Privacy Policy
Last updated:
At Avatarmatic, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI video avatar platform. By using Avatarmatic, you agree to the practices described in this policy.
1. Data We Collect
1.1 Account Information
- Email address: Required for account creation and communication
- Name: Optional, used for personalization
- Password: Securely hashed using industry-standard encryption
- Payment information: Processed by our payment provider (Stripe); we do not store card details
1.2 Photos and Media
- Source photos: Photos you upload to create AI avatars
- Generated avatars: AI-generated avatar images
- Video content: Videos you create using our platform
1.3 Usage Data
- Interaction data: Features used, videos created, avatar preferences
- Device information: Browser type, operating system, device type
- Access times: When you log in and use the service
- Performance data: Loading times, error occurrences, feature usage patterns
1.4 Cookies and Similar Technologies
We use cookies to enhance your experience. See our Cookie Policy for detailed information.
2. How We Use Your Data
- Provide our services: Create and deliver AI-generated avatars and videos
- Process payments: Handle subscription payments securely via Stripe
- Improve our services: Analyze usage patterns to enhance performance
- Communicate with you: Send account updates, support responses, and marketing (with consent)
- Prevent abuse: Detect fraud, enforce terms, and maintain security
3. AI Photo Processing
3.1 Processing Methodology
- Photos are uploaded temporarily to our secure processing environment
- AI models analyze photos to extract facial features and generate avatars
- Once avatar generation is complete, source photos are deleted from our systems
- Only the generated avatar is retained (if you choose to save it)
3.2 Data Retention for AI Processing
- Source photos: Deleted immediately after AI processing completes (typically within minutes)
- Generated avatars: Retained until you delete them or your account is closed
- Processing logs: Retained for 30 days for quality and security purposes
3.3 AI Model Training
We do not use your personal photos to train our AI models. Your uploaded content is used solely for the purpose of generating your personal avatars and is never incorporated into our model training datasets.
4. Third-Party Services
4.1 Payment Processing (Stripe)
- All payment processing is handled by Stripe
- We do not store credit card information on our servers
- Stripe may collect additional data per their privacy policy
- See: Stripe Privacy Policy
4.2 Analytics
- We use analytics tools to understand how users interact with our platform
- Data collected includes page views, feature usage, and anonymized usage patterns
- Analytics data is aggregated and cannot identify individual users
4.3 Cloud Infrastructure
Our services are hosted on cloud infrastructure providers. All data is stored in secure data centers with industry-standard encryption.
5. Data Security
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access controls: Strict access controls limit employee access to user data
- Regular audits: We conduct security audits and vulnerability assessments
- Breach notification: We will notify you of any data breach within 72 hours as required by GDPR
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion |
| Source photos | Deleted immediately after processing (minutes) |
| Generated avatars | Until you delete or account is closed |
| Payment records | 7 years (legal requirement) |
| Analytics data | 26 months (anonymized) |
| Processing logs | 30 days |
7. Cookies
We use cookies to provide essential functionality and analyze site usage. For detailed information about the cookies we use, please see our Cookie Policy.
8. Children's Privacy
Avatarmatic is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
9. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
9.1 Right to Access
You can request a copy of all personal data we hold about you, including:
- Account information
- Generated avatars
- Usage data
9.2 Right to Rectification
You can request correction of inaccurate or incomplete personal data.
9.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data. This includes:
- Account closure and data deletion
- Deletion of all generated avatars
- Removal from marketing lists
Note: Some data may be retained for legal or contractual obligations (e.g., payment records).
9.4 Right to Data Portability
You can request your personal data in a machine-readable format that you can transfer to another service.
9.5 Right to Object
You can object to processing of your personal data for direct marketing or legitimate interests.
9.6 Right to Withdraw Consent
You can withdraw consent for processing at any time. This does not affect processing that occurred before withdrawal.
9.7 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Or use our contact form
We will respond to your request within 30 days as required by GDPR.
10. International Data Transfers
Your data may be transferred and processed outside your country of residence. We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) for transfers outside EEA
- Adequacy decisions where applicable
- Encryption during transfer
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on this page
- Updating the "Last updated" date
- Email notification for significant changes
We encourage you to review this policy periodically.
12. Contact Information
For questions about this Privacy Policy or to exercise your rights, contact us:
If you have a complaint about how we handle your data, you have the right to lodge a complaint with your local data protection authority.