Privacy Policy

Last updated August 16, 2026

This Privacy Policy explains what data Twindra ("we," "us") collects when you use the service, why, and who it's shared with. It's written to describe what this product actually does, not a generic template. Under GDPR, the data controller is Kilian Becher, operating as an Austrian sole proprietor (Einzelunternehmer) trading as Twindra, based in Vienna, Austria — reachable at support@twindra.app. Registered business address: Linzer Straße 18, 1140 Vienna, Austria.

1. Data we collect

2. How we use it

To operate the service: authenticate you, generate the content you request, run moderation checks before content is shown to you, process payments, respond to support requests, and comply with legal obligations (including the NCII removal process described on our report page). We do not sell your personal data, and we do not use your uploaded photos or generated content to train models for any purpose beyond your own account's persona/LoRA features that you explicitly initiate.

3. Who we share it with

We share data with the following categories of processor, each strictly to perform the function they're providing — not for their own independent use:

4. Data retention

Account data, persona data, and generated content are retained for as long as your account is active. Some categories are intentionally short-lived by design: reference photos and video clips uploaded for one-time analysis (LoRA training image sets, Recreate's uploaded reference clips, Face Swap's target photo) are deleted from storage once the job that needed them has settled — they are not retained as a separate archive. Content blocked by our moderation pipeline is not shown or stored as a usable asset; the moderation decision and reason are retained on the record for audit purposes even when the underlying content itself is discarded.

5. Your rights & account deletion

Depending on your location, you may have rights to access, correct, export, or delete your personal data (for example under GDPR or CCPA). You can permanently delete your account, every persona, all generated content, and your token history at any time from the Settings page — this takes effect immediately and does not require contacting support. For any other data right (access, correction, or export), email support@twindra.app from your account's email address; we aim to fulfill these requests within 30 days.

6. Children's privacy

Twindra is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from anyone under 18. If we learn that someone under 18 has created an account, we will terminate it and delete associated data.

7. International data transfers

Our infrastructure providers (Supabase, fal.ai, and others listed above) may process data in countries other than your own, including the United States. Where required, we rely on standard contractual clauses or equivalent safeguards provided by those processors.

8. Cookies

See our Cookie Policy for what cookies Twindra sets and why.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.

10. Contact

Questions about this policy, or to exercise a data right: support@twindra.app.