Privacy Policy

Boros Studio LLC

Last updated: 31 July 2026

1. Scope — What This Policy Covers

This Privacy Policy explains how Boros Studio LLC ("Boros Studio", "we", "us", "our") collects, uses, shares and protects personal data.

It applies to all of our products and services: our website at boros.studio, and every application, website, subscription and digital product operated, published or sold by Boros Studio LLC (each a "Product", and collectively the "Services").

Individual Products publish their own privacy notices with detail specific to that Product — the categories of content it processes and the providers it relies on. Those notices supplement this policy; they do not replace it. This policy always applies to your account, your purchases and your billing data, whichever Product you use.

2. Who Is Responsible For Your Data

Data controller
BOROS STUDIO LLC
1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States
info@boros.studio

Third-party technical providers engaged by us to develop and operate certain Products act as data processors on our instructions only. They do not determine how your data is used and they do not use it for their own purposes.

For all privacy requests — access, correction, deletion, portability, objection, or withdrawal of consent — write to info@boros.studio. We respond within 30 days.

3. Data We Collect

3.1 Data you give us

  • Account data — name or display name, email address, password or authentication identifier. If you sign in through a third-party identity provider, we receive a limited identifier from that provider.
  • Content you submit — the prompts, messages, images, files and other material you send to a Product in order to receive a response or use a feature.
  • Purchase data — the information needed to complete a purchase, submitted through our payment providers (see Section 5).
  • Support communications — the content of your emails, support tickets and in-product feedback.

3.2 Data we collect automatically

  • Technical data — IP address, device model, operating system and version, browser type, language, approximate location derived from IP address.
  • Usage data — pages and screens viewed, features used, session timestamps, interaction events, crash and error reports.
  • Cookies and similar technologies — see Section 9.

3.3 Data about your subscription

Subscription status, plan, purchase date, billing period, renewal date, cancellation date, payment-provider customer and transaction identifiers, and the outcome of each charge attempt (approved, declined, refunded, disputed).

3.4 Voice features

Where a Product offers a voice feature, it is text-to-speech only unless that Product's own notice expressly states otherwise: the Product generates synthetic speech from text. We do not record your voice and we do not create voiceprints or biometric identifiers.

3.5 Data we do not collect

We do not receive or store your full card number or your card security code (CVC/CVV). Those are captured directly by our payment providers.

4. Why We Process Your Data, And On What Legal Basis

PurposeLegal basis (GDPR / UK GDPR)
Create and maintain your account, deliver the Product you signed up forPerformance of a contract
Process your purchase, manage your subscription, issue receipts and refundsPerformance of a contract
Route your payment to a provider and select the appropriate providerLegitimate interest (reliable payment processing)
Respond to your support, cancellation, billing and privacy requestsPerformance of a contract; legal obligation
Send transactional email — receipts, renewal reminders, cancellation confirmations, security alertsPerformance of a contract
Detect and prevent fraud, abuse, chargeback fraud and security incidentsLegitimate interest; legal obligation
Moderate content and enforce our Acceptable Use rulesLegitimate interest; legal obligation
Maintain, debug and improve the ServicesLegitimate interest
Marketing email and advertising measurementConsent
Comply with tax, accounting, payment-network and other legal obligationsLegal obligation

Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.

5. Payment And Billing Data — What Each Provider Receives

Payments for purchases made on our websites are processed on our behalf by one or more third-party payment service providers. Which provider handles a given transaction depends on the checkout, your region and your payment method.

  • Stripe Payments Europe Ltd. (Ireland) — website card payments. Data shared: first and last name, email address, billing address or country where collected, card brand, the last four digits and expiry date of your card, card BIN and BIN country, transaction date, amount, currency, IP address, device and browser data used for fraud screening, a recurring-billing indicator, the payment-credential token stored for renewals, and authorisation, refund, decline and dispute response codes. We do not receive your full card number.
  • Adyen N.V. (Amsterdam, Netherlands) — website card payments. Data shared: the same categories as Stripe.
  • Unlimit (Unlimint EU Ltd, Limassol, Cyprus for EU/EEA users; Unlimit UK Ltd, London, United Kingdom for other users) — website card payments. Data shared: the same categories as Stripe.
  • Payrails GmbH (Berlin, Germany) — payment orchestration; routes each transaction to the appropriate provider above. Data shared: transaction routing metadata, tokenised payment identifiers, amount, currency, transaction and customer identifiers, payment-method type, the provider selected, the result of each attempt, IP address and device metadata. Payrails does not receive your full card number.
  • Outpost Technologies Ltd. (United Kingdom) — Merchant of Record and seller of record for the Outpost checkout channel. For purchases made through that channel, Outpost processes your order, billing, payment, tax and transaction data as an independent controller under its own privacy policy at https://outpost.ai/privacy-policy/. Data shared: the order, billing and payment information necessary to complete and support your purchase.
  • We may engage other payment service providers from time to time for card processing on our website channel.

