Privacy Policy

Last updated July 27, 2026 · Effective July 29, 2026

This Privacy Policy (“Policy”) describes how Real Influencer Studios LLC, a Missouri limited liability company (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with our websites, applications, APIs, and related services (collectively, the “Service”). It is incorporated by reference into our Terms of Service (“Terms”) and Acceptable Use Policy (“AUP”). Capitalized terms not defined here have the meaning given in the Terms.

Who this Policy is for. The Service is intended only for adults aged 18 or older (Section 9). We operate from the United States and the Service is US-first; we do not currently direct the Service to the European Union, the United Kingdom, or other non-US markets (Section 11).

1. The short version (summary — the full terms control)

  • What we are. The Service is a software tool that generates fictional, AI-generated personas (explicitly not real people) as images and short videos at your direction. You direct the generation; we provide the tool. We do not post, distribute, or publish Output on your behalf.
  • What we collect. Account and contact data (including your email and a device identifier used to prevent abuse of free allowances), the prompts/settings/templates you choose, any reference photos you choose to upload, the Output we generate for you, payment-transaction metadata (we do not store full card numbers), and standard usage/log data.
  • Reference photos. You may upload reference photos. We process them only to generate your Output. We do not use your uploaded photos to train any model, and we do not derive or store a faceprint / biometric template from your uploaded photos (Section 4). They are not sold.
  • We do not train on your content, and we do not sell your personal information today. We may transfer information to a successor in a merger, acquisition, financing, reorganization, or sale of assets (Section 6). We say “we do not sell now” and “we may transferin an M&A event” — we never say “never” (the absolute would defeat the lawful M&A carve-out).
  • Who else touches the data. A small set of service providers / processorsoperate the Service on our behalf — our generation, hosting, storage, payment, and authentication vendors (Section 5). They process data for us, under contract, not for their own purposes, and the tiers we use are contracted not to retain or train on the content we send.
  • Your rights. Depending on where you live, you can request to access, delete, or correct your information, and to opt out of any “sale”/“sharing” (we do not sell/share today, so this is a no-op unless that changes) (Section 7).
  • No minors. The Service is for adults only. We do not knowingly collect information from anyone under 18 (Section 9).

2. The information we collect

We collect the categories below. Where a category maps to a CCPA/CPRA statutory category, that mapping appears in Section 12.

2.1 Information you provide directly.

  • Account & authentication data. When you create an account or sign in, we collect identifiers tied to your account. Sign-in on the web is by a one-time email code (via our authentication provider, Supabase); Sign in with Apple or Google is offered only where enabled. We use sign-in for authentication only — we do not connect to, or post to, your social-media accounts. We collect your email address (a verified email is required to claim certain free allowances and to secure the account).
  • Reference uploads (a metered feature).If you use the “add reference” feature, we receive the reference photo or file you choose to upload. You direct this; it is optional. We own a durable copy of the bytes you upload to provide the feature (we do not serve the original source URL as our system of record). See Section 4 for how we handle these, including the biometric-data position.
  • Generation inputs. The prompts, text, settings, templates, niche/aesthetic selections, and product/affiliate links you choose or enter to direct a generation.
  • Payment information. When you purchase credits, our payment processor (Stripe) collects and processes your payment details directly. We do not receive or store full payment-card numbers; we receive transaction metadata (e.g., a customer/transaction reference, amount, status, and a card brand/last-four where the processor returns it). On iOS, where in-app purchases are offered, they are processed by Appleunder Apple’s terms, and we would receive a transaction record, not your card data. (At launch, credit purchases are processed on the web via Stripe; the iOS in-app-purchase path is enabled when it ships.)
  • Communications. Anything you send us (support requests, reports, feedback).

2.2 Information generated by your use of the Service.

  • Output. The images and short videos we generate for you at your direction, and the metadata about each generation (the template used, model, cost, quality signals, and an AI-disclosure flag). We retain a durable, auditable record of each generation as part of operating the Service and meeting our legal and safety obligations (Section 3, Section 8).
  • Credits-wallet & billing activity.Your closed-loop credits balance and the ledger of credit grants, purchases, and spends (a closed-loop wallet redeemable only for our Service — no cash-out, no peer-to-peer transfer, no gifting).
  • Captions we author for you. When you use the export/caption feature, we run one automated pass to suggest a caption/hashtags for the platform you choose; this is a suggestion you can edit, copy, and use yourself.
  • “Posted” markers.If you tap a “Posted” marker, we record only the fact that you say you posted to a named platform. We make no platform API call and collect no analytics from your social accounts— the marker is self-asserted state only.

