Privacy Policy – Creator AI : Photo & Video

Effective Date: June 1, 2026

Last Updated: June 22, 2026

Version: 1.3

This Privacy Policy explains how JAI UYGULAMA VE YAPAY ZEKA TEKNOLOJİLERİ ANONİM ŞİRKETİ ("JAI," "Company," "we," "us," or "our") collects, uses, stores, shares, transfers, and protects personal data when you access or use the Creator AI: Photo & Video mobile application, its related services, and any associated websites or support channels (collectively, the "App" or "Services").

For users located in Türkiye, this Privacy Policy also serves as a disclosure notice under Article 10 of Turkish Personal Data Protection Law No. 6698 ("KVKK" or "PDPL").

For users located in the European Economic Area, the United Kingdom, Switzerland, California, or other jurisdictions with applicable privacy legislation, additional rights and legal bases described in this Privacy Policy may apply.

By accessing or using the App, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request that consent separately.


1. Data Controller and Company Information

The data controller responsible for processing your personal data is:

Company Name: JAI UYGULAMA VE YAPAY ZEKA TEKNOLOJİLERİ ANONİM ŞİRKETİ

Address: Reşitpaşa Mah. Katar Cad. Arı 2 Binası, No: A Blok / 4 / 1 İç Kapı 501, 34467 Sarıyer / İstanbul, Türkiye

Privacy and Support Email: non-gaming@jaitech.ai

You may use this email address to submit privacy requests, account-related questions, complaints, or support requests.


2. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed through:

This Privacy Policy does not apply to third-party websites, applications, or services that you access independently of the App.


3. Principles of Personal Data Processing

We process personal data:


4. How We Collect Personal Data

4.1 Data You Provide Directly

This includes data provided when you: sign in through Apple or Google; create or update your profile; upload an image or video; enter a prompt or generation instruction; generate, save, publish, report, or remix content; contact customer support; submit a complaint, report, or privacy request; or participate in surveys, promotions, or feedback activities.

4.2 Data Collected Automatically

When you use the App, certain technical and usage data may be collected automatically through the App, our infrastructure, and authorized third-party service providers. This may include device data, IP address, app activity, technical logs, analytics events, purchase events, and advertising or attribution identifiers where legally permitted.

4.3 Data Received from Third Parties

We may receive limited data from: Apple or Google (authentication); Apple App Store or Google Play (purchases); subscription and paywall management providers (Adapty); analytics and attribution providers (AppsFlyer, Meta); AI infrastructure and model providers; users who report content or accounts; and authorities or professional advisors where legally permitted or required.


5. Categories of Personal Data We Process

5.1 Account and Authentication Data

We process: email address made available through Apple or Google sign-in; authentication provider and provider-specific account identifier; authentication and session tokens; account creation and login timestamps; account status and internal user identifier. Apple may provide a relay email address where you choose to hide your email address. We do not request your telephone number, date of birth, or legal name during account registration.

5.2 Optional Profile Data

You may voluntarily provide: username, display name, profile picture, biography, and other profile information. You are responsible for avoiding the inclusion of unnecessary sensitive or confidential information in your public profile.

5.3 Uploaded Media and Input Content

We process: photographs, images, videos, cropped or edited versions of uploaded media, files selected through the camera or photo library, visual references used for generation, and technical metadata associated with uploaded files.

Uploaded media may contain personal data relating to you or other individuals. You must have the necessary rights, authority, or permission to upload and process any image or video that depicts another person.

The App does not use uploaded faces for facial recognition, identity verification, or biometric identification. We do not create biometric templates for the purpose of uniquely identifying individuals.

Metadata handling: Photographs are re-encoded upon upload; EXIF data, GPS coordinates, and embedded device information are stripped before storage and transmission to AI providers. Videos are currently stored without metadata removal; video metadata stripping is planned for a future update.

