Privacy Policy

What we keep. What we don't.

Last updated · October 3, 2026

01. Who we are

Personifex is operated by [LEGAL ENTITY], [REGISTERED ADDRESS], [COUNTRY] (company number [COMPANY NUMBER]). We are the data controller for the personal data described in this policy, except where section 03 says we act as a processor instead.

For any privacy question, request or complaint, email privacy@personifex.com. A person reads that address; it is not a ticket queue that goes nowhere.

02. What this policy covers

This policy covers the Personifex website, the application at /app, the optional Personifex Capture browser extension, and the account emails we send you. It explains what we collect, why we are allowed to, who else touches it, how long it survives, and what you can make us do about it.

It does not cover third-party sites you reach from our links, the social platforms you publish your content to, or the AI providers you connect with your own API key: each of those is governed by its own terms. Section 07 explains where that boundary falls, because on this product it matters more than usual.

03. Our two roles

Personifex is a workspace tool, so we sit on both sides of the controller/processor line depending on which data you mean.

We are the controller for data about you as a customer: account and identity details, consent records, billing identifiers, security and audit logs, and operational telemetry. We decide why and how that is processed.

We are a processor for the content inside a workspace: prompts, generated and uploaded images and video, personas and reference images, captions, hashtags and the posting calendar. The organisation that owns the workspace is the controller for that content. We process it on their instructions to run the service, and for nothing else.

If you need a data processing agreement, email privacy@personifex.com and we will provide one. We will give notice before adding a new subprocessor to the list in section 10.

04. What we collect

Grouped by what it is, not by which database table it lands in.

  • Account and identity: email address, display name, organisation name, your role and permissions, your timezone, and a coarse last-active timestamp.
  • Consent records: when you accept the Terms and this policy we store the versions you accepted, the timestamp, your IP address and your browser user agent. That is the evidence that consent was given, so it is deliberately kept rather than discarded. Your confirmation that you are 18 or older is recorded in the same place as its own field, because it is a separate statement from accepting the Terms and we want to be able to produce it on its own.
  • Workspace content: the prompts you write, the images and video you generate or upload, persona details and reference images, captions, hashtags, ratings and the posting calendar.
  • Generation records for each run: the model used, the settings, the estimated cost, timings, the outcome and any error message. This is how billing estimates, capacity limits and your dashboard statistics are calculated. If you connect a WaveSpeed key, this also covers what we read back from your WaveSpeed account with it: the credit balance, and the amount and number of requests it billed per day and per model. See section 07.
  • Billing identifiers: your Stripe customer and subscription identifiers, plan, status and billing period. Card numbers go directly to Stripe. We never see or store your card details. The billing page shows the workspace owner your invoices and next charge, read from Stripe when it opens. If the owner adds invoice details, the name, billing address and VAT ID pass through our server to Stripe, which prints them on invoices. We keep no copy of either.
  • Security and operational records: an audit log of significant actions in your workspace, background job records, and ordinary server logs.
  • API keys you supply: the generation and AI provider keys you enter in Settings. See section 14 for how these are stored.
  • Browser extension captures, if you install Personifex Capture: the image you choose to capture, which is uploaded to the same storage as the rest of your workspace media, and a coarse label for where it came from. That label is one of six fixed values, such as extension:instagram, and anything else collapses to extension. We do not store the address of the page, its text, its captions, or anything you did not capture. The extension reads a page only to find the image you point it at, it never sees your browsing history, and it signs in with a token rather than your session cookie.
  • Anything you send us: support emails and their contents.
  • How you use the app: which pages and features you open and where you get stuck, tied to a per-device identifier. Only if you agree; see section 08.
  • Account milestones: three events our servers record, when you create an account, when you finish onboarding and when a subscription starts. They carry your account and workspace identifiers, your plan and billing interval, and for sign-up the campaign, referral code or referring website that brought you, if we have one. They reach our analytics provider whether or not you agree to analytics, because they store and read nothing on your device; section 05 gives the basis and how to object.

