Privacy Policy
Last updated: 2026-07-28
This Privacy Policy explains how Content Engine Cloud (the “Service”) collects, uses, and shares your personal data. The Service is operated by Vatai-Gáspár Kata e.v., registered in Hungary at 4032 Debrecen, Károli Gáspár utca 298., tax number 59191063-1-29. Contact: info@theignitingstudio.com.
We follow the EU General Data Protection Regulation (GDPR) and the Hungarian Info Act (2011. évi CXII. törvény). You have the right to lodge a complaint with the Hungarian Data Protection Authority (NAIH) here.
What we collect
- Account data: email address (for sign-in via magic link), the timestamp when you agreed to Terms + Privacy Policy, your billing tier and Polar customer ID.
- Content you upload or paste: transcripts, source URLs, audio and video files, and reference thumbnail images used to teach the Service your visual style.
- Face photos that you optionally upload for AI thumbnail generation. Storing photos of identifiable people is a data-protection sensitive activity — see the dedicated section below.
- Generated outputs: the AI-generated captions, descriptions, and thumbnails the Service produces from your input.
- Usage data: generation counts, image counts, API cost incurred, and timestamps — used to enforce billing tier caps and diagnose failures.
- Server logs: HTTP request paths, error stack traces, and user IDs. Retained by our hosting provider for up to 30 days.
Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b)): account data, uploaded content, generated outputs, usage data — necessary to deliver the Service you subscribed to.
- Consent (GDPR Art. 6(1)(a)): face-photo storage for AI thumbnail generation. You can revoke this at any time by removing the photo in Settings.
- Legitimate interest (GDPR Art. 6(1)(f)): server logs, security monitoring, aggregated usage statistics to improve the Service.
Face photos and biometric-adjacent data
The Service optionally accepts a photo of your face (and, in the multi-video calendar, a second “guest” photo) to include in AI-generated YouTube thumbnails. We store these photos in a private storage bucket scoped to your account. They are:
- Not used to identify you or anyone else.
- Not used to train any AI model. When you generate a thumbnail we send the photo to Google (via fal.ai’s nano-banana-pro endpoint) which processes it to produce the output and does not use it for training under fal.ai’s terms.
- Deleted whenever you remove them in Settings.
- Deleted, along with all other data, when you close your account.
When you upload a guest photo (the “Person 2” slot), you confirm that either the photo is of yourself or you have permission from the person shown to use their likeness for AI-generated content. You are responsible for obtaining that permission.
Sub-processors
We use the following third-party services to run the Service. Each acts as a data processor under our instructions. See the Sub-processors page for the current full list, jurisdictions, and links to their privacy policies.
- Supabase (Ireland, US) — authentication, database, file storage
- Vercel (US) — application hosting + compute
- Anthropic (US) — Claude LLM for text generation and voice fingerprinting
- OpenAI (US) — GPT-4o vision for thumbnail style extraction and Whisper for audio transcription fallback
- fal.ai / Google (US) — nano-banana-pro image model for thumbnail generation
- Groq (US) — primary Whisper endpoint for audio transcription
- Polar.sh (US) — subscription billing and payment processing
- Publer (Malta) — optional; only when you connect your Publer account to publish drafts
International transfers to non-EU providers happen under the EU Standard Contractual Clauses.
How long we keep it
- Generated outputs, voice fingerprints, style profiles: kept while your account is active. Deleted when you delete your account.
- Uploaded audio/video source files: transcribed then deleted from storage within minutes of processing (uploads bucket has a scheduled cleanup).
- Face photos and reference thumbnails: kept until you remove them or delete your account.
- Server logs: up to 30 days at our hosting provider.
- Billing records: retained for the period required by Hungarian accounting law (currently 8 years) even after account deletion.
Your rights
You can:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and all associated data (in-app, from Settings, or by emailing us)
- Export your generated outputs (CSV export in the calendar)
- Restrict or object to processing
- Complain to the Hungarian Data Protection Authority (NAIH)
For access, correction, or deletion requests, email info@theignitingstudio.com from the email associated with your account. We respond to verified requests within 30 days as required by GDPR Article 12.
Security
We protect your data with the following measures:
- Encryption at rest: Supabase encrypts database and file-storage disks by default.
- Encryption in transit: all traffic between your browser, our app, and our sub-processors runs over HTTPS/TLS.
- Row-level access control:the database enforces that each user can read and write only their own rows — this is enforced at the database layer, not just in application code, so a bug in the app cannot expose one user’s data to another.
- Passwordless authentication: we do not store passwords. Sign-in uses one-time magic-link URLs delivered by email; sessions are managed by Supabase Auth.
- Restricted admin access: production database and storage admin access is limited to Vatai-Gáspár Kata.
- Third-party API keys (e.g. your Publer key) are stored in a row scoped to your user, protected by the row-level access control above, and never exposed to other users, the browser, or our logs.
No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify you by email without undue delay and in any event within 72 hours of becoming aware, as required by GDPR Article 33.
Automated decision-making
We do not use your personal data for automated decisions that produce legal or similarly significant effects (GDPR Article 22). The AI models we use generate content on request but do not make decisions about you (such as approving, ranking, or restricting access based on personal profiling).
Cookies
We use only strictly necessary cookies for authentication (session cookies set by Supabase Auth). We do not use analytics or advertising cookies at this time. If we add analytics in the future, we will update this policy and add a consent banner where required by the EU ePrivacy Directive.
AI-generated content
Outputs from the Service (captions, descriptions, thumbnails, blog drafts) are generated by AI models based on inputs you provide. AI can produce inaccurate or fabricated content. You are responsible for reviewing outputs before publishing them and for complying with the EU AI Act’s transparency requirements (Art. 50) when posting AI-generated content on public platforms.
Changes to this policy
We may update this policy. Material changes will be communicated by email at least 30 days before taking effect.