5.4 Prompts and Generation Data

We process: text prompts, negative prompts, generation instructions, model selection, style settings, image dimensions and aspect ratio, video duration, quality settings, motion and camera settings, reference media, generation request identifiers, generation timestamps, and generation status and error information.

5.5 Generated Content

We process and store: AI-generated images and videos, edited or transformed content, thumbnails and preview files, generation metadata, content publication status, and content moderation status. Generated content remains private unless you actively choose to publish or share it.

5.6 Community and Engagement Data

We process: published posts, public profile information, likes, favorites, remix actions, content opens, viewing and engagement activity, content saves, publication and removal actions, and reports and moderation outcomes. The App does not currently support public comments.

5.7 Technical, Device, and Usage Data

We process: IP address; device model, operating system and version, app version, device language, country or general region, time zone; device and application identifiers, session identifiers, request identifiers; usage events, feature interactions, screen views, generation attempts, performance information, network and connection information; and error, diagnostic, and security logs. We do not request access to your precise GPS location.

5.8 Notification Data

If you enable push notifications, we process: push notification token, device and platform information, notification delivery status, notification interaction events, and notification preferences.

5.9 Purchase, Subscription, and Credit Data

Purchases are processed by Apple App Store or Google Play. We do not directly collect or store your complete payment card details. We process: product or subscription identifier, subscription status, purchase date, renewal and expiration date, trial status, transaction identifier, entitlement status, credit balance and usage, purchase verification data, restore purchase status, and refund or cancellation status. Adapty assists with subscription status, entitlement management, and purchase analytics.

5.10 Support, Report, and Communication Data

When you contact us or submit a report, we process: your email address, message content, screenshots, images or videos, account and request identifiers, support history, reported content, report category, moderation notes, resolution status, and related technical information.


6. Purposes for Processing Personal Data

We process personal data to:

We do not use uploaded media, prompts, or generated outputs to train our own generative AI models.

Regarding third-party AI providers: we do not submit user content to fal.ai for the purpose of training their general-purpose models. However, under fal.ai's standard terms, usage data may be processed to improve and develop AI models unless an enterprise agreement is in place. We are currently evaluating our fal.ai contract tier to determine whether stronger training-exclusion guarantees apply. Input and output data sent to fal.ai is retained for up to 30 days (request data) and at least 7 days (generated media) under fal.ai's default policy.

For AI-assisted content categorization, we use GPT-4o-mini via OpenRouter. OpenRouter does not log or store prompts by default. OpenAI does not use API-submitted data for model training by default and retains content for up to 30 days for abuse monitoring before deletion.


7. AI Processing and Third-Party AI Services

7.1 Use of AI Infrastructure

We use fal.ai as an AI infrastructure and API service provider to access and operate third-party image and video generation models. Models may include those provided by Google, ByteDance, xAI, Kling AI, or other providers. The model catalog may change as models are added, removed, updated, or replaced.

We use GPT-4o-mini via OpenRouter for AI-assisted content categorization when content is published.

7.2 Data Sent for AI Generation

For image and video generation (fal.ai), we may send: text prompts, generation settings, uploaded photographs or videos, reference images, cropped or edited media, generated intermediate files, and technical request identifiers. We transmit only the information reasonably required to perform the requested generation.

For content categorization (OpenRouter / GPT-4o-mini), we send published content metadata necessary to generate category labels. We do not send uploaded personal photographs to the language model.

7.3 User Notice and Consent

Before personal media is transmitted to a third-party AI service, the App provides a specific notice and requests acknowledgment or consent where required by applicable law or platform policy. If you do not agree to the processing required for a photo-based or video-based generation request, you should not upload the relevant media or use that generation feature.

7.4 Retention by AI Providers

fal.ai: Request input/output data is retained for up to 30 days. Generated media files are retained for at least 7 days. We currently apply fal.ai's default retention settings and do not pass storage-override headers. We recommend against including sensitive personal information in prompts beyond what is necessary for the generation request.

