership balance, commissions and their payment referencesTo credit, reverse and spend a balance accurately, and to evidence itPerformance of a contract; legitimate interests (accurate records); legal obligation where tax or accounting law applies
Referral marker, per-device referral record and daily traffic countsTo attribute a referral to the partner whose link you opened, and to detect fraudulent clicksLegitimate interests (running a referral program fairly), balanced by keeping the record for the referral window only and never telling the partner who you are
Reporting suspected child sexual abuse materialBecause the law requires itLegal obligation; substantial public interest

Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.

3.2 Automated decision-making

One process in the Service makes a decision about you without a person reviewing it first. If a model provider refuses your prompts for policy reasons repeatedly, and you cross a threshold we set, your access to the AI Generator is suspended automatically. The rest of your account is unaffected, and the Terms of Service describe the conduct that leads to it in Section 7A.

Suspending your account itself is not automated. A person decides it, a person writes the reason you are shown, and a person reviews it if you contest it. The automatic process described here suspends Generator access only.

We use this because the alternative — reviewing every refusal by hand — is not workable and would mean reading prompts we would rather not read. If it happens to you, you may contest it: write to support@visxy.com and a person will review the decision, hear your explanation, and reinstate access where the suspension was wrong. No other feature of the Service makes an automated decision with a significant effect on you, and we do not profile you for advertising.

3.3 Who inside Visxy can see your data

Access is limited to the people who need it to run the Service. Administrators can reach stored account and generation data — including prompts you wrote and media you generated — through our administrative tools and database. We access that material only where there is a reason to: supporting a request you made, investigating abuse or a security incident, resolving a billing dispute, or meeting a legal obligation. We do not read prompts or view generated media for curiosity, for training, or to build any public or promotional content.

4. Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

  • Essential cookies: required for authentication and core functionality (e.g., keeping you logged in).
  • Analytics cookies: Google Analytics, used to understand usage patterns and improve the Service.
  • Cookieless site measurement (Vercel): Web Analytics and Speed Insights run on every public page. They set no cookie, store no identifier, and are not switched off by declining the cookie banner. Section 5 describes what they send.
  • Security cookies: Google reCAPTCHA uses cookies and behavioral signals to detect and prevent automated abuse when bot protection is enabled. reCAPTCHA may run on account sign-in, sign-up, password reset, and the contact form. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service (see also Section 5). We disclose this in our legal documents rather than repeating it on every form.
  • Local storage used by AI Tools: the free tools keep a few preferences in your browser — recently opened tools, your last filter choices, a flag recording that you have seen the introduction, and, for a guest, the identifier used to count a daily free allowance. These are stored on your device, are not cookies sent with every request, and are not used to profile you. Section 2.9 describes each of them.
  • Creator Partnership referral marker: if you open a partner's referral link and have accepted cookies, we set a first-party cookie, with a browser-storage copy, recording which link you opened, when, and a random identifier for your device; if you decline cookies, we store nothing and delete a copy already stored. The app keeps the same in secure on-device storage after you open a partner's link. It exists only to attribute a referral to that partner, lasts for the 30-day referral window, is not shared with the partner or any advertising network, and is not used to profile you. Section 2.10 describes it.
  • Sponsored placements: the promotional slots shown to Guest and Free Account users are sold and served by us directly — they are not a third-party ad network, they set no advertising cookies, and nothing about you is shared with the sponsor. We count how many times a placement was shown and how many times it was clicked, in aggregate, so we can tell a sponsor how their placement performed. Those counts are not tied to your profile and are not used to build an advertising profile of you. Premium subscribers do not see sponsored placements at all. We do not currently use any third-party advertising network. If that changes, we will name the provider in this Policy before it runs, and you will be able to manage personalization through that provider's settings or industry opt-out tools.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service. Where required by applicable law, we will request your consent before setting non-essential cookies, and you may withdraw that consent at any time.

