Privacy Policy
Boros Studio LLC
Last updated: 31 July 2026
1. Scope — What This Policy Covers
This Privacy Policy explains how Boros Studio LLC ("Boros Studio", "we", "us", "our") collects, uses, shares and protects personal data.
It applies to all of our products and services: our website at boros.studio, and every application, website, subscription and digital product operated, published or sold by Boros Studio LLC (each a "Product", and collectively the "Services").
Individual Products publish their own privacy notices with detail specific to that Product — the categories of content it processes and the providers it relies on. Those notices supplement this policy; they do not replace it. This policy always applies to your account, your purchases and your billing data, whichever Product you use.
2. Who Is Responsible For Your Data
Data controller
BOROS STUDIO LLC
1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States
info@boros.studio
Third-party technical providers engaged by us to develop and operate certain Products act as data processors on our instructions only. They do not determine how your data is used and they do not use it for their own purposes.
For all privacy requests — access, correction, deletion, portability, objection, or withdrawal of consent — write to info@boros.studio. We respond within 30 days.
3. Data We Collect
3.1 Data you give us
- Account data — name or display name, email address, password or authentication identifier. If you sign in through a third-party identity provider, we receive a limited identifier from that provider.
- Content you submit — the prompts, messages, images, files and other material you send to a Product in order to receive a response or use a feature.
- Purchase data — the information needed to complete a purchase, submitted through our payment providers (see Section 5).
- Support communications — the content of your emails, support tickets and in-product feedback.
3.2 Data we collect automatically
- Technical data — IP address, device model, operating system and version, browser type, language, approximate location derived from IP address.
- Usage data — pages and screens viewed, features used, session timestamps, interaction events, crash and error reports.
- Cookies and similar technologies — see Section 9.
3.3 Data about your subscription
Subscription status, plan, purchase date, billing period, renewal date, cancellation date, payment-provider customer and transaction identifiers, and the outcome of each charge attempt (approved, declined, refunded, disputed).
3.4 Voice features
Where a Product offers a voice feature, it is text-to-speech only unless that Product's own notice expressly states otherwise: the Product generates synthetic speech from text. We do not record your voice and we do not create voiceprints or biometric identifiers.
3.5 Data we do not collect
We do not receive or store your full card number or your card security code (CVC/CVV). Those are captured directly by our payment providers.
4. Why We Process Your Data, And On What Legal Basis
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Create and maintain your account, deliver the Product you signed up for | Performance of a contract |
| Process your purchase, manage your subscription, issue receipts and refunds | Performance of a contract |
| Route your payment to a provider and select the appropriate provider | Legitimate interest (reliable payment processing) |
| Respond to your support, cancellation, billing and privacy requests | Performance of a contract; legal obligation |
| Send transactional email — receipts, renewal reminders, cancellation confirmations, security alerts | Performance of a contract |
| Detect and prevent fraud, abuse, chargeback fraud and security incidents | Legitimate interest; legal obligation |
| Moderate content and enforce our Acceptable Use rules | Legitimate interest; legal obligation |
| Maintain, debug and improve the Services | Legitimate interest |
| Marketing email and advertising measurement | Consent |
| Comply with tax, accounting, payment-network and other legal obligations | Legal obligation |
Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.
5. Payment And Billing Data — What Each Provider Receives
Payments for purchases made on our websites are processed on our behalf by one or more third-party payment service providers. Which provider handles a given transaction depends on the checkout, your region and your payment method.
- Stripe Payments Europe Ltd. (Ireland) — website card payments. Data shared: first and last name, email address, billing address or country where collected, card brand, the last four digits and expiry date of your card, card BIN and BIN country, transaction date, amount, currency, IP address, device and browser data used for fraud screening, a recurring-billing indicator, the payment-credential token stored for renewals, and authorisation, refund, decline and dispute response codes. We do not receive your full card number.
- Adyen N.V. (Amsterdam, Netherlands) — website card payments. Data shared: the same categories as Stripe.
- Unlimit (Unlimint EU Ltd, Limassol, Cyprus for EU/EEA users; Unlimit UK Ltd, London, United Kingdom for other users) — website card payments. Data shared: the same categories as Stripe.
- Payrails GmbH (Berlin, Germany) — payment orchestration; routes each transaction to the appropriate provider above. Data shared: transaction routing metadata, tokenised payment identifiers, amount, currency, transaction and customer identifiers, payment-method type, the provider selected, the result of each attempt, IP address and device metadata. Payrails does not receive your full card number.
- Outpost Technologies Ltd. (United Kingdom) — Merchant of Record and seller of record for the Outpost checkout channel. For purchases made through that channel, Outpost processes your order, billing, payment, tax and transaction data as an independent controller under its own privacy policy at
https://outpost.ai/privacy-policy/. Data shared: the order, billing and payment information necessary to complete and support your purchase. - We may engage other payment service providers from time to time for card processing on our website channel.
