← Back to Home

Privacy Policy

Effective Date: January 25, 2026
Last Updated: March 01, 2026

📋 Quick Summary: We collect minimal personal data (email, name), use Clerk for authentication, and store your AI-generated content and prompts. EU users have full GDPR rights including data export and deletion. We use cookies for essential functionality only.

1. Introduction & Data Controller

Rupali AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered media generation platform at rupali.ai ("the Service").

Data Controller:
Rupali AI
Address: Copenhagen, Denmark
Email: support@rupali.ai

For EU/EEA users, we act as the data controller for your personal information. This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.


AI Processing Providers (“AI Providers”)
To provide our AI-powered media generation features, we use third-party AI processing providers (“AI Providers”). These providers receive and process your prompts, parameters, and uploaded media solely for the purpose of generating outputs requested by you.
Current AI Provider: Runware (runware.ai)

We may update or replace our AI Providers in the future. Any such changes will be reflected in this Privacy Policy or in a publicly accessible list of subprocessors that we maintain.

2. Information We Collect

2.1 Account & Identity Information

Collected when you create an account (processed by Clerk):

  • Email address (required for account creation and communication)
  • Full name (used for personalization)
  • User ID (unique identifier generated by Clerk)
  • Authentication tokens (JWT tokens for secure session management)
  • Profile picture (optional, if you choose to upload one)

2.2 AI Generation Data

Information related to your use of our AI media generation service:

  • Text prompts you enter to generate content
  • Negative prompts (what to avoid in generation)
  • Generation parameters (model choice, image size, number of steps, guidance scale, etc.)
  • Generated content and their metadata (model used, generation time, NSFW score)
  • Generation history (timestamps, status, model versions)
  • Favorited/saved content (if you use this feature)

Legal basis: Necessary for contract performance (providing the AI generation service you requested)

2.3 Payment & Billing Information

Collected when you purchase credits (processed by payment processor):

  • Transaction IDs and order details
  • Credit balance and usage history
  • Purchase amounts and dates
  • Country code (for VAT calculation, EU users only)
  • VAT number (optional, for business customers)
  • Payment card details (stored securely by our payment processor, Creem, not by us)

Legal basis: Necessary for contract performance and legal obligation (tax compliance)

2.4 Technical & Usage Data

Automatically collected when you use the Service:

  • IP address (for security, fraud prevention, and approximate location)
  • Browser type and version (for compatibility)
  • Device information (operating system, screen resolution)
  • Session data (login times, page views, feature usage)
  • Cookies (see our Cookie Policy)
  • Error logs (crash reports, technical issues)
  • Performance metrics (page load times, API response times)

Legal basis: Legitimate interest (service improvement, security, fraud prevention)

2.5 Communications

  • Support messages (if you contact customer support)
  • Feedback and surveys (if you choose to provide feedback)
  • Email preferences (which emails you want to receive)

3. How We Use Your Information

3.1 Service Delivery

  • Create and manage your account
  • Authenticate you when you log in (via Clerk)
  • Process your AI media generation requests (via Service Providers)
  • Store and display your generated content in your gallery
  • Track your credit balance and usage
  • Provide customer support and respond to your inquiries

3.2 Payment Processing

  • Process credit purchases via Payment Processor
  • Issue invoices and receipts
  • Calculate and collect applicable VAT (EU customers)
  • Handle refunds and chargebacks
  • Maintain transaction records for accounting and tax purposes

3.3 Service Improvement & Analytics

  • Analyze usage patterns via Umami Analytics (a cookie-less, privacy-focused analytics service)
  • Monitor performance and fix technical issues
  • Aggregate anonymized data for statistical analysis
  • Monitor platform usage to optimize our AI generation features

3.4 Security & Fraud Prevention

  • Detect and prevent unauthorized access to accounts
  • Identify and block abusive or fraudulent activity
  • Monitor for generation of prohibited content (NSFW, illegal content)
  • Protect against distributed denial-of-service (DDoS) attacks
  • Comply with content moderation and safety requirements