We do not buy personal data, we do not run third-party tracking pixels, and there are no advertising networks embedded in this product. We do use one analytics provider, named in section 10, and only with your agreement.

06. Reference images, personas and likeness

Personifex generates images from reference photographs you provide. That makes reference images the most sensitive thing in the product, so they get their own section.

  • You warrant that you have the rights. If a reference image shows a real, identifiable person, you must have that person’s informed consent to use their likeness this way, and the right to grant it. This is also a condition of the Acceptable Use Policy.
  • We are a processor for them. We store reference images and persona details to run generation on your instruction. We do not use them for any purpose of our own.
  • We do not train on them. No model of ours is trained, fine-tuned or improved using your reference images, personas or generated output.
  • We do not run facial recognition. We do not extract, compare or store facial templates or other biometric identifiers, and we do not knowingly process special category data under Art. 9. A photograph on its own is not a biometric identifier; deriving one from it would be, and we do not.
  • They go where generation goes. Running a generation sends the reference image to the generation provider in section 10. That is the entire point of the request, but it is a disclosure and you should know it happens.
  • Removal. Delete a persona or reference image in Settings and the file is removed from storage. If you believe a persona depicts someone without their consent, email privacy@personifex.com and we will remove it.

07. AI providers and your API keys

Personifex is bring-your-own-key. Generation and the optional AI writing features run on your account with the provider, using a key you supply. This has a consequence worth being blunt about.

We never train models on your data. But when your content reaches a third-party provider, that provider’s terms govern what happens next, under the account whose key was used, and we do not set a no-training flag on your behalf. If your provider offers data controls, zero-retention or training opt-outs, configure them in your provider account. We cannot do it for you and we will not claim otherwise.

What actually leaves our servers when you use those features: the prompt text; the persona details the feature writes from (voice, age, bio, interests, personality traits and niche); for prompt writing, the master prompt your workspace keeps for that persona, product or no-reference queue; and, for captions, hashtags and reverse-prompting, the image itself, sent as inline data rather than as a link, so we are not handing out signed URLs to your storage. For the optional dashboard insight widgets we send aggregate counts only, never your images. The AI provider features are entirely optional: if you configure no key, no AI provider ever receives anything.

Information also comes back the other way. With the WaveSpeed key you supply we read two things from your WaveSpeed account: its credit balance, and the amount and number of requests it says were billed, per day and per model. Those requests carry the key and nothing else, no prompt and no image. We store the figures so your dashboard can show what you were actually billed beside our own estimate, and so we can warn you before your credit runs out. They cover that whole WaveSpeed account, including anything else you use it for, and they are shown only to the workspace owner.

We do not carry out automated decision-making that produces legal or similarly significant effects about you.

08. Cookies and local storage

Nothing optional is set until you say so. The cookies in the first group below are required to run the service and are set without asking, including the one that records your cookie choice, and our CDN’s bot-filtering cookie, which is the only one that can be set before you sign in. The second group is analytics, and nothing in it exists until you agree. There are no advertising cookies anywhere in this product, and nothing here follows you to another site.