Where you purchase through an app-store account, that store is the Merchant of Record for the transaction, payment is handled entirely under that store's own policies, and we receive transaction and subscription status rather than your card data.

We do not receive or store your full card number or security code. Our payment providers are independent controllers for their own fraud-prevention, regulatory and payment-network obligations, and they process your data under their own privacy policies in addition to their contracts with us.

Disputes and chargebacks. If you dispute a charge with your bank, the payment network requires us to submit evidence about the transaction. That evidence may include your account email, the date and IP address of the purchase, the plan and price you accepted at checkout, your acceptance of these terms, the delivery and usage record of the paid features, your cancellation and refund history, and our correspondence with you. We process this data to establish or defend a legal claim and to meet our obligations to the payment networks.

Tax and accounting. Transaction records are shared with our accountants, auditors and tax authorities where required by law.

6. AI Providers And Your Content

Where a Product uses artificial intelligence, the content you submit is sent to model providers to generate the response you asked for. Each Product's own notice identifies the providers that Product relies on. Across our Products these currently include:

  • OpenAI Inc. (USA) — AI text generation. Data shared: the content of your messages and prompts, with conversation context.
  • OpenRouter / X.AI (Grok) (USA) — alternative AI text generation. Data shared: same scope as OpenAI.
  • ElevenLabs Inc. (USA) — speech synthesis for voice features. Data shared: the text to be converted to speech. Your own voice is not sent, recorded or stored.
  • fal.ai (USA) — AI image and video generation. Data shared: text prompts.
  • getimg.ai — image generation. Data shared: text prompts.

Training. We contract with these providers on terms that restrict use of your content to serving your request and prohibit its use to train their own foundation models.

Separately, we may use interactions that have been aggregated, de-identified and/or anonymised to improve our own Services and safety systems. Where re-identification is not reasonably possible, such data is no longer personal data — and such data survives the deletion of your account.

Human review. A limited number of trained personnel may review de-identified interactions for safety, moderation and quality purposes.

7. Other Recipients

We work with the following third-party service providers. Each has access only to the data necessary to perform its function and is contractually obliged to protect it. Which of these applies to you depends on the Product you use; each Product's own notice lists the providers specific to it.

7.1 Infrastructure and storage

  • Amazon Web Services — cloud hosting and object storage for Service content. Data shared: the account data and content stored in order to operate the Services. Data centres may be located in the EU (Frankfurt, eu-central-1) or the USA depending on the resource.
  • Vercel and Google Cloud — website hosting and deployment. Data shared: web application hosting data and request logs.

Our own databases and caches (for example PostgreSQL and Redis) are internal components operated within the infrastructure above, not separate third-party recipients.

7.2 Analytics and error reporting

  • Google Firebase Analytics / Google Analytics (Google LLC, USA) — app and web behaviour analytics. Data shared: pseudonymous event data, device identifiers, IP address.
  • Sentry (Functional Software Inc., USA) — application error tracking. Data shared: crash and error diagnostics, device model and OS, application version, technical request context.
  • Firebase Crashlytics (Google LLC, USA) — crash reporting. Data shared: crash reports, device model and OS, application version.
  • Microsoft Clarity (Microsoft Corporation, USA) — session-replay and heatmap analytics on our websites. Data shared: anonymised interaction and session-replay data.
  • AppsFlyer Ltd. (Israel) — mobile attribution and marketing analytics. Data shared: mobile device identifiers, IP address, installation events, purchase events, for advertising attribution.

7.3 Advertising and marketing

  • Meta / Facebook (Meta Platforms Ireland Ltd.) — advertising, retargeting and audience building. Data shared: hashed email, device identifier, app and web events (signup, purchase), aggregated audience signals.
  • Google Ads (Google LLC) — search and display advertising, conversion tracking. Data shared: Google Click ID, hashed email, conversion events.
  • TikTok Ads (TikTok Pte. Ltd.) — install and conversion campaigns. Data shared: hashed email, install and purchase events.
  • Snapchat Ads (Snap Inc.) — install and conversion campaigns. Data shared: device identifier, install events.

7.4 Email, notifications and support

  • Resend — transactional email delivery (sign-in links, receipts, renewal reminders, cancellation confirmations, account notices). Data shared: your email address and delivery/open status.
  • Firebase Cloud Messaging (Google LLC) — push notification delivery. Data shared: your device push token.
  • Pushwoosh — push campaign management and engagement analytics. Data shared: device push token, device identifier, engagement events.
  • Zendesk (Zendesk Inc., USA) — customer support ticketing. Data shared: the content of your support messages, your contact details, and your account and subscription reference.

7.5 Consent management

  • Cookiebot — cookie-consent management on our websites. Data shared: your consent choices, consent timestamp, pseudonymous identifier.

