Legal
Privacy
Last updated 24 August 2026
01Controller
Anyratio is the controller for personal data we collect when you use https://anyratio-dev.web.app and the product at app.anyratio.ai. Write to hello@anyratio.ai for access, deletion, or a DPA discussion (Enterprise).
02What we collect
- Account: email, name, Google profile photo if you sign in with Google, password hashes via Firebase Auth (we never see a Google password).
- Billing: plan, trial status, invoices — processed by Stripe. We store Stripe customer and subscription ids, not full card numbers.
- Product: uploaded masters, generated stills, job names, folders, team invites, usage counts, optional reports on a still.
- Support: whatever you send to hello@anyratio.ai.
- Technical: IP and user agent on our hosts and CDNs (security, abuse, basic logs).
- Marketing (with consent): Google Ads tags may set cookies to measure ad campaigns after you accept the cookie banner on https://anyratio-dev.web.app.
03Why we process it
We process data to run the contract (account, generate sizes, bill stills), to keep the Service secure, and — where required — with consent (optional mail, Google Ads cookies on the marketing site). Legitimate interests cover abuse prevention and product logs, balanced against your rights.
04Processors
We use other companies to operate Anyratio. They only get what they need:
- Google Firebase — authentication, database, file storage.
- Google Gemini — image generation. Your photo is sent so the model can fill the new canvas. Google’s safety systems may also scan that request.
- Stripe — checkout, subscriptions, invoices, tax where configured.
- Amazon SES — transactional email (reset password, invites, receipts) from our sending domain.
- Google Ads — conversion and campaign measurement on the marketing site, only after cookie consent.
We do not sell your personal data. We do not use your masters to train public foundation models.
05Where it lives
Object storage for campaign files is configured in Google Cloud’s europe-west1 region. Transactional mail is sent from AWS SES in eu-central-1.
Generation uses Google’s Gemini API. That inference may happen outside the EU. Stripe and Google Auth may also process some account data in other regions. If we ever claim “nothing leaves the EU” in ads, that claim has to match this setup — it does not, as long as Gemini and those processors are in the path.
Enterprise can negotiate region and a GDPR DPA separately.
06How long we keep it
Account and jobs stay while the account is open. Usage history is kept to meter the plan. After you delete the account we remove jobs, masters, and generated files we still hold, and cancel a subscription we bill for that user. Backups and logs fade on a short rotation. Stripe retains payment records as the law requires. Emails you sent us stay in the inbox until we no longer need them for support.
07Your rights (GDPR)
If you are in the EEA/UK you can ask to access, correct, export, or delete personal data, object to some processing, and complain to a supervisory authority (in Sweden: IMY). Start with hello@anyratio.ai. You can also delete the account yourself in product settings — that is the fastest way to drop jobs and files.
Delete lives in the logged-in app: sign in, then Account. Billing owners with teammates must empty or transfer the team first.
09Children
The Service is for professional use, not for children under 16. Do not create an account for them.
10Changes
We will date this page when it changes. Material changes get a note in the product or by email when we have an address. Related: Terms of use.
Questions: hello@anyratio.ai