Strictly necessary: set without asking

  • Bot and abuse filtering, set by Cloudflare
    Names
    __cf_bm, cf_clearance
    Purpose
    Distinguishes real visitors from automated traffic. This is the one cookie that can be set before you sign in, and it is set on every site behind this CDN.
    Lifetime
    Around 30 minutes for __cf_bm. cf_clearance is set only if you are shown a challenge.
    Script access
    None. It is HTTP-only.
  • Authentication
    Names
    sb-…-auth-token (may be split across numbered parts)
    Purpose
    Keeps you signed in and refreshes your session. Without it the app cannot work at all.
    Lifetime
    Session, refreshed as you use the app. Cleared on sign-out.
    Script access
    None. It is HTTP-only.
  • Subscription status cache
    Names
    subok_…
    Purpose
    Remembers that your subscription check passed so we do not query the database on every page load.
    Lifetime
    5 minutes, kept short so a change in status takes effect within minutes.
    Script access
    None. It is HTTP-only.
  • Consent record cache
    Names
    cok_…
    Purpose
    Remembers which versions of these documents you have accepted, so we do not query the database on every page load. Its value is the version pair itself, which means that when we publish a new version every copy of this cookie stops matching at once and you are asked again.
    Lifetime
    30 days, or until we publish a new version of the Terms or this policy.
    Script access
    None. It is HTTP-only.
  • Onboarding status cache
    Names
    ob_…
    Purpose
    Remembers that you finished onboarding, so you are not asked again.
    Lifetime
    30 days.
    Script access
    None. It is HTTP-only.
  • Persona selection
    Names
    generate_persona_id, active_persona_id, generate_persona_lanes, browse_persona_filters
    Purpose
    Remembers which persona you were working on, so the correct workspace renders on first paint instead of flashing the wrong one.
    Lifetime
    1 year.
    Script access
    None. It is HTTP-only.
  • Interface state
    Names
    activeTab, generateMode, videoSubMode, defaultTab, defaultGenerateMode, tabLayout
    Purpose
    Remembers your last tab, your preferred starting tab, and your tab order, so the server renders the right screen immediately.
    Lifetime
    1 year.
    Script access
    Readable by scripts on this site. They hold interface preferences only, no identifiers.
  • Payment fraud prevention, set by Stripe
    Names
    __stripe_mid, __stripe_sid
    Purpose
    Set by Stripe when the billing page loads their payment form, to detect card fraud. We do not read them. They are only ever set on the billing page; no other page loads Stripe.
    Lifetime
    Around 1 year for __stripe_mid; around 30 minutes for __stripe_sid.
    Script access
    Readable by scripts on this site; Stripe reads them itself.

Analytics: set only if you agree

  • Product analytics, set by PostHog
    Names
    ph_… (the name includes our project identifier)
    Purpose
    Gives you a consistent identifier across visits so we can see which features are used and where people get stuck. It does not follow you to any other site, and we do not use it for advertising.
    Lifetime
    Up to 1 year, or until you withdraw, whichever is first.
    Script access
    Readable by scripts on this site.
    If you say no
    Nothing is set and the analytics code is never even downloaded. The app works exactly the same.

We also use your browser’s local storage for roughly thirty appearance and interface preferences: theme, accent colour, density, text size, font, animation, pointer style, sound, notification position, tile size, calendar week start, time format and similar. These never leave your device, are not sent to our servers, and are not used to identify you. Clearing site data resets them to defaults.

A few other things live there and are not preferences, so we list them separately. If you arrive on a link carrying a discount code, we hold that code in local storage so it survives the trip through sign-up: it is sent to our payment processor when you subscribe, and cleared once applied. And when we schedule a change to these documents, we record that you dismissed the notice, so it does not reappear on every page. Your cookie choice itself is kept there too, including a refusal, which is the only way we can avoid asking you again. Storing that one is not something we can ask permission for, since it is the permission.

Your cookie choice. The first time you visit we ask once, and we ask plainly: accept the optional analytics, or refuse. Refusing is a single click in the same place, at the same size, as accepting, and it costs you nothing, because every feature works identically either way. We do not treat closing the banner as agreement, nothing optional is ticked for you in advance, and until you answer, the analytics code is not downloaded at all.

We remember your answer for a year so we are not asking on every visit; a refusal is remembered exactly as long as an acceptance. You can change it whenever you like from the Cookies link in the footer of any page, and withdrawing does not just stop the collection: we delete the cookie and the stored data from your browser on the spot. If we ever add a new purpose, or a new company that receives this data, that record stops counting and we ask you again rather than assuming the old answer covers it.

The persona and interface cookies are the ones worth being explicit about, because “strictly necessary” is a narrow test and we are claiming it. They hold no identifier, are set only after you sign in, and exist so that the server can render the workspace you actually left instead of a default one you would have to correct on every single visit. We treat that as necessary to deliver the service in the form you asked for it. If you disagree, clearing site data removes them and the app still works.

09. Performance measurement

We measure page performance ourselves rather than through an analytics vendor. Pages report standard web-performance metrics: how quickly the page became visible and responsive, and the path it happened on.