OpenRouter / OpenAI (GPT-4o-mini): OpenRouter does not store prompt content by default. OpenAI retains API content for up to 30 days for abuse monitoring; data is not used for model training.

7.5 Model Training

We do not use user inputs or outputs to train our own generative AI models. We do not submit user content to OpenRouter or OpenAI for training purposes; their default policies exclude API data from training.

For fal.ai, under standard (non-enterprise) terms, usage data may be used to improve and develop AI models. We are evaluating whether an enterprise agreement providing stronger training-exclusion guarantees is appropriate. Until confirmed otherwise, users should be aware that fal.ai's standard terms permit this use.


8. Public Content and Community Features

Content saved in your personal gallery is private unless you choose to publish it. When you publish content: it may become visible to other users; your username, display name, profile image, or profile may be associated with it; other users may view, like, favorite, report, or remix it; and the content may appear in Feed, Explore, Moov, search, recommendation, or promotional surfaces within the App.

Remixing uses the published content, prompt structure, or generation settings to create a new output. Remix is applied only to content you have chosen to publish. Users are not permitted to directly download another user's content through the App.

Deleting a public post may remove it from public display. Copies may remain temporarily in backups, caches, moderation systems, or CDN systems. You should not publish content that you do not want others to view, interact with, report, or remix.


9. Content Moderation and Safety

We may review uploaded, generated, or published content: after a user report; when automated systems identify potential policy violations; to investigate abuse or technical issues; to enforce our Terms of Use; to comply with legal requirements; or to protect users and the public.

Authorized employees, contractors, or service providers may access limited user content when necessary for moderation, support, safety, security, or technical operations. Reported or potentially harmful content may be reviewed by human moderators.

We may remove content, limit its visibility, restrict features, suspend accounts, or terminate accounts where we reasonably believe that content or conduct violates applicable law, our Terms of Use, community standards, or safety requirements.


10. Automated Processing and Recommendations

We may use automated systems to: rank or recommend content; personalize Feed, Explore, or Moov; detect spam, abuse, or harmful content; identify unusual purchase or account activity; prioritize content for moderation; and measure product and campaign performance. These systems are not intended to make legal or similarly significant decisions about you without appropriate safeguards.


11. Service Providers and Data Recipients

We may share personal data with authorized third parties that process data on our behalf or assist us in providing the Services:

AI Infrastructure and Processing

Authentication

Purchases and Subscription Management

Analytics and Attribution

Notifications

Infrastructure, Hosting, Storage, and Delivery

Monitoring and Diagnostics

Professional and Legal Recipients

We may disclose data to legal advisors, auditors, accountants, insurers, financial institutions, courts, law enforcement, and administrative or regulatory authorities, where required or permitted by law.

We require service providers to process personal data only for authorized purposes and subject to applicable contractual, confidentiality, security, and data protection obligations.


12. Analytics, Attribution, Advertising, and Tracking

Active analytics tools include Amplitude (mobile and backend), Firebase Analytics/GA4 (mobile), Firebase Crashlytics (mobile), AppsFlyer (install attribution), and Meta/Facebook SDK (advertising attribution). AWS CloudWatch is used for backend structured logging.

The App does not currently display personalized third-party advertisements. We may introduce advertising features in a future version; before doing so, we will update this Privacy Policy and provide any legally required notices or choices.

Where required, we request permission through Apple's AppTrackingTransparency (ATT) framework before accessing the advertising identifier. The ATT prompt is presented before any third-party SDK is initialized. If you grant permission, AppsFlyer and Meta (Facebook) SDK access the IDFA for attribution purposes. If you decline, both SDKs operate without the IDFA; Meta falls back to Aggregated Event Measurement (AEM).

We do not sell personal data for monetary payment. Where applicable law defines certain advertising disclosures as a "sale" or "sharing," eligible users may contact us to exercise applicable opt-out rights.


