Privacy Policy
Last updated: 4 July 2025
Welcome to Aluo ("Aluo AI", "we", "our"). This Privacy Policy explains how we collect, use, disclose and safeguard your personal data when you visit our websites or use our services (collectively, the "Service").
The images you upload are only saved in your browser's temporary cache and are cleared regularly. AI-generated output content is not stored server-side unless you explicitly agree.
1. Information We Collect
Category | Examples | Purpose |
---|---|---|
Account Data | Name, email address, avatar URL, locale | Account creation, login, support |
Usage Data | Editor actions, generation history, credit consumption | Product analytics, model tuning, fraud prevention |
Device Info | Browser UA, OS, screen resolution | Optimisation, performance monitoring |
Cookies / Local Storage | Session token, UI preferences, recent projects | Seamless sign-in, personalised UI, quick resume |
Billing Data | Order ID, payment token (stored by Stripe) | Subscription management, invoicing |
2. How We Use Your Information
- Provide and maintain the Service (AI generation, online editor, HD export)
- Send important notices (system updates, low-credit reminders)
- Analyse aggregated usage to improve features and stability
- Detect fraud and abuse
- Comply with legal obligations
3. AI Content & Model Usage
- Prompts & images are streamed to the model endpoint only during inference and are not persisted. They are never used for model fine-tuning or retraining.
- Models in production We orchestrate multiple state-of-the-art models, including GPT-Image 1, Flux Context V3, and Stable Diffusion XL. The router selects the best model for your scene prompt.
- Background removal When you enable Auto-Remove Background, the computation runs entirely in your browser; image pixels are not uploaded to our servers.
- You own the copyright to any final image generated / edited with Aluo, except where a template with its own licence is explicitly indicated.
4. Data Retention & Security
- Database hosted on Supabase (PostgreSQL), traffic encrypted via HTTPS/TLS.
- AI output files remain in the browser session for download and are discarded afterwards, unless you opt to save them.
- User-uploaded images live in the browser's IndexedDB cache and are purged by the client at regular intervals or when you clear site data.
- We enforce the principle of least privilege and run periodic security audits.
- Despite best efforts, no online transmission is 100 % secure—if you discover a vulnerability, email [email protected].
5. Sharing & Disclosure
We never sell or rent personal data. We share it only when:
- You give explicit consent;
- It's required for payment processing (Stripe PCI-DSS);
- Law enforcement or public authorities demand it;
- We undergo a business transfer (we will give prior notice).
6. Your Rights
- Access or correct your account details
- Download your generation records
- Withdraw consent and delete your account (Settings → Delete Account)
7. Children's Privacy
The Service is intended for users 16 years and older. If we learn a child under 16 has provided personal data, we will delete it and close the account.
8. Changes to This Policy
We may update this Policy. We'll post any changes here and, if they're significant, send a site notification or email 7 days in advance. Continued use of the Service means you accept the revised Policy.
9. Contact Us
Email [email protected]
Address Boulder, CO, USA
Thank you for trusting Aluo!