This carries no cookie and no persistent identifier. The measurement id is generated fresh in the page and is gone when you navigate away. The readings go to our own server logs, not to a third party and not into our database. This runs on public pages too, so it applies to visitors who have never signed in.

10. Subprocessors

These providers process personal data on our behalf so that the service can run. Each operates under its own privacy terms, and we will give notice before adding to this list.

  • Supabase
    Role
    Database, authentication, file storage, and generating the account emails that Resend then delivers.
    Data
    Effectively everything in section 04.
    Location
    United States (Virginia).
  • Cloudflare
    Role
    Media storage (R2), content delivery, DNS, and routing for our contact addresses.
    Data
    Your images, video, reference images and thumbnails; all traffic to the site transits their network.
    Location
    Cloudflare guarantees that media is stored and processed in the United States (its US jurisdiction). The delivery network is global by design.
  • Railway
    Role
    Hosting for the application and the background workers.
    Data
    Anything processed in a request or a job, plus server logs.
    Location
    United States (Virginia).
  • Stripe
    Role
    Subscription billing and payment processing.
    Data
    Your email and name, payment details you enter directly with them, the invoice name, billing address and VAT ID the owner adds, and your subscription record. We never receive your card number.
    Location
    United States, with global processing.
  • Resend
    Role
    Delivery of account emails: sign-in codes and links, email-change confirmations, and invitations.
    Data
    Your email address and the contents of those messages.
    Location
    United States.
  • PostHog
    Role
    Product analytics: which pages and features are used, only if you agree (section 08). Also three account milestones recorded by our servers, whatever you choose (section 04).
    Data
    A per-device identifier, the pages you open inside the app, event names, coarse device and browser information, and your IP address. The identifier of the browser you signed up in is linked to your account, so we can tell a returning user from a new one; other browsers and devices are not linked. The account milestones carry your account and workspace identifiers, your plan and billing interval, and how you found us.
    Location
    United States. PostHog Inc. is certified under the EU-US Data Privacy Framework.
  • WaveSpeed
    Role
    Image and video generation, called with the API key you supply.
    Data
    Your prompts, your reference images, and source video for the video features.
    Location
    Outside the EEA. Governed by your account with them; see section 07.
  • OpenRouter, and the model vendor you choose there
    Role
    Optional writing features: captions, hashtags, reverse-prompting, prompt assistance.
    Data
    Prompt text, the persona details and master prompt the feature writes from, and the relevant image for image-based features.
    Location
    Outside the EEA. OpenRouter receives the request and routes it on to the model vendor you select, which can be anywhere that vendor operates. Configure no key and neither receives anything.

11. International transfers

The core of the service runs in the United States. Our database and our servers are hosted in Virginia, and Cloudflare guarantees that our media storage stays in the United States, so your account data, your images and your video are stored there. If you are in the EEA or the United Kingdom, that is a transfer of your personal data outside the EEA, and it happens for every account, not only when a feature is used.

The rest of the processing is in the United States or elsewhere too. Stripe processes payments and invoice details in the United States. Our email delivery provider is in the United States. Generation requests go to a provider outside the EEA. Where we are the exporter, every one of these transfers rests on the European Commission’s Standard Contractual Clauses or on an adequacy decision, as applicable.

Analytics adds a transfer. PostHog, which measures how the app is used, processes that data in the United States. PostHog Inc. is certified under the EU-US Data Privacy Framework. Refusing analytics stops the measurement in your browser, but the three account milestones in section 04 still reach PostHog, because our servers record them.

The AI writing features are different, and you should read this before enabling them. You supply the OpenRouter key and you pick the model, so you determine where that content goes. OpenRouter is a router: it receives your prompt and passes it to the vendor behind the model you chose. Its catalogue spans the United States, Europe and China, so selecting a China-hosted model sends your prompts and images there under that vendor’s terms. The model is yours to set, in Settings or in your OpenRouter account, and changing it changes the destination. Choose deliberately.

