Last updated · October 3, 2026
Personifex is operated by [LEGAL ENTITY], [REGISTERED ADDRESS], [COUNTRY] (company number [COMPANY NUMBER]). We are the data controller for the personal data described in this policy, except where section 03 says we act as a processor instead.
For any privacy question, request or complaint, email privacy@personifex.com. A person reads that address; it is not a ticket queue that goes nowhere.
This policy covers the Personifex website, the application at /app, the optional Personifex Capture browser extension, and the account emails we send you. It explains what we collect, why we are allowed to, who else touches it, how long it survives, and what you can make us do about it.
It does not cover third-party sites you reach from our links, the social platforms you publish your content to, or the AI providers you connect with your own API key: each of those is governed by its own terms. Section 07 explains where that boundary falls, because on this product it matters more than usual.
Personifex is a workspace tool, so we sit on both sides of the controller/processor line depending on which data you mean.
We are the controller for data about you as a customer: account and identity details, consent records, billing identifiers, security and audit logs, and operational telemetry. We decide why and how that is processed.
We are a processor for the content inside a workspace: prompts, generated and uploaded images and video, personas and reference images, captions, hashtags and the posting calendar. The organisation that owns the workspace is the controller for that content. We process it on their instructions to run the service, and for nothing else.
If you need a data processing agreement, email privacy@personifex.com and we will provide one. We will give notice before adding a new subprocessor to the list in section 10.
Grouped by what it is, not by which database table it lands in.
We do not buy personal data, we do not run third-party tracking pixels, and there are no advertising networks embedded in this product. We do use one analytics provider, named in section 10, and only with your agreement.
Under the GDPR every purpose needs a lawful basis. Ours, category by category, with the retention that applies to each.
Where we rely on legitimate interests, we have weighed that interest against your rights and you can object at any time; see section 15.
Personifex generates images from reference photographs you provide. That makes reference images the most sensitive thing in the product, so they get their own section.
Personifex is bring-your-own-key. Generation and the optional AI writing features run on your account with the provider, using a key you supply. This has a consequence worth being blunt about.
We never train models on your data. But when your content reaches a third-party provider, that provider’s terms govern what happens next, under the account whose key was used, and we do not set a no-training flag on your behalf. If your provider offers data controls, zero-retention or training opt-outs, configure them in your provider account. We cannot do it for you and we will not claim otherwise.
What actually leaves our servers when you use those features: the prompt text; the persona details the feature writes from (voice, age, bio, interests, personality traits and niche); for prompt writing, the master prompt your workspace keeps for that persona, product or no-reference queue; and, for captions, hashtags and reverse-prompting, the image itself, sent as inline data rather than as a link, so we are not handing out signed URLs to your storage. For the optional dashboard insight widgets we send aggregate counts only, never your images. The AI provider features are entirely optional: if you configure no key, no AI provider ever receives anything.
Information also comes back the other way. With the WaveSpeed key you supply we read two things from your WaveSpeed account: its credit balance, and the amount and number of requests it says were billed, per day and per model. Those requests carry the key and nothing else, no prompt and no image. We store the figures so your dashboard can show what you were actually billed beside our own estimate, and so we can warn you before your credit runs out. They cover that whole WaveSpeed account, including anything else you use it for, and they are shown only to the workspace owner.
We do not carry out automated decision-making that produces legal or similarly significant effects about you.
We measure page performance ourselves rather than through an analytics vendor. Pages report standard web-performance metrics: how quickly the page became visible and responsive, and the path it happened on.
This carries no cookie and no persistent identifier. The measurement id is generated fresh in the page and is gone when you navigate away. The readings go to our own server logs, not to a third party and not into our database. This runs on public pages too, so it applies to visitors who have never signed in.
These providers process personal data on our behalf so that the service can run. Each operates under its own privacy terms, and we will give notice before adding to this list.
The core of the service runs in the United States. Our database and our servers are hosted in Virginia, and Cloudflare guarantees that our media storage stays in the United States, so your account data, your images and your video are stored there. If you are in the EEA or the United Kingdom, that is a transfer of your personal data outside the EEA, and it happens for every account, not only when a feature is used.
The rest of the processing is in the United States or elsewhere too. Stripe processes payments and invoice details in the United States. Our email delivery provider is in the United States. Generation requests go to a provider outside the EEA. Where we are the exporter, every one of these transfers rests on the European Commission’s Standard Contractual Clauses or on an adequacy decision, as applicable.
Analytics adds a transfer. PostHog, which measures how the app is used, processes that data in the United States. PostHog Inc. is certified under the EU-US Data Privacy Framework. Refusing analytics stops the measurement in your browser, but the three account milestones in section 04 still reach PostHog, because our servers record them.
The AI writing features are different, and you should read this before enabling them. You supply the OpenRouter key and you pick the model, so you determine where that content goes. OpenRouter is a router: it receives your prompt and passes it to the vendor behind the model you chose. Its catalogue spans the United States, Europe and China, so selecting a China-hosted model sends your prompts and images there under that vendor’s terms. The model is yours to set, in Settings or in your OpenRouter account, and changing it changes the destination. Choose deliberately.
The windows below are how quickly deletion happens, not guarantees of the exact minute: the jobs that enforce them run on a schedule, so removal can lag by a few hours.