5. Third-Party Services

We share data with the following third-party service providers, each governed by their own privacy policies:

  • fal.ai, Replicate, and kie.ai: AI model inference for the Generator and for the paid paths of AI Tools. They receive the prompt text and any reference files for the generation you requested, and nothing that identifies you. Each is governed by its own privacy and content policy (fal.ai, Replicate, kie.ai). kie.ai is a reseller: a request it handles may also be processed by the upstream model vendor it uses to fulfil that request, under that vendor's own terms.
  • Cloudflare R2: private object storage for media you generate.
  • Supabase: database, authentication, and storage infrastructure.
  • Paddle: payment processing and merchant of record services for web subscriptions.
  • Apple: sign-in authentication (Sign in with Apple) and iOS subscription billing, governed by Apple's Privacy Policy.
  • Google: sign-in authentication (Google Sign-In), usage analytics (Google Analytics), bot protection (reCAPTCHA), and Android subscription billing, governed by Google's Privacy Policy and Terms of Service.
  • Sentry (Functional Software, Inc., sentry.io): error monitoring and crash reporting. When an application error occurs, technical information such as the error message, stack trace, browser/device information, page URL, and approximate timestamp may be sent to Sentry. We configure Sentry to scrub personal data (including email addresses, user-generated content, cookies, and IP addresses) before transmission, in line with the principle of data minimization. This processing is carried out on the basis of our legitimate interest in maintaining the security and proper functioning of the Service.
  • Vercel, Inc.: website hosting, plus cookieless Web Analytics (page and session counts) and Speed Insights (Core Web Vitals from real devices). These two products set no cookie, store no identifier, and do not reconstruct a browsing session across pages. They record the route and URL, device and browser type, country, network speed class, and — for Speed Insights — the web-vital value and a CSS selector for the element that was measured. They run on the public site only (not the admin panel or the AI Generator) and are not gated by the cookie banner, because they are not cookies. This processing is carried out on the basis of our legitimate interest in understanding how the Service is used and how fast it is for real visitors. See Vercel's Privacy Policy and Speed Insights privacy.
  • Cloudflare, Inc.: content delivery network (CDN), DDoS protection, and security services. Cloudflare processes network-level data including IP addresses and HTTP request metadata in transit. Cloudflare does not have access to the content of your account or stored personal data beyond what is necessary for routing and security purposes.
  • Brevo (formerly Sendinblue, SAS): service email only — account verification, password reset, email-change confirmation, security notices, receipts and the other messages described in Terms Section 6B.1. We share your email address with Brevo for the purpose of delivering those service-critical communications. Brevo is not used for marketing email.
  • Resend (Plus Five Five, Inc.): marketing and broadcast email — the product news you opted in to, and occasional announcements sent to all members. Resend receives your email address, the content of the message, and the events its own systems record about it (whether it was delivered, bounced, or reported as spam, and whether it was opened or a link was clicked). It is a separate provider from Brevo on purpose: a complaint about a marketing message cannot then affect the delivery of a password reset. See Resend's Privacy Policy.
    • Open and click measurement. Marketing messages may include a small tracking image and links that pass through Resend before reaching their destination. This is how "opened" and "clicked" are recorded. Open tracking is unreliable by design of modern mail clients — Apple Mail Privacy Protection loads images for everybody — so we treat it as a weak signal, never as proof that you read something. Unsubscribing stops the messages and therefore the measurement.
    • Suppression. If an address hard-bounces or reports a message as spam, we add it to a suppression list and never write to it again. That list holds the address and the reason, and exists so an objection cannot be undone by a later mistake.
  • Google reCAPTCHA: bot detection and abuse prevention. reCAPTCHA may collect behavioral signals, IP address, and browser/device information to assess whether interactions are made by a human user. This data is transmitted to Google and is governed by Google's Privacy Policy and Terms of Service.
  • Meta Platforms, Inc. (Instagram, Facebook): Visxy uses the Meta Graph API to operate a comment-triggered marketing automation feature on its own Instagram Business account and Facebook Page. Comment content and commenter identifiers ingested via the Meta API are used solely to classify comments, send automated DMs, post public replies, and enforce deduplication and rate limits. This data is not shared with any other third parties, is not used for advertising profiling, and is not linked to Visxy user accounts. We operate this integration in accordance with Meta's Platform Terms and Developer Policies.
  • Advertising networks: none. Sponsored placements are served by us directly, as described in Section 4; no third-party advertising provider receives your data today. Any future provider will be named here before it is enabled.