12. How long we keep things

The windows below are how quickly deletion happens, not guarantees of the exact minute: the jobs that enforce them run on a schedule, so removal can lag by a few hours.

  • Images and video you delete: held in trash so you can restore them, then purged. The window depends on your plan: 7 days on Solo, 14 on Creator, 30 on Agency. Workspaces without an active plan fall back to 7 days.
  • Prompts you delete: erased outright at the end of the same window.
  • Audit log: deleted daily once entries pass 7 days old.
  • Unreferenced files in storage: swept automatically after a grace period of at least 24 hours.
  • Error text from the generation pipeline: the message the AI provider returned is cleared after 90 days. The record that an attempt failed, and our own short classification of why, is kept. See the paragraph below on why those records outlive the images.
  • Cached output from the AI dashboard widgets: deleted after 30 days. The widgets already treat anything older than a day as stale, so this only clears text nothing will read again.
  • Invitations you have sent: deleted 90 days after they are accepted. An invitation that has not been accepted is kept, because deleting it would quietly stop that person joining your workspace.
  • Storage usage statistics: daily per-workspace totals, deleted after 400 days.
  • The IP address and user agent recorded with your consent: cleared after 12 months. What you accepted, which version, when, and your confirmation that you are 18 or older are kept: that is the evidence we are obliged to be able to produce. Those two fields are corroborating detail, and keeping them forever is much harder to justify than keeping them for a year.
  • The balance and billed totals read from your WaveSpeed account: refreshed while your key is connected, and kept for the life of the workspace. They are deleted with it. There is no separate expiry, because the current figures are the point of holding them at all.
  • Account and identity data: for the life of the account.
  • Enforcement records: kept indefinitely, and deliberately. If we restrict, remove content from, or terminate a workspace under the Acceptable Use Policy, we keep a record of the decision: what we did, when, and why. We need it to answer an appeal, to show a regulator we handled a report properly, and to defend a legal claim. It holds no image, no prompt, no email address and no IP address, only a workspace identifier, a timestamp and our reasons.

Be aware that deleting media is not a full erasure. When the trash window expires we remove the file from storage, but we keep a minimal record of the generation (the timestamp, the model, the settings and your rating) so that historical statistics stay accurate and are not silently rewritten by deletions. That record contains no image and no prompt text.

Two things above have no fixed limit, and both are deliberate rather than an oversight: the generation records described in the paragraph above, and enforcement records. Everything else on this page has a window. If you want any of it removed sooner, you can ask under section 15.

13. Deleting your account

Account deletion is in Settings, under Your data, and at /app/account, which stays reachable even when a lapsed subscription, unfinished onboarding or unaccepted terms lock the rest of the app. It is immediate and irreversible. What it does depends on whether you own the workspace, so here is the honest version of both.

If you own the workspace, deletion removes the workspace and everything in it: every image, video and reference image in storage, all prompts, personas, calendar entries, achievements, audit entries and members’ memberships. Your subscription is cancelled and your customer record at Stripe is deleted, though Stripe retains its own transaction records for as long as its legal obligations require. A minimal payment-event log survives on our side; it contains no name, email or workspace reference.

One thing deliberately survives even an owner’s deletion: an enforcement record, if we ever restricted, removed content from, or terminated the workspace under the Acceptable Use Policy. It is kept so that an appeal can still be answered and so that we can show a regulator how a report was handled: the same reasons set out in section 12. Once the workspace is gone the record identifies nobody: it holds a workspace identifier that no longer refers to anything, a timestamp, and our reasons. No name, email, IP address, image or prompt.

If you are a member of someone else’s workspace, deletion removes your sign-in, your profile (display name, timezone, and the IP address and user agent from your consent record), your interface layout, your saved drafts and settings, and your achievement counters and badges. The workspace itself belongs to its owner and survives. So does the content you created in it, because it is the owner’s data, not yours to remove unilaterally. Specifically, these persist after you delete your account:

  • Images and video you generated or uploaded, including the underlying files; your authorship link is cleared, but the content stays in the workspace.
  • Generation and error records, which are not linked to individual users at all.
  • Audit entries you caused. Your user reference is cleared, though entry details may still name an email address where the action itself concerned one, for example an invitation you sent. These are deleted within 7 days by the ordinary audit retention.
  • Invitations you sent, and cached output from the AI dashboard widgets, each until the window in section 12 expires.