13. Push Notifications and Marketing Communications

Push notifications are sent only after you grant notification permission through your device. Notifications may include: generation completion notices, service and account updates, security messages, credit or subscription updates, product announcements, feature recommendations, and promotional messages. You can disable push notifications at any time through your device settings.

Marketing emails and promotional push notifications will be sent only where permitted by applicable law. Where legally required, we will obtain separate consent and provide an unsubscribe or opt-out mechanism. Withdrawing marketing consent does not prevent us from sending essential transactional, security, legal, or service-related communications.


14. Legal Bases for Processing

14.1 Türkiye and KVKK

Under Article 5 of KVKK, personal data may be processed where: you have provided explicit consent; processing is necessary for the performance or establishment of a contract; processing is necessary for compliance with a legal obligation; processing is necessary for the establishment, exercise, or protection of a legal right; or processing is necessary for our legitimate interests, provided that your fundamental rights and freedoms are not harmed.

For transfers of personal data outside Türkiye (including to fal.ai, AWS, Firebase, AppsFlyer, Meta, Adapty, OpenRouter, and OpenAI), your explicit consent is obtained separately under Article 9 of KVKK. The Company complies with VERBİS registration requirements where applicable thresholds are met.

14.2 European Economic Area, United Kingdom, and Switzerland

Where GDPR or equivalent legislation applies, we rely on: performance of a contract; compliance with legal obligations; legitimate interests; consent; establishment, exercise, or defense of legal claims; and protection of vital interests where applicable.

Where we rely on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

Processing of photographs containing faces through AI systems may constitute high-risk processing under GDPR Article 35. We have conducted or are conducting a Data Protection Impact Assessment (DPIA) covering this activity.


15. International Transfers of Personal Data

Our Company is established in Türkiye. The following service providers are located in or accessible from countries outside Türkiye or your country of residence: fal.ai (United States), Amazon Web Services / eu-west-1 (Ireland), Firebase and Google (United States), Apple (United States), OpenRouter and OpenAI (United States), AppsFlyer (United States), Meta Platforms (United States), and Adapty (United States).

Where required, we use applicable legal and contractual safeguards including standard contractual clauses, KVKK-recognized transfer mechanisms, adequacy decisions, binding contractual data protection obligations, explicit consent where legally permitted and required, and other valid transfer mechanisms recognized by applicable law.

Primary AWS region: eu-west-1 (Ireland). This is the current development configuration; the production region will be confirmed prior to launch.

Backup retention: Automated database backups are retained for 7 days. After a record is deleted from live systems, it may persist in automated backups for up to 7 days before being overwritten.


16. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

16.1 Account and Profile Data

Account and profile data is retained while your account remains active. When you request account deletion, your account is immediately deactivated and all sessions are revoked. A 30-day grace period applies during which your account may be restored. After 30 days, the following are permanently deleted: profile information and account data, all generated content and generation records, likes, saves, favorites, and personalization signals, engagement records, and uploaded reference files belonging solely to your account.

Data retained after account deletion: audit logs are retained indefinitely for legal and operational compliance. Payment and subscription transaction records are anonymized rather than deleted, for accounting and financial audit purposes. Reference files used in another user's content are retained to preserve that content's integrity.

Deleted data may persist in automated database backups for up to 7 days after deletion from live systems.

16.2 Uploaded Images and Videos

Uploaded image files: EXIF and GPS metadata are stripped at upload. Files not associated with any generation are automatically deleted after 48 hours. Files associated with another user's published content are retained for as long as that content exists.

Uploaded videos: retained under the same conditions. Note: video metadata is not currently stripped at upload; this is planned for a future update.

16.3 Generated Outputs

Generated outputs remain in your private gallery until you delete them or delete your account. If you delete an individual output, it is marked as removed and the CDN cache is cleared; however, the underlying media file is not automatically deleted from storage at that time. A lifecycle policy for removing storage files upon individual content deletion is planned.