3.5 Communications (With Your Consent)

  • Transactional emails: Order confirmations, credit balance alerts, security notifications (essential, always sent)
  • Product updates: New features, model announcements (opt-in)
  • Marketing emails: Promotions, special offers (opt-in, with easy unsubscribe)

3.6 Legal Compliance

  • Comply with GDPR, EU AI Act, and other applicable laws
  • Respond to legal requests (court orders, subpoenas)
  • Enforce our Terms of Service and Acceptable Use Policy
  • Report illegal content to authorities when required

4. GDPR Rights (EU Users)

If you are located in the European Union, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain data processing
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with a supervisory authority

To exercise these rights, please contact us at support@rupali.ai. We will respond to GDPR data requests within 30 days.

4.1 Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a data protection supervisory authority. In the EU, you can contact the authority in your country of residence. Find your local data protection authority.

4.2 Age Requirements

You must be at least 18 years old to use Rupali AI. By using our service, you confirm that you are at least 18 years of age. We do not knowingly collect data from users under 18. If we become aware that data from a user under 18 has been collected, we will delete it immediately.

4.3 AI Training & Your Data

Rupali AI does NOT use your prompts or generated content to train our own AI models.Your creative content remains private and is primarily used to provide the service you requested.
Our AI Provider may temporarily store processing data (such as logs or metadata) for system performance, safety, caching, and abuse prevention, but they do not use your inputs or outputs to train their models unless explicitly stated in their own policies. Their handling of logs is governed by their privacy terms. We do not share your content with other third parties for AI training purposes without your explicit consent.


When you generate media using our Service, your prompts, parameters, and any uploaded media (e.g. images) are transmitted to our AI Provider for processing. Our AI Provider may operate servers in the EU or in other jurisdictions, depending on model availability and operational requirements.


We process certain metadata (e.g., content safety scores) to detect prohibited content. This processing is based on our legitimate interest in ensuring platform safety and compliance with legal obligations.

5. Data Retention

We retain your personal information only as long as necessary to provide our services and comply with legal obligations.

AI Provider Retention Policies
Our AI Provider may temporarily store processing data, technical logs (e.g., prompt processing logs or model error logs) for system performance, safety, caching, or abuse detection, as permitted under their policies. These logs are controlled by the AI Provider and subject to their retention policy.

Data TypeRetention PeriodReason
Account dataUntil deletion + 30 daysService delivery & grace period
Generated contentUntil you delete them or expireYour content ownership
PromptsUntil you delete themYour content ownership
Transaction records7 yearsTax law requirement
Technical logs90 daysSecurity & debugging
Cookie consent365 daysLegal requirement

6. Third-Party Services & Sub-Processors

We use the following third-party services to provide our platform:

ProcessorPurposeLocationTransfer Mechanism
ClerkAuthenticationUSASCCs + DPF
RunwareAI Content GenerationUKSCCs
RailwayApplication HostingUSASCCs
CloudflareCDN & SecurityUSASCCs + DPF
CreemPayment Processing & Tax Compliance (Merchant of Record)Estonia (EU)EU-based
UmamiPrivacy-First Website AnalyticsUSAPrivacy-by-design (Cookie-less)

SCCs = Standard Contractual Clauses | DPF = EU-US Data Privacy Framework

7. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit and at rest, secure authentication, and regular security audits.

8. International Data Transfers

We may transfer and process your personal data outside the EU/EEA. Transfers by our AI provider or other subprocessors may occur depending on server location and availability. Where required by law, we protect transfers using appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework (DPF) for certified US companies
  • Adequacy decisions for countries deemed adequate by the EU

All subprocessors enter into Data Processing Agreements (DPAs) containing appropriate safeguards for international transfers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by email or through our service.

10. Contact Us

For privacy-related questions or to exercise your rights:

Email: support@rupali.ai

Privacy Policy — Rupali AI | Rupali AI