Privacy Policy

Last Updated: October 26, 2025

At Forevi AI, your privacy and the protection of your data are top priorities. This Privacy Policy explains what information we collect, how we use it, the choices you have, and the rights available to you under applicable laws. Forevi AI operates from Poland as a sole proprietorship or company and provides services primarily to users in the United States and internationally.

By using our website, mobile apps (including iOS), and related services (collectively, the "Service"), you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Who we are and how to contact us

Forevi AI is the data controller for personal data processed in connection with the Service. If you have questions, requests, or complaints regarding this Privacy Policy or our practices, please contact us via the contact options provided on our website.

2. Scope of this policy

This Privacy Policy applies to www.foreviai.com and any related apps or services that link to it. It covers personal data we collect from or about you when you visit our Service, create an account, purchase or use our products, or otherwise interact with us.

3. No tracking and minimal cookies

We do not use third-party advertising trackers or behavioral profiling cookies. We use only strictly necessary cookies (for things like session management, security, fraud prevention, and basic site functionality) and, if applicable, limited preference cookies that you explicitly enable. You can manage preferences in your browser or device settings. Disabling strictly necessary cookies may prevent the Service from functioning.

4. The data we collect

4.1 Information you provide directly

  • Account data: name or display name, email, password or sign-in token (including third-party sign-in identifiers), and optional profile details.
  • Payment data: handled by Stripe. We receive limited payment metadata (e.g., transaction ID, last four digits, card brand, status) but do not store full card numbers.
  • User Content: images, photos, videos, prompts, and related metadata you upload to use our AI features.
  • Communications: messages you send us (support requests, feedback), and your communication preferences.

4.2 Information we collect automatically

  • Device and usage data: basic logs (e.g., IP address, timestamp, user agent, operating system, app version, language, referrer) to operate, secure, and improve the Service. We do not run third-party analytics that track you across sites.
  • Diagnostics and telemetry: de-identified, aggregate operational metrics (e.g., feature performance, error rates, rendering time). These metrics do not include your images or video content.

4.3 Information from third parties

  • Authentication providers (e.g., Apple, Google) when you choose to sign in with them, in accordance with their terms and your settings.
  • Payment processor (Stripe) in connection with payments, refunds, or disputes.

5. How we use your data

We process personal data for the following purposes and under the legal bases noted (GDPR):

  • Provide and operate the Service (contract): create/maintain accounts, fulfill orders, render AI features, deliver Outputs, provide storage per your tier, and handle customer support.
  • Security and integrity (legitimate interests/legal obligation): protect accounts, detect/prevent abuse and fraud, secure systems, and comply with laws.
  • Payments and billing (contract/legal obligation): process payments via Stripe, manage subscriptions/credits, prevent fraud, and meet tax and accounting obligations.
  • Service improvement (legitimate interests): analyze de-identified, aggregate telemetry to maintain and improve reliability, performance, and usability.
  • Communications (consent/legitimate interests): send essential transactional notices (account, billing, policy changes). We may send optional product updates where permitted; you can opt out at any time.

6. Special notes about AI processing

  • User Content you upload (input photos, videos, prompts) is used only to generate requested Outputs and to provide, operate, protect, and support the Service.
  • We do not use your User Content or Outputs to train or retrain our machine-learning models or third-party models.
  • We may use de-identified, aggregate telemetry (e.g., runtime, error codes) to improve infrastructure. This telemetry does not include your images or videos.

7. Deletion and retention

  • Input files: input photos and other uploaded source media are automatically deleted 1 hour after upload, unless required to complete an in-progress job. You may also delete them sooner from your account if available.
  • Outputs: generated Outputs (e.g., restored/colorized images, upscaled 4K files, animated/talking portraits) may be stored in your gallery based on your paid tier's storage limits. If you exceed your tier's storage or your subscription lapses, we may remove older Outputs after reasonable notice. You can delete Outputs at any time.
  • Account data: we retain account and billing records as long as you maintain an account and for a reasonable period afterward for legal, tax, fraud prevention, and backup purposes.
  • Backups and logs: limited data may persist in encrypted backups and system logs for a defined retention window and will be purged on a rolling basis.
  • Legal holds: we may retain data longer where required by law, regulation, or to establish, exercise, or defend legal claims.

8. Storage and international transfers

We may process data in the EU/EEA, the United States, and other jurisdictions. When transferring personal data internationally, we use lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses, as applicable. We implement appropriate safeguards designed to protect your data consistent with this Privacy Policy.

9. Our service providers (processors)

We use carefully selected third parties to help us operate the Service, for example:

  • Cloud hosting and content delivery;
  • Payment processing (Stripe);
  • Email and support tooling;
  • Image/video processing infrastructure.