2.3 Information we collect automatically.

  • Device & technical data. A device identifier / device hash(used to enforce per-device limits on free allowances and to detect abuse — a no-farm control), app/version, operating system, and general technical data needed to run the Service.
  • Usage & log data. Standard server logs (timestamps, request metadata, error and security events) and IP-derived coarse, approximate location(e.g., country/region for compliance, fraud, and routing — not precise geolocation).
  • Cookies, analytics and advertising identifiers. We and our analytics providers set cookies and similar identifiers to measure how the Service is used (pages viewed, features used, whether a signup or purchase completed) and, where enabled, to measure the performance of our own advertising. This includes advertising click identifiers passed in a link when you arrive from an ad, and campaign labels (e.g. utm_source). You can turn this off — see Your Privacy Choices and Section 7.

2.4 Information we do NOT collect / do NOT do.

  • We do not connect to, read, or post to your social-media accounts (sign-in OAuth is authentication only).
  • We do not derive or store a faceprint or biometric template from your uploaded reference photos (Section 4).
  • We do not use your content to train any AI model (Section 3.2).
  • We do not knowingly collect information from anyone under 18 (Section 9).

3. How we use information

3.1 To provide and operate the Service. To create your account, authenticate you, generate the Output you direct, host and deliver your media, process your credit purchases, maintain your credits wallet, and provide support.

3.2 We do NOT train on your content. We do not use your User Content (your prompts, reference uploads, or Output) to train, fine-tune, or improve any AI model, and the third-party model providers we route to operate on tiers contracted not to retain or train on the content we send (Section 5). We may use de-identified, aggregated, or anonymized data (data that cannot reasonably be linked to you) for analytics, safety, capacity planning, and Service improvement.

3.3 Safety, security, and legal compliance. To screen content against our safety rules, detect and prevent fraud and abuse (including farming of free allowances), enforce our Terms and AUP, preserve records we are required to keep, respond to lawful requests, and protect the rights, safety, and property of users, the public, and the Company. This includes our non-shiftable obligations regarding child-sexual-abuse material: if we obtain actual knowledge of apparent CSAM, we will report and preserve as required by law.

3.4 To communicate with you. Transactional and service messages (account, security, billing, and support).

3.5 AI disclosure.We embed a machine-readable, invisible AI content-credential (a C2PA “AI-generated” provenance tag) in the Output we deliver to you, and we do not apply a visible watermark to it; whether and how to make the conspicuous, human-visible disclosure when you post is your responsibility as the publisher (Terms §10, AUP §5). We also keep an internal record of generations for our own safety and compliance purposes.

We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you, and we do not sell or share it for cross-context behavioral advertising today (Section 6, Section 7).

4. Reference photos and biometric data (the upload path)

This Section governs photos and files you choose to upload as references.

4.1 What we do with an uploaded reference. We copy the bytes into our durable storage, register it as your user-owned reference, screen it against our safety rules where screening is enabled (which may include an apparent-minor check), and use it solely to generate the Output you direct. We do not publish it, and we do not make it available to other users.

4.2 We do NOT create a biometric template from your uploads. We do not run facial-recognition, face-geometry, or face-embedding processing on your uploaded photos, and we do not derive, store, or use a “faceprint” or other biometric identifier from them. Our face-similarity tooling runs only on imagery we ourselves generated(for internal quality/consistency checks on our own synthetic personas) — never on a user-uploaded photo. This is enforced today as a code-level practice (the only pipeline that derives a face embedding profiles our synthetic personas exclusively, and the upload path never routes an uploaded photo to face-embedding); a hard structural guard that would prevent an upload from ever reaching face-embedding is being added. When safety screening is enabled, your uploaded image (including any face in it) may be sent to our content-safety provider (Google) to classify it against our safety rules; this is a content classification, not facial-recognition or biometric-template extraction, and no faceprint is derived or stored.

4.3 The line this Policy does NOT cross (and the trigger if it ever does).No current feature stores a per-user faceprint, trains a per-user model on a real person’s face, or builds a “clone yourself” likeness from an uploaded real photo. If we ever contemplate such a feature, it is a separate launch-gate requiring its own biometric-consent package (written release, published retention/destruction schedule, no-sale-of-biometrics commitment, secure storage) before it ships.

