Privacy Policy

Last updated:

This Privacy Policy describes how Modela AI (“we”, “us”, or “our”) collects, uses, and shares information when you use our AI-powered fashion product image generation platform available at studiomodela.com (the “Service”). By using the Service, you agree to the practices described in this Policy.

1. Information We Collect

Account Information

When you register, we collect your full name, email address, and — if you choose email/password authentication — a hashed version of your password. We never store your password in plain text.

OAuth Authentication Data

If you sign in via Google or Facebook, we receive your name, email address, and profile picture from the respective provider. We do not receive or store your social-network password. OAuth tokens are managed securely by our authentication provider and are never exposed to our application layer.

Content You Upload

To use the Service, you upload garment images (“Input Images”). These images are stored in encrypted cloud storage. You retain full ownership of all content you upload — we do not claim any rights to your Input Images.

You are solely responsible for ensuring you have the necessary rights and a valid legal basis to upload any images. This includes images that may feature identifiable persons — you must have obtained the necessary consents from those individuals before uploading. Do not upload content that infringes third-party intellectual property rights or applicable law.

AI-Generated Images

Images generated by our platform based on your Input Images (“Generated Images”) are stored in your account. You retain full ownership of all Generated Images.

We do not guarantee that Generated Images are unique or free from similarity to other AI-generated content. The Service is provided as a creative tool; you are responsible for reviewing outputs before commercial use.

Usage & Generation Data

We automatically record:

  • Generation job parameters (AI model selected, pose, background environment)
  • Credit balance and transaction history
  • Subscription plan and status
  • Feature usage patterns (which tools you use and how often)

Payment Information

Payments are processed by Stripe. We do not store your full card number, CVV, or banking credentials on our servers. Stripe provides us with a payment token, last 4 digits, card brand, and expiry date for display purposes. Stripe's own privacy policy governs how they handle payment data.

Technical & Device Data

We automatically collect:

  • IP address and approximate geographic location (country/region level)
  • Browser type, version, and operating system
  • Referring URL and pages visited within the Service
  • Session identifiers stored in secure HTTP-only cookies
  • Error logs and performance metrics

Customer Support Data

If you contact us for support, we may collect the content of your messages, attachments you share, and any other information you provide to help resolve your request.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity
  • Provide, operate, and improve the AI image generation service
  • Process payments and manage your subscription and credit balance
  • Send transactional emails (account verification, password reset, billing receipts, generation completion notifications)
  • Send promotional and marketing emails about new features, offers, and updates (you can opt out at any time — see Section 9)
  • Analyse usage patterns to improve product quality and user experience
  • Detect and prevent fraud, abuse, and security incidents
  • Respond to your support requests
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your Input Images or Generated Images to train AI models without your explicit consent.

4. Third-Party Services & Sub-processors

To operate the Service, we engage trusted third-party sub-processors who may access your personal data solely to perform services on our behalf. Each is bound by a data processing agreement requiring GDPR-equivalent protections and appropriate security standards. We organise them by function:

CategoryPurposeData Region
Authentication & identityUser account creation, login, session management, and OAuth token handlingUSA
Cloud database & file storageStoring account data, uploaded garment images, and generated imagesUSA
Payment processingSecure payment collection, subscription billing, and invoice generation (Stripe)USA
AI model inferenceProcessing uploaded garment images to generate product photographyUSA
Email deliverySending transactional emails (verification, receipts) and marketing communicationsUSA
Cloud infrastructure & job processingHosting the application and executing background generation tasksUSA
Application monitoringDetecting and diagnosing errors and performance issuesUSA
Web analytics (Google Analytics)Aggregated, pseudonymised usage analytics to improve the ServiceUSA
Advertising measurement (Meta)Measuring ad campaign performance on Meta platforms (Facebook, Instagram)USA
Behavioural analytics (Hotjar)Anonymised heatmaps and session analysis to improve user experienceEU
Customer supportManaging support requests and user communicationTBD

A complete list of named sub-processors — including provider legal names, data regions, and transfer safeguards — is available on our Sub-processor List. We will notify you of material changes at least 14 days before they take effect.

We may engage additional providers as the Service grows. We will update this Policy and notify you in advance before activating any new integrations that affect the processing of your personal data.

When you authenticate via Google or Facebook, you are also subject to their respective privacy policies. We encourage you to review them independently.