Be aware that deleting media is not a full erasure. When the trash window expires we remove the file from storage, but we keep a minimal record of the generation (the timestamp, the model, the settings and your rating) so that historical statistics stay accurate and are not silently rewritten by deletions. That record contains no image and no prompt text.
Two things above have no fixed limit, and both are deliberate rather than an oversight: the generation records described in the paragraph above, and enforcement records. Everything else on this page has a window. If you want any of it removed sooner, you can ask under section 15.
Account deletion is in Settings, under Your data, and at /app/account, which stays reachable even when a lapsed subscription, unfinished onboarding or unaccepted terms lock the rest of the app. It is immediate and irreversible. What it does depends on whether you own the workspace, so here is the honest version of both.
If you own the workspace, deletion removes the workspace and everything in it: every image, video and reference image in storage, all prompts, personas, calendar entries, achievements, audit entries and members’ memberships. Your subscription is cancelled and your customer record at Stripe is deleted, though Stripe retains its own transaction records for as long as its legal obligations require. A minimal payment-event log survives on our side; it contains no name, email or workspace reference.
One thing deliberately survives even an owner’s deletion: an enforcement record, if we ever restricted, removed content from, or terminated the workspace under the Acceptable Use Policy. It is kept so that an appeal can still be answered and so that we can show a regulator how a report was handled: the same reasons set out in section 12. Once the workspace is gone the record identifies nobody: it holds a workspace identifier that no longer refers to anything, a timestamp, and our reasons. No name, email, IP address, image or prompt.
If you are a member of someone else’s workspace, deletion removes your sign-in, your profile (display name, timezone, and the IP address and user agent from your consent record), your interface layout, your saved drafts and settings, and your achievement counters and badges. The workspace itself belongs to its owner and survives. So does the content you created in it, because it is the owner’s data, not yours to remove unilaterally. Specifically, these persist after you delete your account:
If you want any of that removed as well, email privacy@personifex.com and we will action it manually. You have that right and we will not make you argue for it.
Traffic between you and Personifex is encrypted with TLS. Our database provider and our media storage provider encrypt data at rest on their platforms.
Row-level security is enabled on every table in our database, and access from a browser is scoped to your organisation and enforced by the database itself rather than by application code alone. Our own servers connect with a privileged account, as they must to do their job, and apply the same scoping in application code: every action resolves your membership and permissions before it touches anything.
The API keys you supply for generation and for your AI provider are held in an encrypted secrets vault, separate from the tables that hold your account data: those tables store only a reference, never the key. They are also never returned to your browser once saved, not even to you: the interface can tell you a key is set, but it cannot show it back. If you lose one, replace it.
There are no passwords. Signing in means asking for a one-time code, which we email to the address on your account. So there is no password of yours for us to store, and none to be exposed if we were ever breached. Deleting your account requires a fresh code sent to that same address, and changing your email requires confirming it from both the old address and the new one.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the competent supervisory authority within 72 hours where required, and notify you directly where the risk to you is high. If you believe you have found a vulnerability, email privacy@personifex.com. We will not pursue anyone who reports one in good faith and gives us a reasonable chance to fix it.
If you are in the EEA or the UK, you have the following rights. We extend them to everyone, because operating two standards of care is worse than operating one.
Self-service. Settings has a data export and account deletion under Your data, and both are also at /app/account. The export is a structured JSON file. It does not bundle your image and video files, which can run to gigabytes: download those from the Gallery, or ask us and we will arrange it.
That page stays reachable when the rest of the app does not. A lapsed subscription, unfinished onboarding, or a change to these documents that you have not yet accepted will each stop you entering the app; none of them stops you reaching /app/account, exporting, or deleting your account. We will never require a payment to honour a data right, and we will never require you to accept a new version of our terms in order to leave. If the page will not load for any reason, email us and we will do it for you.
How to exercise any of these. Email privacy@personifex.com. We respond within 30 days, and will tell you if a request is genuinely complex enough to need longer. We do not charge for this. We may ask you to confirm your identity, but only where we genuinely cannot otherwise tell that the request is yours.
If the data concerns a workspace you are a member of rather than one you own, we may need to route part of your request through the workspace owner, who is the controller for that content. We will tell you if that happens.
Complaints. If you think we have got this wrong, tell us first; we would rather fix it. You also have the right to complain to your local data protection authority. Ours is [SUPERVISORY AUTHORITY], and you may complain to the authority in your own country of residence or workplace instead.
Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information we have collected, request deletion or correction, and you may not be discriminated against for exercising any of it. Use the same address: privacy@personifex.com.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months or at any point. We run no advertising and no financial incentive programmes. The categories we collect, our purposes, and the parties we disclose to are set out in sections 04, 05 and 10; those apply to you as written.
Personifex is not for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, email privacy@personifex.com and we will delete it. Everyone is asked to confirm that they are 18 or older when they create an account, in a checkbox separate from accepting the Terms, and we record when they confirmed it (section 04).
When this policy changes we update the date at the top and the version identifier below. Minor clarifications take effect on publication. For a material change, meaning a new purpose, a new category of data, or a new class of recipient, we will give notice by email or in the app at least 14 days before it takes effect, so that you can object or leave.
We keep the version you accepted on your account record, so it is always answerable what you actually agreed to.
Version 2026-10-03