4.4 Your warranties on what you upload. You may upload only content you have the right to upload. You must notupload a photo of a real person without that person’s documented consent, and you must neverupload a photo of a minor or any unlawful content (see the Terms §8.3 and the AUP). The legal risk allocation for uploads lives in the Terms and AUP; this Policy governs only how we handle the data.

5. The service providers / processors we use

We share information with a limited set of vendors that operate the Service on our behalf, under contract, processing data for us— not for their own purposes. The current set is:

ProviderRoleWhat it processes
SupabaseAuthentication, application database, and a durable record of accounts, generations, and assetsAccount/auth data; generation traces; asset metadata
StripePayment processing for web credit purchasesYour payment details (collected by Stripe directly); we receive transaction metadata, not card numbers
AppleIn-app purchase processing (iOS, when enabled) and Sign in with Apple (where enabled)Transaction record (iOS purchases); authentication token
GoogleSign in with Google; Google (Gemini) AI models for generation and content-safety screeningAuthentication token; the prompts/settings/reference images you direct us to send for a generation or a safety screen
fal.aiThe image (free-tier and edit), voice (text-to-speech), avatar/motion-video, and transcription model-routing platform we generate throughThe prompts/settings/reference images and audio you direct us to send for a generation; fal also runs CSAM hash-matching on content routed through it
SegmindThe platform for our default short-video / reel generation (the Seedance model)The prompts/settings/reference images you direct us to send for a video generation
ElevenLabs (accessed via fal.ai)Voice / text-to-speech generation (the synthetic voices)The text you direct us to synthesize into a voiceover (no reference photo or face data); operated on a no-retention / no-train tier
OpenAICertain image-generation/edit models (routed via our model platform)The prompts/settings/reference images you direct us to send for those generations
Backblaze B2Durable, S3-compatible storage for generated mediaThe Output media we host for you
Google (Analytics & Tag Manager)Product and marketing analytics, and the tag container through which measurement tags are deployedCookies and similar identifiers, pages viewed, events (e.g. signup, purchase), device/browser data, coarse location from IP. Operated under the Google Ads Data Processing Terms; Google signals and ads-personalization data sharing are off
PostHogProduct analytics — how the app is used, so we can improve itCookies and similar identifiers, product events, and an account identifier once you sign in
Cloudflare (planned)Content delivery (CDN) for public/share mediaMedia delivery; standard CDN logs

Other disclosures. We may also disclose information: (a) to professional advisors (lawyers, accountants, auditors); (b) to comply with law or respond to lawful requests, court orders, or legal process; (c) to protect rights and safety(ours, users’, or the public’s), including fraud prevention and enforcement of our Terms/AUP; and (d) in a business transfer (Section 6).

We do not disclose your personal information to third parties for their own marketing, and we do not sell or share it for cross-context behavioral advertising today (Section 7).

6. Business transfers (the M&A carve-out)

We do not sell your personal information today (Section 7). We may, however, transfer information — including the categories described in this Policy — to a successor or acquirer in connection with a merger, acquisition, financing, corporate reorganization, bankruptcy, or sale of some or all of our assets, or in negotiations or due diligence for any of the foregoing. In any such transaction, we will require the recipient to honor this Policy with respect to your information, including by maintaining privacy protections at least as protective as those in this Policy and by honoring any opt-out preferences you had previously communicated to us. We will provide notice (and, where required, choices) before your information becomes subject to a materially different privacy policy.

7. “Sale” / “sharing” and your opt-out (CCPA/CPRA)

We do not “sell” your personal information for money. We use advertising and conversion-measurement technologies (including analytics and, where enabled, advertising platform tags) that may constitute “sharing” for cross-context behavioral advertising as that term is defined under the California Consumer Privacy Act, as amended by the CPRA. Section 2.3 lists what these collect and Section 5 lists the providers.

You may opt out at any time. Use the “Do Not Sell or Share My Personal Information” link in the footer of every page, or visit Your Privacy Choices directly. We also honor the Global Privacy Control (GPC)browser signal as a valid opt-out request, applied on the first page you load, before any tag on the page runs — so if your browser sends GPC you do not need to do anything. You may also submit a request through Section 10, and we will honor it.