Where you purchase through an app-store account, that store is the Merchant of Record for the transaction, payment is handled entirely under that store's own policies, and we receive transaction and subscription status rather than your card data.
We do not receive or store your full card number or security code. Our payment providers are independent controllers for their own fraud-prevention, regulatory and payment-network obligations, and they process your data under their own privacy policies in addition to their contracts with us.
Disputes and chargebacks. If you dispute a charge with your bank, the payment network requires us to submit evidence about the transaction. That evidence may include your account email, the date and IP address of the purchase, the plan and price you accepted at checkout, your acceptance of these terms, the delivery and usage record of the paid features, your cancellation and refund history, and our correspondence with you. We process this data to establish or defend a legal claim and to meet our obligations to the payment networks.
Tax and accounting. Transaction records are shared with our accountants, auditors and tax authorities where required by law.
6. AI Providers And Your Content
Where a Product uses artificial intelligence, the content you submit is sent to model providers to generate the response you asked for. Each Product's own notice identifies the providers that Product relies on. Across our Products these currently include:
- OpenAI Inc. (USA) — AI text generation. Data shared: the content of your messages and prompts, with conversation context.
- OpenRouter / X.AI (Grok) (USA) — alternative AI text generation. Data shared: same scope as OpenAI.
- ElevenLabs Inc. (USA) — speech synthesis for voice features. Data shared: the text to be converted to speech. Your own voice is not sent, recorded or stored.
- fal.ai (USA) — AI image and video generation. Data shared: text prompts.
- getimg.ai — image generation. Data shared: text prompts.
Training. We contract with these providers on terms that restrict use of your content to serving your request and prohibit its use to train their own foundation models.
Separately, we may use interactions that have been aggregated, de-identified and/or anonymised to improve our own Services and safety systems. Where re-identification is not reasonably possible, such data is no longer personal data — and such data survives the deletion of your account.
Human review. A limited number of trained personnel may review de-identified interactions for safety, moderation and quality purposes.
7. Other Recipients
We work with the following third-party service providers. Each has access only to the data necessary to perform its function and is contractually obliged to protect it. Which of these applies to you depends on the Product you use; each Product's own notice lists the providers specific to it.
7.1 Infrastructure and storage
- Amazon Web Services — cloud hosting and object storage for Service content. Data shared: the account data and content stored in order to operate the Services. Data centres may be located in the EU (Frankfurt, eu-central-1) or the USA depending on the resource.
- Vercel and Google Cloud — website hosting and deployment. Data shared: web application hosting data and request logs.
Our own databases and caches (for example PostgreSQL and Redis) are internal components operated within the infrastructure above, not separate third-party recipients.
7.2 Analytics and error reporting
- Google Firebase Analytics / Google Analytics (Google LLC, USA) — app and web behaviour analytics. Data shared: pseudonymous event data, device identifiers, IP address.
- Sentry (Functional Software Inc., USA) — application error tracking. Data shared: crash and error diagnostics, device model and OS, application version, technical request context.
- Firebase Crashlytics (Google LLC, USA) — crash reporting. Data shared: crash reports, device model and OS, application version.
- Microsoft Clarity (Microsoft Corporation, USA) — session-replay and heatmap analytics on our websites. Data shared: anonymised interaction and session-replay data.
- AppsFlyer Ltd. (Israel) — mobile attribution and marketing analytics. Data shared: mobile device identifiers, IP address, installation events, purchase events, for advertising attribution.
7.3 Advertising and marketing
- Meta / Facebook (Meta Platforms Ireland Ltd.) — advertising, retargeting and audience building. Data shared: hashed email, device identifier, app and web events (signup, purchase), aggregated audience signals.
- Google Ads (Google LLC) — search and display advertising, conversion tracking. Data shared: Google Click ID, hashed email, conversion events.
- TikTok Ads (TikTok Pte. Ltd.) — install and conversion campaigns. Data shared: hashed email, install and purchase events.
- Snapchat Ads (Snap Inc.) — install and conversion campaigns. Data shared: device identifier, install events.
7.4 Email, notifications and support
- Resend — transactional email delivery (sign-in links, receipts, renewal reminders, cancellation confirmations, account notices). Data shared: your email address and delivery/open status.
- Firebase Cloud Messaging (Google LLC) — push notification delivery. Data shared: your device push token.
- Pushwoosh — push campaign management and engagement analytics. Data shared: device push token, device identifier, engagement events.
- Zendesk (Zendesk Inc., USA) — customer support ticketing. Data shared: the content of your support messages, your contact details, and your account and subscription reference.
7.5 Consent management
- Cookiebot — cookie-consent management on our websites. Data shared: your consent choices, consent timestamp, pseudonymous identifier.
7.6 Professional advisers, legal and compliance
We may disclose personal data to our legal, accounting and audit advisers, and to law enforcement, courts, regulators or other authorities, where required by applicable law, subpoena or court order — limited in each case to the data the specific matter or lawful request requires.