We do not sell your personal information to third parties.

6. Data Retention

We retain your account information for as long as your account is active. If you delete your account, we will delete or anonymize your personal data, except where retention is required for legal, accounting, or fraud-prevention purposes (e.g., transaction records).

Backups. Deleting your account removes your data from our live systems. Routine encrypted backups may still contain a copy until they are overwritten on their normal rotation schedule. During that period the backup is not used for any other purpose, and is not searched, restored, or analysed except to recover the service from failure.

License and copy records (Section 2.4) are retained as part of your subscription history for the life of your account, including after individual Premium periods end, so that your record of commercial usage rights remains available to you. These records are removed when you delete your account (see Section 7), subject to the legal and accounting retention exceptions above.

AI Generator data is retained as follows:

  • Generated media you delete is held in trash for a short period, stated in the Service, and then permanently deleted from storage.
  • Once you hold neither an active Generator plan nor any usable credits, your generated media remains available for a limited retention period, stated in the Service, and is then permanently deleted. This exists so you can save your work, not so we can keep it.
  • Reference files are kept until you delete them or delete your account.
  • Generation and credit ledger records are retained for the life of your account as the audit trail behind your balance and charges, and are removed when you delete your account, subject to the legal and accounting exceptions above.
  • Credit pack purchase records are transaction records: like refund records below, they are kept after an account is deleted with the account identifier removed, because a seller must be able to evidence a sale. Unused credits are forfeited on deletion (Section 7.2).
  • Policy-refusal records are retained only as long as needed to operate the misuse thresholds described in the Terms of Service, Section 7A.

AI Tools data (Section 2.9) is retained as follows:

  • Nothing at all for a tool that runs in your browser. There is no record to retain, because the content never reaches us.
  • Daily usage counts hold a tool, a date and a number, with no user identifier. They are aggregate statistics rather than personal data, and are kept for as long as they are useful for deciding which tools to keep.
  • Free-allowance counters are day-scoped and swept regularly: yesterday's counter answers no question, so it is not kept. A guest's counter is tied to an identifier in that browser, not to a person.
  • Paid-path data follows the AI Generator rules above, without exception.
  • Preferences stored in your browser are not retained by us at all, because we never receive them. They persist until you clear your browser's site data.

Creator Partnership data (Section 2.10) is retained as follows:

  • Per-device referral records are kept only while the 30-day referral window is open, then deleted; only an anonymous daily count remains. A referral linked to an account keeps the device identifier only while it is open. After that it is kept without it, as the record of which partner the account came through, together with any commission it produced.
  • Devices a partner used on their own link are kept for 180 days after last use.
  • Daily traffic counts hold a partner, a date and numbers, with no visitor identifier, and are kept for as long as the partnership's statistics are useful.
  • Commissions, the balance ledger and partnership records are kept for as long as the Program runs, including after a partnership ends, as the record behind every balance. If a partner's account is deleted, these records are kept with the account identifier removed, for the same accounting and dispute reasons as refund records below.
  • Applications are kept for as long as the account exists. If the account is deleted, the application is kept with the name, links, promotion text, notes and reasons removed, so that only the channel type, audience band, country, decision and dates remain for statistics.