8. Retention and deletion

8.1 How long we keep information. We keep personal information for as long as neededto provide the Service, maintain your account, comply with our legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements — then we delete or de-identify it. Indicative schedule (these periods are current targets, not guarantees, and counsel will finalize them):

CategoryIndicative retention
Account & authentication dataLife of the account + 90 days after closure
Reference uploadsUntil you delete them or close your account, then deleted within 30 days
Output & generation traces3 years (auditability + safety)
Payment-transaction metadataAs required for tax/accounting/anti-fraud (7 years)
Server/security logs12 months
Content reported as apparent CSAMPreserved as required by law (e.g., the §2258A 1-year preservation floor) — NOT deleted on the normal schedule

8.2 The deletion-vs-preservation conflict (flagged, not papered over). Where a privacy rule would call for prompt destruction but a legal-preservation duty(e.g., the §2258A 1-year CSAM-preservation floor, or a litigation hold) requires retention, the preservation duty controls for that specific content and we will not delete it until the duty lapses.

8.3 Deletion requests. You may request deletion of your information (Section 10). We will delete it except where we are permitted or required to retain it (e.g., legal-preservation duties, fraud prevention, completing a transaction, or our own internal records as allowed by law).

9. Children (the COPPA floor)

The Service is for adults aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18, and we do not knowingly permit anyone under 18 to use the Service. If we learn that we have collected information from a person under 18 (or under 13 in a manner that would implicate COPPA), we will delete it. If you believe a minor has provided us information, contact us at privacy@realinfluencer.ai and we will act promptly.

10. Your privacy rights and how to exercise them

Depending on your state of residence, you may have rights to:

  • Know / access the personal information we hold about you and how we use and disclose it;
  • Delete your personal information (subject to the exceptions in Section 8);
  • Correct inaccurate personal information;
  • Opt out of any “sale” or “sharing”for cross-context behavioral advertising (we do not sell/share today — Section 7);
  • Limit the use of sensitive personal information (we do not use sensitive PI for purposes that trigger the right — but you may still ask); and
  • Non-discrimination for exercising any of these rights.

How to submit a request. Email privacy@realinfluencer.ai (or use the privacy-request option in your account settings, where available). We will verify your request (to protect your account) and respond within the timeframe the applicable law requires. You may use an authorized agent where the law permits.

11. International users and the EU/UK (deferred posture)

The Service is operated from the United States and is directed to US users. We do not currently offer the Service in, or target, the European Union, the United Kingdom, or other non-US markets, and pricing is in US dollars. We do not intend the Service to fall within the extraterritorial scope of the EU/UK GDPR at this time.

12. CCPA/CPRA categories table (for the California disclosure)

For California residents, the categories of personal information we collect, the sources, the business/commercial purposes, and the categories of recipients are described throughout this Policy. A statutory-category mapping (to be finalized by counsel):

CCPA/CPRA category (Cal. Civ. Code §1798.140(v))Do we collect it?Example in our Service
Identifiers (name/email/account ID, device ID, IP)YesEmail, account ID, device hash, IP-derived coarse location
Customer-records / financial infoLimitedPayment-transaction metadata (not card numbers)
Commercial informationYesCredit purchases, generation/usage history
Internet/network activityYesApp usage, logs, technical/device data
GeolocationCoarse onlyCountry/region from IP (not precise)
Sensitive PIbiometric for unique IDNoWe do not derive/store a faceprint from uploads (Section 4)
Visual information (photos)YesReference photos you choose to upload; Output we generate
InferencesLimitedDe-identified/aggregated only (Section 3.2)

13. Security

We use administrative, technical, and physical safeguards designed to protect personal information, and we require our service providers to do the same. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and regulators as required by law.

14. Changes to this Policy

We may update this Policy from time to time. If we make materialchanges, we will provide notice (e.g., in-app, by email, or by updating the “Last updated” date) beforethe change takes effect, and — where the law requires for a material or retroactive change to how we use already-collected information (especially sensitive or biometric data) — we will obtain your consent. Your continued use of the Service after a non-material update means you accept the updated Policy.

15. Contact

Real Influencer Studios LLC

Privacy requests: privacy@realinfluencer.ai

Mailing address: Real Influencer Studios LLC, 117 S Lexington St, Ste 100, Harrisonville, MO 64701