Privacy
Privacy Notice
Last updated September 14, 2026
Learn what personal information Aveniqa processes, why it is used, and how to manage your privacy, export your data or delete your account.
On this page
- 01Data we collect
- 02Public works and external sources
- 03Purposes and legal bases
- 04Analytics and personalized recommendations
- 05AI, infrastructure, and processors
- 06Sharing, sale, advertising, and automated processing
- 07Retention and deletion
- 08International transfers and security
- 09Your choices and rights
- 10Age, contact, and changes
Operator and privacy contact
Data we collect
We process account and verified identity data, profile fields, content and license records, follows and interactions, device and network security signals, purchases and entitlements, generation jobs, moderation and support records, consent decisions, and operational logs. Payment providers and app stores handle payment credentials; we retain transaction and entitlement records, not complete card numbers.
Public works and external sources
Works, prompts, profiles and recorded remix relationships that you share publicly can be viewed by others and may be indexed by search engines. Creative graphs show connections between public works. Aveniqa also collects AI examples from public websites, retaining known authors, source links and license information. Avoid including personal information you do not wish to disclose in public works or materials sent for generation. Use the work's report action or support route if content about you or its attribution is incorrect.
Purposes and legal bases
We use necessary data to authenticate users, provide feeds and search, process uploads and Remix jobs, secure the service, moderate content, fulfill purchases, maintain creator and accounting records, respond to requests, and comply with law. Depending on location, the basis is performance of a contract, legal obligation, legitimate interests balanced against your rights, protection of people and the service, or consent.
Analytics and personalized recommendations
Product analytics and personalized recommendations have separate account settings. They are enabled by the service default unless you have turned them off; your saved choices take precedence. Refusing either does not block guest browsing. Without recommendation permission, the service uses non-personalized cold-start, following, recency, or popularity signals. You may withdraw either choice, remove interests, or reset recommendations. Required payment, generation, moderation, security, and audit records are not controlled by these optional switches.
AI, infrastructure, and processors
On-site generation sends the task's prompt, parameters and reference materials to the provider identified in the quote. Supabase supports authentication; Cloudflare may support media storage and delivery; the payment service shown at checkout handles Web payments. Model services may involve OpenAI, Google or compatible interfaces; the recipient is the provider identified for the task.
Product analytics follows your privacy settings. PostHog and Sentry are currently disabled; analytics events and client diagnostics are not sent to either service. Optional first-party analytics and personalized recommendations remain separately controllable in the Privacy center.
Sharing, sale, advertising, and automated processing
We disclose data only to contracted service providers, rights holders or transaction parties where needed, professional advisers, and authorities where legally required. The current service does not sell personal data, share it for cross-context behavioral advertising, or use third-party advertising. Recommendation ranking does not make legal or similarly significant decisions about you.
Retention and deletion
Recommendation signals are subject to a 30-day cleanup window; turning off recommendations or deleting an account also triggers the relevant cleanup. Account, transaction, reward, license, moderation, security and dispute records are retained as needed to provide the service, meet legal obligations and handle disputes. Account deletion revokes sessions and starts cleanup; required transaction records and evidence of valid public licenses do not disappear immediately.
International transfers and security
The website server is located in Finland. Authentication, media, payment and model services may process data in other regions. Processing locations and transfer requirements depend on the feature and its providers. Access controls, encryption in transit, restricted service permissions and audit records help protect data and investigate security incidents.
Your choices and rights
The product provides profile controls, separate privacy choices, data export, recommendation reset, and account deletion. Depending on location, you may request access, correction, deletion, portability, restriction, objection, withdrawal, or an appeal, and may lodge a complaint with a regulator. We may verify identity before fulfilling a request and will not discriminate for exercising applicable rights.
Age, contact, and changes
The service is not offered to anyone under 18. Material changes that affect an optional purpose require a new notice version and a fresh choice for that purpose. Contact the published privacy mailbox for rights requests; urgent child-safety reports use the dedicated safety route.