7.7 We do not sell your personal data
We do not sell your personal data to third parties for monetary consideration. Our use of the advertising and attribution partners in Sections 7.2 and 7.3 constitutes "sharing" for cross-context behavioural advertising under the CPRA. You may opt out through the "Do Not Sell or Share My Personal Information" control in our cookie-consent banner, through your device advertising settings, or by sending a Global Privacy Control (GPC) signal, which we honour. See also Section 11.2.
Business transfer. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction; it remains subject to this policy or to a policy at least as protective, and we will notify you of any material change.
8. International Transfers
We are established in the United States and our providers operate in a number of countries, so your personal data may be transferred to and processed outside your country of residence — including the United States, the United Kingdom, Israel, and EU member states such as Ireland, Cyprus, Germany and the Netherlands.
Where we transfer personal data from the EEA or the UK, we rely on the appropriate mechanism for each recipient: an adequacy decision where one applies (Israel, for example, benefits from an EU adequacy decision); the EU-US Data Privacy Framework and its UK extension where the recipient is certified; and the European Commission's or UK Standard Contractual Clauses, with supplementary technical and organisational measures, in all other cases. You may request details of the mechanism applying to a specific recipient by writing to info@boros.studio.
9. Cookies And Similar Technologies
Our websites use cookies and similar technologies in the following categories:
- Strictly necessary — session management, security, load balancing, fraud prevention and checkout functionality. These cannot be switched off.
- Preference — remembering your language, region and display settings.
- Analytics — understanding how the website and Products are used so we can improve them.
- Advertising — measuring campaign performance and, where applicable, delivering relevant advertising.
Non-essential cookies are set only where you consent. You can change or withdraw your choices at any time through the cookie settings on the website, and you can block or delete cookies in your browser. Where legally required, we honour the Global Privacy Control (GPC) signal as a valid opt-out.
10. How Long We Keep Data
| Data | Retention |
|---|---|
| Account data | While your account is active |
| Content you submit | While your account is active, then deleted within 30 days of account deletion |
| Backups containing your data | Purged on a rolling schedule, normally within 60 days of deletion |
| Billing and transaction records | As required by tax, accounting and payment-network rules — typically up to 7 years — regardless of account deletion |
| Dispute and chargeback evidence | For the duration of the dispute and any applicable limitation period |
| Server and security logs | Up to 90 days |
| Moderation and abuse records | Up to 24 months, or longer where an ongoing safety or legal matter requires it |
| Aggregated, de-identified and anonymised data | Retained indefinitely; survives account deletion (Section 6) |
11. Your Rights
11.1 If you are in the EEA or the UK (GDPR / UK GDPR)
You have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing, including processing based on legitimate interest; to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your national supervisory authority.
11.2 If you are in California (CCPA / CPRA)
You have the right to know what personal information we collect, use, disclose and share; to access and to delete it; to correct inaccurate information; to opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights. We do not sell personal information for money. To opt out of advertising-related sharing, use the cookie settings on our website, send a Global Privacy Control signal, or write to info@boros.studio. An authorised agent may submit a request on your behalf with proof of authorisation.
11.3 If you are in Türkiye (KVKK, Law No. 6698)
Under Article 11 you have the right to learn whether your personal data is processed; to request information about the processing; to learn its purpose and whether the data is used in accordance with that purpose; to know the third parties to whom data is transferred domestically or abroad; to request correction of incomplete or inaccurate data; to request erasure or destruction under Article 7; to require that any correction or erasure be notified to the third parties concerned; to object to a decision produced solely by automated processing that adversely affects you; and to claim compensation for damage arising from unlawful processing.
11.4 Automated decision-making
We use automated systems to screen payments for fraud and to detect content that breaches our Acceptable Use rules. Where an automated decision significantly affects you, you may request human review by writing to info@boros.studio.
11.5 Exercising your rights
Write to info@boros.studio from the address on your account. We may need to verify your identity before acting. We respond within 30 days and will tell you if we need longer.
12. Security
We apply administrative, technical and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure and destruction. These include encryption in transit (TLS) and at rest, role-based access control on a least-privilege basis, audit logging, and regular dependency and vulnerability scanning.
No system is perfectly secure, and no transmission over the internet can be guaranteed to be fully secure. If you believe your account has been compromised, or if you have found a security issue, write to info@boros.studio immediately.
13. Children
The Services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a minor is using the Services, contact info@boros.studio.
14. Changes To This Policy
We may update this policy. We indicate changes by updating the "Last updated" date above, and where a change materially affects your rights we notify you by email or through the Services in advance of it taking effect.
15. Contact
BOROS STUDIO LLC
1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States
E-mail: info@boros.studio
We answer within 48 hours, and complete formal privacy requests within 30 days.