Privacy Policy
Last updated August 16, 2026
This Privacy Policy explains what data Twindra ("we," "us") collects when you use the service, why, and who it's shared with. It's written to describe what this product actually does, not a generic template. Under GDPR, the data controller is Kilian Becher, operating as an Austrian sole proprietor (Einzelunternehmer) trading as Twindra, based in Vienna, Austria — reachable at support@twindra.app. Registered business address: Linzer Straße 18, 1140 Vienna, Austria.
1. Data we collect
- Account data — email address and password (hashed, via Supabase Auth — we never see or store your plaintext password), account creation date.
- Persona & preference data — the attributes you choose when building a persona (age, appearance preferences, etc.) and, if you use the photo-upload path, the images you upload and the self-attestation consent you give alongside them (see Terms Section 5).
- Generated content — every image and video you generate, the prompts/settings used to generate it, and its moderation-check result (see our content moderation pipeline, described in the README and referenced in Terms Section 6).
- Billing data — we do not store your card number or full payment details ourselves; those are handled directly by our payment processor. We store your token balance, transaction history, and plan tier.
- Usage & log data — standard server logs (IP address, timestamps, request paths) collected by our hosting and infrastructure providers for security and debugging.
- Optional third-party connections — if you connect a Fanvue creator account (Settings page), we store the OAuth connection scope and tokens needed to post on your behalf. Nothing is posted without an explicit action from you.
2. How we use it
To operate the service: authenticate you, generate the content you request, run moderation checks before content is shown to you, process payments, respond to support requests, and comply with legal obligations (including the NCII removal process described on our report page). We do not sell your personal data, and we do not use your uploaded photos or generated content to train models for any purpose beyond your own account's persona/LoRA features that you explicitly initiate.
3. Who we share it with
We share data with the following categories of processor, each strictly to perform the function they're providing — not for their own independent use:
- Supabase — database, authentication, and file storage (uploaded photos, generated content).
- fal.ai — receives your prompts and any reference images you submit in order to run the actual AI generation. This is unavoidable: it is the infrastructure generation runs on.
- Payment processor (currently Stripe for non-adult-content billing scaffolding — see README for why this is being migrated to an adult-content-compatible processor) — receives what's needed to process a payment. We never see your full card number.
- SocialKit — if you use Recreate's "paste a link" feature, the pasted URL is sent to SocialKit to resolve a direct video file. No account or profile data is sent, only the URL itself.
- Fanvue — only if you explicitly connect your Fanvue account in Settings, and only to the extent of the OAuth scopes you approve at connection time.
- Law enforcement / NCMEC — where legally required, per Terms Section 7, in cases involving suspected child sexual abuse material.
4. Data retention
Account data, persona data, and generated content are retained for as long as your account is active. Some categories are intentionally short-lived by design: reference photos and video clips uploaded for one-time analysis (LoRA training image sets, Recreate's uploaded reference clips, Face Swap's target photo) are deleted from storage once the job that needed them has settled — they are not retained as a separate archive. Content blocked by our moderation pipeline is not shown or stored as a usable asset; the moderation decision and reason are retained on the record for audit purposes even when the underlying content itself is discarded.
5. Your rights & account deletion
Depending on your location, you may have rights to access, correct, export, or delete your personal data (for example under GDPR or CCPA). You can permanently delete your account, every persona, all generated content, and your token history at any time from the Settings page — this takes effect immediately and does not require contacting support. For any other data right (access, correction, or export), email support@twindra.app from your account's email address; we aim to fulfill these requests within 30 days.
6. Children's privacy
Twindra is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from anyone under 18. If we learn that someone under 18 has created an account, we will terminate it and delete associated data.
7. International data transfers
Our infrastructure providers (Supabase, fal.ai, and others listed above) may process data in countries other than your own, including the United States. Where required, we rely on standard contractual clauses or equivalent safeguards provided by those processors.
8. Cookies
See our Cookie Policy for what cookies Twindra sets and why.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
10. Contact
Questions about this policy, or to exercise a data right: support@twindra.app.