5. Cookies & Tracking Technologies

We use cookies and similar technologies. You can manage your preferences through our cookie consent banner.

Essential Cookies

Required for the Service to function. These include your authentication session token (HTTP-only, cannot be accessed by JavaScript) and security tokens. You cannot opt out of essential cookies while using the Service.

Analytics Cookies (Google Analytics 4)

Help us understand how users interact with the Service — which pages are visited, how long sessions last, and what features are used. Data is aggregated and pseudonymised. Requires your consent.

Marketing Cookies (Meta Pixel)

Used to measure the effectiveness of our advertising campaigns on Meta platforms (Facebook, Instagram) and to deliver relevant ads. Requires your consent.

Behavioural Analytics (Hotjar)

Used to record anonymised heatmaps, session replays, and user feedback to improve the user experience. Hotjar does not capture passwords or payment information. Requires your consent.

You can withdraw your consent at any time via the cookie settings link in the footer, or by clearing cookies in your browser settings. Note that withdrawing consent for non-essential cookies will not affect the lawfulness of processing before withdrawal.

6. Data Retention

Data TypeRetention Period
Account profile & credentialsUntil account deletion (immediately purged on request)
Uploaded garment imagesUntil account deletion
AI-generated imagesUntil deleted by you, account deletion, or 1 year of account inactivity
Generation job metadataUntil account deletion
Payment & billing recordsUp to 7 years (legal & tax obligations)
Security & audit logs90 days
Support correspondence2 years after ticket closure
Analytics data (GA4, Hotjar)Per provider settings (typically 14 months)

After the applicable retention period, data is either permanently deleted or irreversibly anonymised. Payment records may be retained longer where required by applicable tax or financial regulations.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data (“right to be forgotten”)
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — request that we limit how we process your data in certain circumstances
  • Objection — object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing

You may delete your account at any time via your account settings or by contacting us at privacy@studiomodela.com. Account deletion triggers immediate and permanent erasure of all personal data, except where retention is required by law (see Section 6).

To exercise any other rights, email us at privacy@studiomodela.com. We will respond within 30 days. We may ask you to verify your identity before processing the request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

8. International Data Transfers

Modela AI is operated from Ukraine. Our sub-processors are primarily based in the United States. When we transfer your personal data outside your country of residence, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA to third countries
  • Data Processing Agreements with each sub-processor requiring GDPR-equivalent protections
  • Providers that are certified under recognised frameworks (e.g., Stripe and Google are certified under ISO 27001)

All international data transfers are conducted in accordance with applicable data protection laws. Where required, we implement Standard Contractual Clauses (SCCs) and supplementary safeguards to ensure an adequate level of protection for your personal data regardless of where it is processed.

9. Marketing Communications

With your consent, we may send you promotional emails about new features, special offers, product updates, and relevant industry news.

You can opt out at any time by:

  • Clicking the “Unsubscribe” link in any marketing email
  • Emailing privacy@studiomodela.com with “Unsubscribe” in the subject line

Opting out of marketing emails does not affect transactional communications (e.g., billing receipts, password resets, generation notifications), which are necessary for the operation of your account.

10. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@studiomodela.com and we will delete the data promptly.

11. Security

We implement industry-standard technical and organisational measures to protect your data:

  • All data in transit is encrypted with TLS 1.2 or higher
  • Data at rest is encrypted using AES-256
  • Authentication sessions use HTTP-only, Secure cookies — inaccessible to JavaScript
  • Passwords are hashed using a strong adaptive algorithm (Argon2id)
  • Database access is governed by Row Level Security (RLS) policies
  • Production secrets are stored as environment variables, never in source code
  • Access to production systems is restricted to authorised personnel only
  • Security incidents are monitored via automated alerting

Despite these measures, no transmission over the internet or electronic storage is 100% secure. If you believe your account has been compromised, please contact us immediately at privacy@studiomodela.com.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Notify you by email (to the address associated with your account) at least 14 days before the changes take effect
  • Where required by law, request your renewed consent

Continued use of the Service after the effective date constitutes your acceptance of the updated Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out to us:

Modela AI (legal entity registration pending)

Ukraine (full address to be added upon registration)

Email: privacy@studiomodela.com

We aim to respond to all privacy-related enquiries within 30 days of receipt.