Email subscription data (Section 2.11) is retained as follows:

  • Your subscription and the record of your consent are kept for as long as you hold an account, and for as long as the consent could need to be evidenced after you withdraw it. Turkish electronic-message law requires a sender to be able to prove consent, so a withdrawal removes you from the list rather than erasing the fact that you once asked to be on it.
  • A subscription with no account is kept until you unsubscribe. An address that never confirms is deleted once its confirmation link expires, because an unconfirmed address is not a subscriber and there is nothing to keep.
  • Delivery and engagement events (delivered, bounced, complained, opened, clicked) are kept while the campaign they belong to is still worth reporting on, and are removed with the campaign.
  • Suppression records — an address that hard-bounced or reported us as spam — are kept indefinitely, on purpose. The whole point of the list is that we never write to that address again, and deleting the record would defeat it. It holds the address and the reason, nothing else.
  • Deleting your account turns marketing email off, removes your subscription and your per-recipient delivery records, and leaves aggregate campaign totals that identify nobody. A suppression record survives, for the reason above.

Refund and dispute records (Section 2.3) are transaction records. They are retained under the legal, accounting and fraud-prevention exception above, which means they can outlive the account itself — with the account identifier removed where we no longer need it — because tax and commercial law require a seller to be able to evidence a sale and its reversal for a fixed number of years.

Account enforcement records (Section 2.8) are kept for as long as the account exists. Where a suspension relates to a dispute, a complaint, a payment chargeback, or a report we are required to make, the record is kept for as long as we need it for that purpose, and this is one of the cases in which we may decline to delete an account (Section 7).

Data collected via the Meta Graph API (comment identifiers, commenter identifiers, and DM delivery logs) is retained only for as long as necessary to operate the automation feature — specifically, to enforce deduplication and rate limits. This data is not retained beyond its operational purpose and is not archived or used for any secondary purpose.

7. Account Suspension, Deletion & Email Changes

7.1 Suspension

  • We may suspend an account in the circumstances set out in the Terms of Service, Section 11.2. A suspension blocks sign-in and deletes nothing — your account, content, purchases, and records stay exactly as they were.
  • You are told the reason. Because a suspended account cannot read anything inside the Service, we also send the reason to the email address on the account.
  • A person makes the decision and a person reviews it if you contest it at support@visxy.com (see Section 3.2).
  • What we record about a suspension, and for how long, is described in Sections 2.8 and 6.

7.2 Deletion

  • You may delete your account at any time from your account settings.
  • Deletion is scheduled 21 days ahead by default. Nothing is removed during that period and your account keeps working normally, so you can sign in and choose Keep my account at any point to cancel it. This window exists to protect you against an accidental or unauthorised deletion — it is not a delay we impose on your rights.
  • If you want your data erased without waiting, tick Delete without the 21-day recovery window when you confirm. We then delete on the next scheduled run.
  • When deletion runs, we permanently remove your profile, favorites, collections, copy and like history, license records, generated media, and uploaded reference files. Records we must keep for accounting, tax, or fraud-prevention reasons — what was purchased and when — are kept with your identity removed, as described in Section 6. Backups follow the rotation described there.
  • Any unused AI Generator credits are forfeited when you delete your account, and an active Generator plan stops renewing as soon as you request deletion. A subscription bought through the App Store or Google Play must be cancelled where you bought it (see the Terms of Service).
  • Content you authored and that we published — prompts or articles — is transferred to a Visxy-operated profile rather than removed, so that the public library is not broken by an account closing.
  • If you are a Creator Partnership partner, the account cannot be deleted while your partnership is active or suspended, or while a balance or an amount owed remains; ask us to end the partnership first (Terms of Service, Section 6D.5). Once deleted, your commission and balance records are kept with your identity removed, and your application is kept with its personal fields removed (Section 6).
  • If your account is suspended, we may decline to delete it while the matter that led to the suspension is unresolved, where we need the records to establish, exercise, or defend a legal claim (GDPR Article 17(3)(e)). We will tell you when we do this and why.

7.3 Email changes

  • You may change your account email address at any time. For your security, this requires confirmation via links sent to both your old and new email addresses.