7.6 Professional advisers, legal and compliance

We may disclose personal data to our legal, accounting and audit advisers, and to law enforcement, courts, regulators or other authorities, where required by applicable law, subpoena or court order — limited in each case to the data the specific matter or lawful request requires.

7.7 We do not sell your personal data

We do not sell your personal data to third parties for monetary consideration. Our use of the advertising and attribution partners in Sections 7.2 and 7.3 constitutes "sharing" for cross-context behavioural advertising under the CPRA. You may opt out through the "Do Not Sell or Share My Personal Information" control in our cookie-consent banner, through your device advertising settings, or by sending a Global Privacy Control (GPC) signal, which we honour. See also Section 11.2.

Business transfer. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction; it remains subject to this policy or to a policy at least as protective, and we will notify you of any material change.

8. International Transfers

We are established in the United States and our providers operate in a number of countries, so your personal data may be transferred to and processed outside your country of residence — including the United States, the United Kingdom, Israel, and EU member states such as Ireland, Cyprus, Germany and the Netherlands.

Where we transfer personal data from the EEA or the UK, we rely on the appropriate mechanism for each recipient: an adequacy decision where one applies (Israel, for example, benefits from an EU adequacy decision); the EU-US Data Privacy Framework and its UK extension where the recipient is certified; and the European Commission's or UK Standard Contractual Clauses, with supplementary technical and organisational measures, in all other cases. You may request details of the mechanism applying to a specific recipient by writing to info@boros.studio.

9. Cookies And Similar Technologies

Our websites use cookies and similar technologies in the following categories:

  • Strictly necessary — session management, security, load balancing, fraud prevention and checkout functionality. These cannot be switched off.
  • Preference — remembering your language, region and display settings.
  • Analytics — understanding how the website and Products are used so we can improve them.
  • Advertising — measuring campaign performance and, where applicable, delivering relevant advertising.

Non-essential cookies are set only where you consent. You can change or withdraw your choices at any time through the cookie settings on the website, and you can block or delete cookies in your browser. Where legally required, we honour the Global Privacy Control (GPC) signal as a valid opt-out.

10. How Long We Keep Data

DataRetention
Account dataWhile your account is active
Content you submitWhile your account is active, then deleted within 30 days of account deletion
Backups containing your dataPurged on a rolling schedule, normally within 60 days of deletion
Billing and transaction recordsAs required by tax, accounting and payment-network rules — typically up to 7 years — regardless of account deletion
Dispute and chargeback evidenceFor the duration of the dispute and any applicable limitation period
Server and security logsUp to 90 days
Moderation and abuse recordsUp to 24 months, or longer where an ongoing safety or legal matter requires it
Aggregated, de-identified and anonymised dataRetained indefinitely; survives account deletion (Section 6)

11. Your Rights

11.1 If you are in the EEA or the UK (GDPR / UK GDPR)

You have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing, including processing based on legitimate interest; to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your national supervisory authority.

11.2 If you are in California (CCPA / CPRA)

You have the right to know what personal information we collect, use, disclose and share; to access and to delete it; to correct inaccurate information; to opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights. We do not sell personal information for money. To opt out of advertising-related sharing, use the cookie settings on our website, send a Global Privacy Control signal, or write to info@boros.studio. An authorised agent may submit a request on your behalf with proof of authorisation.

11.3 If you are in Türkiye (KVKK, Law No. 6698)

Under Article 11 you have the right to learn whether your personal data is processed; to request information about the processing; to learn its purpose and whether the data is used in accordance with that purpose; to know the third parties to whom data is transferred domestically or abroad; to request correction of incomplete or inaccurate data; to request erasure or destruction under Article 7; to require that any correction or erasure be notified to the third parties concerned; to object to a decision produced solely by automated processing that adversely affects you; and to claim compensation for damage arising from unlawful processing.

11.4 Automated decision-making

We use automated systems to screen payments for fraud and to detect content that breaches our Acceptable Use rules. Where an automated decision significantly affects you, you may request human review by writing to info@boros.studio.

11.5 Exercising your rights

Write to info@boros.studio from the address on your account. We may need to verify your identity before acting. We respond within 30 days and will tell you if we need longer.

12. Security

We apply administrative, technical and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure and destruction. These include encryption in transit (TLS) and at rest, role-based access control on a least-privilege basis, audit logging, and regular dependency and vulnerability scanning.

No system is perfectly secure, and no transmission over the internet can be guaranteed to be fully secure. If you believe your account has been compromised, or if you have found a security issue, write to info@boros.studio immediately.

13. Children

The Services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a minor is using the Services, contact info@boros.studio.

14. Changes To This Policy

We may update this policy. We indicate changes by updating the "Last updated" date above, and where a change materially affects your rights we notify you by email or through the Services in advance of it taking effect.

15. Contact

BOROS STUDIO LLC

1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States

E-mail: info@boros.studio

We answer within 48 hours, and complete formal privacy requests within 30 days.