Privacy Policy

Last updated: September 13, 2026

This policy describes information handling on the AI Renovation website at airenovation.io (the “Service”). AI Renovation is the service name. The legal name and business address of the operator are not currently identified in the website materials. Privacy questions and requests can be sent to support@airenovation.io.

1. Information the Service Handles

  • Account information. Firebase Authentication handles sign-in information. Depending on how you sign in, this can include your email address, display name, authentication provider, account identifier, verification status, and account creation time. AI Renovation does not receive your full payment-card number from Stripe.
  • Photos and generation content. The Service handles photos you upload, file names, file types and sizes, prompts, tool choices, generated images and videos, project and design names, and related generation records. A generation record can include links to the source and generated media, the prompt, tool label, request identifier, and time created.
  • Subscription and transaction records. The Service stores plan, usage, subscription status, provider identifiers, and billing-period information. Stripe processes web payments. RevenueCat may be used to verify a linked subscription entitlement.
  • Support and privacy requests. We handle the contact details and message you provide. The current account-deletion request endpoint sends your account ID, email address, and optional reason to Telegram so the request can be reviewed.
  • Website and device activity. The Service uses PostHog, Google Analytics and Google Ads, Hotjar, and the Meta Pixel. These tools can collect page views, clicks, form interactions, time on page, performance and error information, referral details, browser or device information, IP address, and cookie or local-storage identifiers when you allow the corresponding optional tools. Usage analytics uses Google Analytics and PostHog, with PostHog session recording disabled. Hotjar recordings have a separate optional choice; recordings can contain visible page content and interactions. Application and provider logs can also contain account or request identifiers, file metadata, media links, prompt details, error details, and billing-status information.

2. How Information Is Used

The Service uses this information to:

  • authenticate users and maintain account, project, generation, and subscription records;
  • upload photos, process prompts, and return generated images or videos;
  • provide downloads, recent-generation history, saved projects, and customer support;
  • process payments and confirm subscription access and credit usage;
  • send account messages, including welcome and password-reset emails;
  • measure use, diagnose errors, understand website interactions, and measure advertising; and
  • protect the Service, prevent abuse, and comply with legal obligations.

Photos, prompts, and generated content are processed by fal.ai and models made available through fal.ai. Its API termsgenerally restrict training on client content, but state an exception for models designated “Pending Enterprise Ready” or another notified designation. The provider catalog listed the currently configured image and video models as enterprise ready when checked on September 10, 2026. Account-specific notices, effective service terms, and retention settings have not been verified, so AI Renovation does not make a categorical promise that uploaded content is never used for model training.

3. Service Providers and Disclosure

Information is disclosed to providers as needed for the functions described above:

  • Google Firebase for authentication, database records, and stored video files, and Google for sign-in, analytics, and advertising measurement;
  • fal.ai for photo upload, image and video generation, and media delivery;
  • Stripe for web checkout, payments, billing records, and the customer billing portal;
  • RevenueCat for linked subscription-entitlement verification;
  • PostHog and Hotjar for product analytics, heatmaps, error or performance information, and session replay;
  • Meta for advertising measurement through the Meta Pixel;
  • SendGrid for account email and Telegram for routing account-deletion requests; and
  • Vercel for website hosting and server execution.

These providers process information under their own terms and privacy notices and may process it outside your country. We may also disclose information when required by law or when reasonably necessary to protect users, the Service, or others. The analytics and advertising disclosures above may be treated as a “sale” or “sharing” under some privacy laws even when no money is paid for the information.

4. Storage, Media Links, and Retention

Account, billing, upload, prompt, generation, project, and video-job records are stored in Firebase services. Uploaded images and generated image outputs are hosted by fal.ai. Completed video files are copied to Firebase Storage. The Service stores links to this media in its records. The configured video-storage bucket is in US-CENTRAL1. Its soft-delete policy retains deleted objects for seven days, as checked on September 13, 2026; removing a file from active storage does not mean that retained copy disappears immediately.

fal.ai media links are public links: anyone who obtains a link may be able to open the file until it expires or is deleted. Firebase video download links contain access tokens and should also be treated as private links that can be opened by anyone who obtains them. Do not upload photos you do not have permission to use, or photos containing information you would not want exposed if a link were shared.

AI Renovation has not established a verified, fixed retention period for these records and files. fal.ai stores request inputs and outputs by default, and the Service does not currently call fal.ai's media-deletion API. Deleting an upload, saved design, or project record from Firebase therefore does not by itself establish that the underlying fal.ai file was erased. Provider logs, security records, backups, and transaction records may follow separate retention rules. Contact us for a request concerning particular content or an account.

5. Cookies, Local Storage, and Recording

Google, PostHog, Hotjar, Meta, Firebase Authentication, and the Service may place or read cookies or browser storage. PostHog is configured to persist identifiers in cookies and local storage. The video workflow also temporarily stores an in-progress request in local storage so a refresh does not submit the same paid request twice. Optional usage analytics, session recordings, and advertising measurement remain off until you allow the corresponding choice. Use the Privacy choices button to accept, decline or change each category. Saving refreshes the page to stop previously loaded tools. Anonymous choices stay in that browser. After sign-in, the current account choice is loaded before optional account tracking can start and is kept separate from other accounts used in the same browser. Choices expire after 180 days. A pending withdrawal keeps optional tools off locally and a failed account synchronization is shown for retry. Essential sign-in, payment processing and security records continue regardless of these optional choices. A withdrawal does not erase information already collected; contact us to request access or deletion. You can also use browser controls to block or clear storage, although essential features may stop working.

6. Security

The Service uses HTTPS, authentication checks on account APIs, and provider access controls. No method of transmission or storage is completely secure. Keep media links and account access private, and contact us if you believe your information has been exposed.

7. Access, Correction, Export, and Deletion Requests

Depending on where you live, you may have rights to ask about, access, correct, export, delete, restrict, or object to certain handling of your personal information, and to appeal a decision. These rights are subject to applicable law and exceptions.

Email support@airenovation.iofrom the address linked to your account and describe your request. We may need to verify your identity. Email us for account-deletion or data-export requests; no automatic deletion or completion time is promised here. A request may be limited by legal requirements, fraud or security needs, transaction records, backups, or a provider's available controls. Request help with your data if you need the support contact details.

8. Changes to This Policy

We may update this policy as the Service and its providers change. The date at the top shows when this page was last updated. Material claims should be rechecked against the live configuration and provider terms before relying on an older version.

9. Contact

Email privacy questions and requests to support@airenovation.io.