These providers act under contracts that require appropriate technical and organizational measures, confidentiality, and processing only on our documented instructions. We remain responsible for their performance as processors where required by law.

10. Stripe payments

All payments are processed by Stripe. Stripe acts as an independent controller for certain payment-related data and as our processor for others. Please review Stripe's own privacy notices for details about their processing and your choices. We do not store complete card numbers on our systems.

11. Legal bases and your choices

11.1 Consent

Where we rely on consent (for example, certain preference communications), you may withdraw it at any time through your account settings or by contacting us.

11.2 Legitimate interests

Where we rely on legitimate interests (e.g., service security, minimal telemetry), we have balanced those interests against your rights and expectations and implemented safeguards.

11.3 Contract and legal obligations

We process data as necessary to perform our contract with you and to comply with applicable legal obligations (e.g., tax and accounting).

12. Your rights

Your rights depend on where you live. Subject to legal limits, you may have the right to:

  • Access: obtain confirmation and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your personal data.
  • Restriction: ask us to limit processing in certain circumstances.
  • Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Objection: object to processing based on legitimate interests, and object to direct marketing at any time.
  • Consent withdrawal: withdraw consent where processing is based on consent.
  • Automated decisions: request information about automated decision-making that has legal or similar significant effects (Forevi AI does not make such decisions about you personally; our AI transforms content you request).

To exercise your rights, please contact us via the contact options on our website. We will verify your request and respond within the time required by law. You may also lodge a complaint with your supervisory authority (for EU/EEA residents) or with your local regulator.

13. U.S. state privacy disclosures (including California)

We address applicable U.S. privacy laws, including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and similar laws in other states.

  • Categories collected: identifiers (e.g., email), account credentials, limited payment metadata, internet activity logs (basic server logs), and User Content you upload.
  • Sources: you, your devices, and our service providers.
  • Purposes: as described in Sections 5–7 (provide Service, payments, security, support, improvement).
  • Disclosures to third parties: we share data with processors (service providers) under contract; we may disclose as required by law or in connection with a business transfer.
  • No sale or sharing: we do not "sell" or "share" personal information as defined by the CCPA/CPRA (no cross-context behavioral advertising).
  • Retention: as outlined in Section 7.

California and certain other U.S. residents may have rights to access, delete, correct, and obtain information about processing. To exercise rights, use the contact options on our website. We will not discriminate against you for exercising your rights.

14. Children's privacy

The Service is intended for individuals 18 years and older. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will take appropriate steps to delete such information.

15. Security

We use technical and organizational measures designed to protect your data, including encryption in transit and at rest where appropriate, access controls, network segmentation, key management, monitoring, and vulnerability management. No system is completely secure; you are responsible for safeguarding your account credentials and promptly notifying us of any suspected compromise.

16. Communications preferences

We may send you essential transactional or service communications (e.g., account notices, billing, material policy changes). You may opt out of non-essential communications (e.g., product updates) at any time through the unsubscribe link or your account settings. Because we do not run third-party advertising trackers, you will not receive behaviorally targeted ads from us based on tracking cookies.

17. Third-party links and integrations

Our Service may include links to third-party sites or integrations you choose to use (e.g., sign-in with Apple or Google). Your use of those services is subject to the third party's terms and privacy notices. We are not responsible for third-party practices.

18. Business transfers

If we undergo a merger, acquisition, reorganization, or asset sale, personal data may be transferred as part of that transaction, subject to this Privacy Policy and applicable laws. We will provide appropriate notice if your personal data becomes subject to a materially different policy.

19. Do Not Track and Global Privacy Control

Your browser may offer Do Not Track (DNT) or Global Privacy Control (GPC) signals. While there is no industry consensus on DNT, we do not engage in cross-site behavioral tracking. Where GPC is recognized under applicable law, we will treat it as a request to opt out of any "sale" or "sharing" of personal information (which we do not perform).

20. Changes to this Privacy Policy

We may revise this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by posting an updated policy on the website or within the app). The updated Privacy Policy will be effective when posted unless otherwise stated. Your continued use of the Service after the effective date constitutes acceptance.

21. How to contact us

For privacy questions, rights requests, or complaints, please contact us using the contact options available on our website. We will respond within the timelines required by applicable law.

Appendix: Summary of key retention points

  • Input photos and other source media: automatically deleted 1 hour after upload unless needed to complete processing, and deletable by you sooner where available.
  • Outputs: stored subject to your tier's storage limits; deletable by you; may be removed if limits are exceeded or subscription lapses after reasonable notice.
  • Account and billing records: retained as required by law and for fraud prevention and security, then deleted or anonymized.
  • Backups/logs: retained for a limited, rolling window and then purged.