8. Your Rights

Depending on your location, you may have rights under applicable data protection laws (such as the GDPR or CCPA), including the right to:

  • Access the personal data we hold about you;
  • Request correction or deletion of your data;
  • Object to or restrict certain processing;
  • Request a copy of your data in a portable format;
  • Withdraw consent where processing is based on consent.

If you are in Turkey, the KVKK gives you equivalent rights under its Article 11, including the right to learn whether your data is processed, to request correction or erasure, and to object to a result produced solely by automated analysis.

To exercise any of these rights, contact us at support@visxy.com. You may also delete your account directly via your account settings. We will respond within the period the applicable law allows — one month under the GDPR, thirty days under the KVKK — and will tell you if we need longer and why. We do not charge for a request unless it is manifestly unfounded or excessive.

Deleting your account from settings is an erasure request. The 21-day recovery window described in Section 7.2 runs inside those statutory periods, not on top of them: the deletion itself is carried out well within one month of your request, and you can waive the window entirely when you confirm.

If we decline a request, in whole or in part, we tell you which exception we rely on and why — for example an erasure request from a suspended account, where we need the records to establish, exercise, or defend a legal claim. You may complain to a supervisory authority about that decision, as described below.

Right to complain. If you think we have handled your data wrongly, you may complain to a supervisory authority as well as to us:

  • In the EEA, the data protection authority of the country where you live or work, or where the issue arose.
  • In the UK, the Information Commissioner's Office (ico.org.uk).
  • In Turkey, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr).

We would rather hear from you first, but you are not required to contact us before complaining.

Where processing is carried out by third-party providers on our behalf (such as Sentry for error monitoring, or Vercel for hosting and cookieless site measurement), those providers operate under Data Processing Agreements and support data subject rights requests. Requests received by us will be forwarded to the relevant provider where applicable.

We do not sell or share personal information for cross-context behavioural advertising as those terms are used in the CCPA and similar laws. Sponsored placements are served by us and disclose nothing about you to the sponsor. If we ever engage an advertising partner whose involvement would amount to a "sale" or "share", we will name it in this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism before it goes live.

9. Children’s Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us so we can remove it.

10. Data Security

We implement technical and organizational measures appropriate to the risk, including:

  • Access control at the database level. Rows are readable only by the account that owns them, enforced by the database itself rather than by application code alone.
  • Private storage. Generated media and reference files sit in a private bucket with no public address; every read is an individually authorised link that expires in minutes.
  • Encryption in transit, throughout the Service and to every provider listed in Section 5.
  • Secrets held server-side, never delivered to your browser or app.
  • Error reports scrubbed of personal data before they leave our systems (Section 5, Sentry).

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where the law requires it, you — without undue delay.

11. International Data Transfers

Your information may be processed and stored in countries other than your own. Our key third-party providers operate as follows:

  • Supabase, Paddle, Google (Analytics, sign-in), Apple: data may be processed in the United States or other countries where these providers maintain infrastructure.
  • fal.ai, Replicate, kie.ai: prompt text and reference files for Generator jobs may be processed on those providers' infrastructure, including in the United States. kie.ai (NEXUSAI SERVICES LLC) is based in Colorado, United States.
  • Meta Platforms, Inc.: comment and DM log data processed via the Meta Graph API may be stored on Meta's infrastructure, which operates globally including in the United States. Meta's data transfer practices are governed by Meta's own Data Policy and applicable transfer mechanisms.
  • Sentry: error monitoring data is stored on Google Cloud infrastructure, currently in the United States. Sentry offers an EU data residency option; if we migrate to EU residency in the future, this Policy will be updated accordingly.

Where personal data is transferred from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or the provider's certification under applicable data transfer frameworks. Sentry is GDPR and CCPA compliant and maintains a Data Processing Agreement (DPA) that covers such transfers.

By using the Service, you acknowledge that your data may be transferred to and processed in the United States or other countries, which may have different data protection laws than your jurisdiction.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

13. Contact

For privacy-related questions or requests, contact us at: support@visxy.com