Privacy Policy
Last updated August 16, 2026
This Privacy Policy explains what data Twindra ("we," "us") collects when you use the service, why, and who it's shared with. It's written to describe what this product actually does, not a generic template. Under GDPR, the data controller is Kilian Becher, operating as an Austrian sole proprietor (Einzelunternehmer) trading as Twindra, based in Vienna, Austria — reachable at support@twindra.app. Registered business address: Linzer Straße 18, 1140 Vienna, Austria.
1. Data we collect
- Account data — email address and password (hashed, via Supabase Auth — we never see or store your plaintext password), account creation date.
- Persona & preference data — the attributes you choose when building a persona (age, appearance preferences, etc.) and, if you use the photo-upload path, the images you upload and the self-attestation consent you give alongside them (see Terms Section 5).
- Generated content — every image and video you generate, the prompts/settings used to generate it, and its moderation-check result (see our content moderation pipeline, described in the README and referenced in Terms Section 6).
- Billing data — we do not store your card number or full payment details ourselves; those are handled directly by our payment processor. We store your token balance, transaction history, and plan tier.
- Usage & log data — standard server logs (IP address, timestamps, request paths) collected by our hosting and infrastructure providers for security and debugging.
- Optional third-party connections — if you connect a Fanvue creator account (Settings page), we store the OAuth connection scope and tokens needed to post on your behalf. Nothing is posted without an explicit action from you.
2. How we use it
To operate the service: authenticate you, generate the content you request, run moderation checks before content is shown to you, process payments, respond to support requests, and comply with legal obligations (including the NCII removal process described on our report page). We do not sell your personal data, and we do not use your uploaded photos or generated content to train models for any purpose beyond your own account's persona/LoRA features that you explicitly initiate.
3. Who we share it with
We share data with the following categories of processor, each strictly to perform the function they're providing — not for their own independent use:
- Supabase — database, authentication, and file storage (uploaded photos, generated content).
- fal.ai — receives your prompts and any reference images you submit in order to run the actual AI generation. This is unavoidable: it is the infrastructure most generation runs on.
- Atlas Cloud and WaveSpeedAI — receive your prompts and reference images for specific engines within Uncensored Studio (persona LoRA image generation, and the Wan and Seedance "Spicy" video engines) that run on their infrastructure instead of fal.ai's. Same purpose and handling as fal.ai above — generation infrastructure only, not used for anything beyond running the request you made.
- Payment processor — all subscriptions and purchases are billed through Fanvue Payments once you connect your Fanvue account; Fanvue receives what's needed to process a payment, and we never see your full card number. An earlier Stripe integration used during development is disabled in production and is not used to process real payments.
- SocialKit — if you use video or Image Studio Recreate's "paste a link" feature, the pasted URL is sent to SocialKit to resolve a direct video file (video Recreate) or a thumbnail image (Image Studio Recreate). No account or profile data is sent, only the URL itself.
- Fanvue — only if you explicitly connect your Fanvue account in Settings, and only to the extent of the OAuth scopes you approve at connection time.
- Sentry — error monitoring. When something fails server-side (a generation, a webhook, a payment sync), we send Sentry the error details needed to diagnose it, which can include your account ID and the ID of the persona or generation involved — never your uploaded images, generated content, or prompt text itself.
- Law enforcement / NCMEC — where legally required, per Terms Section 7, in cases involving suspected child sexual abuse material.
4. Data retention
Account data, persona data, and generated content are retained for as long as your account is active. Some categories are intentionally short-lived by design: reference photos and video clips uploaded for one-time use (LoRA training image sets, video Recreate's uploaded reference clips, Image Studio Recreate's uploaded source photo, Face Swap's target photo) are deleted from storage once the job that needed them has settled — they are not retained as a separate archive. Image Studio Recreate's "paste a link" path (TikTok/Instagram) never stores anything on our side at all — the resolved image URL is used directly and only exists on the third-party service (SocialKit) that resolved it. Content blocked by our moderation pipeline is not shown or stored as a usable asset; the moderation decision and reason are retained on the record for audit purposes even when the underlying content itself is discarded.
5. Your rights & account deletion
Depending on your location, you may have rights to access, correct, export, or delete your personal data (for example under GDPR or CCPA). You can permanently delete your account, every persona, all generated content, and your token history at any time from the Settings page — this takes effect immediately and does not require contacting support. For any other data right (access, correction, or export), email support@twindra.app from your account's email address; we aim to fulfill these requests within 30 days.
6. Children's privacy
Twindra is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from anyone under 18. If we learn that someone under 18 has created an account, we will terminate it and delete associated data.
7. International data transfers
Our infrastructure providers (Supabase, fal.ai, and others listed above) may process data in countries other than your own, including the United States. Where required, we rely on standard contractual clauses or equivalent safeguards provided by those processors.
8. Cookies
See our Cookie Policy for what cookies Twindra sets and why.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
10. Contact
Questions about this policy, or to exercise a data right: support@twindra.app.