If you want any of that removed as well, email privacy@personifex.com and we will action it manually. You have that right and we will not make you argue for it.

14. Security

Traffic between you and Personifex is encrypted with TLS. Our database provider and our media storage provider encrypt data at rest on their platforms.

Row-level security is enabled on every table in our database, and access from a browser is scoped to your organisation and enforced by the database itself rather than by application code alone. Our own servers connect with a privileged account, as they must to do their job, and apply the same scoping in application code: every action resolves your membership and permissions before it touches anything.

The API keys you supply for generation and for your AI provider are held in an encrypted secrets vault, separate from the tables that hold your account data: those tables store only a reference, never the key. They are also never returned to your browser once saved, not even to you: the interface can tell you a key is set, but it cannot show it back. If you lose one, replace it.

There are no passwords. Signing in means asking for a one-time code, which we email to the address on your account. So there is no password of yours for us to store, and none to be exposed if we were ever breached. Deleting your account requires a fresh code sent to that same address, and changing your email requires confirming it from both the old address and the new one.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the competent supervisory authority within 72 hours where required, and notify you directly where the risk to you is high. If you believe you have found a vulnerability, email privacy@personifex.com. We will not pursue anyone who reports one in good faith and gives us a reasonable chance to fix it.

15. Your rights

If you are in the EEA or the UK, you have the following rights. We extend them to everyone, because operating two standards of care is worse than operating one.

  • Access: get a copy of the personal data we hold about you.
  • Rectification: correct anything inaccurate.
  • Erasure: have your data deleted.
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction: have us pause processing while a dispute is resolved.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where processing rests on consent, withdraw it at any time. This does not undo processing already carried out.

Self-service. Settings has a data export and account deletion under Your data, and both are also at /app/account. The export is a structured JSON file. It does not bundle your image and video files, which can run to gigabytes: download those from the Gallery, or ask us and we will arrange it.

That page stays reachable when the rest of the app does not. A lapsed subscription, unfinished onboarding, or a change to these documents that you have not yet accepted will each stop you entering the app; none of them stops you reaching /app/account, exporting, or deleting your account. We will never require a payment to honour a data right, and we will never require you to accept a new version of our terms in order to leave. If the page will not load for any reason, email us and we will do it for you.

How to exercise any of these. Email privacy@personifex.com. We respond within 30 days, and will tell you if a request is genuinely complex enough to need longer. We do not charge for this. We may ask you to confirm your identity, but only where we genuinely cannot otherwise tell that the request is yours.

If the data concerns a workspace you are a member of rather than one you own, we may need to route part of your request through the workspace owner, who is the controller for that content. We will tell you if that happens.

Complaints. If you think we have got this wrong, tell us first; we would rather fix it. You also have the right to complain to your local data protection authority. Ours is [SUPERVISORY AUTHORITY], and you may complain to the authority in your own country of residence or workplace instead.

16. California residents

Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information we have collected, request deletion or correction, and you may not be discriminated against for exercising any of it. Use the same address: privacy@personifex.com.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months or at any point. We run no advertising and no financial incentive programmes. The categories we collect, our purposes, and the parties we disclose to are set out in sections 04, 05 and 10; those apply to you as written.

17. Children

Personifex is not for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, email privacy@personifex.com and we will delete it. Everyone is asked to confirm that they are 18 or older when they create an account, in a checkbox separate from accepting the Terms, and we record when they confirmed it (section 04).

18. Changes to this policy

When this policy changes we update the date at the top and the version identifier below. Minor clarifications take effect on publication. For a material change, meaning a new purpose, a new category of data, or a new class of recipient, we will give notice by email or in the app at least 14 days before it takes effect, so that you can object or leave.

We keep the version you accepted on your account record, so it is always answerable what you actually agreed to.

Version 2026-10-03