16.4 Published Content

Public content may remain available until you delete it, remove it from publication, delete your account, or we remove it. After deletion, temporary copies may remain in caches, backups, moderation records, or CDN systems for a limited period.

16.5 Prompts and Generation Metadata

Prompts and generation metadata are retained to provide generation history, enable remix functionality, diagnose errors, prevent abuse, improve product performance, and resolve support and moderation issues.

16.6 Purchase Records

Purchase and subscription information is retained for the duration of the subscription and for additional periods required for financial, accounting, tax, dispute, fraud prevention, or legal compliance purposes. Payment records are anonymized upon account deletion rather than deleted. Apple, Google, and Adapty may retain separate purchase records under their own legal obligations.

16.7 Technical and Security Logs

Application logs are sent to AWS CloudWatch with filtering to prevent personal data leakage. Security, performance, and usage logs are retained for a limited period appropriate to the relevant operational, security, analytics, or compliance purpose.

16.8 Support Communications

Support communications are retained while necessary to resolve the request and for a reasonable period afterward for service quality, dispute resolution, security, and legal purposes.

16.9 Reports and Moderation Records

Reports and moderation records are retained indefinitely. This includes: report status, category, reporter and reported party identifiers, timestamps, content or profile snapshots at the time of the report, and related audit logs. Reports filed by a user who subsequently deletes their account are deleted with the account. Reports filed against a user who subsequently deletes their account are retained as moderation evidence.


17. Account and Content Deletion

You may delete your account through the App via: Settings > Account > Delete Account. Upon receiving a deletion request:

The following may be retained after account deletion: automated database backups (up to 7 days); CDN caches (limited period); security and diagnostic logs; moderation records related to reports filed against your account; support communications; anonymized payment and transaction records; and data required to comply with law or defend legal rights.

Deleting your account does not automatically delete records independently controlled by Apple, Google, Adapty, fal.ai, OpenRouter, or other third-party providers.


18. Data Security

We implement the following technical and organizational security measures:

No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security. If a personal data breach occurs, we will investigate and notify affected users or competent authorities where required by applicable law.


19. Children — Age Requirements and Parental Rights

The App is rated 13+ on the Apple App Store (12+ in Vietnam, Brazil, and Korea) and rated 12+ (Parental Guidance) on Google Play.

19.1 Minimum Age

You must be at least 13 years old to use the App. If you are under 13, you may not use the App. In jurisdictions where a higher minimum age applies for consent to data processing — including 16 years in certain EEA member states under GDPR Article 8 — users below that age must have verifiable parental or guardian consent before using the App.

If you are between 13 and 17 years old, your parent or legal guardian must review and agree to these Terms and our Privacy Policy on your behalf before you use the App.

19.2 Data We Collect from Minors

We do not knowingly collect more personal data from users under 18 than is reasonably necessary to provide the App. We do not knowingly collect personal data from users under 13. We do not use personal data of minors for advertising profiling or behavioral targeting.

19.3 Parental Controls and Rights

Parents or legal guardians of minor users may contact us at non-gaming@jaitech.ai to: review personal data collected from the minor; request correction or deletion of the minor's personal data; withdraw consent and request account deletion; or raise concerns about the minor's use of the App. We will respond to verified parental requests within 30 days.

19.4 Discovery of Underage Users

If we learn that a user is under 13, or that a user under the applicable consent age is using the App without the required parental consent, we will suspend or terminate the account, remove the user's published content, and delete associated personal data. If you believe your child has used the App without authorization, please contact us immediately at non-gaming@jaitech.ai.

19.5 Content Appropriate for Minors

The App's content moderation and safety filters are calibrated to the 13+ age rating. Content inappropriate for users aged 13 and above is prohibited under our Terms of Use. Users who encounter inappropriate content should use the in-app reporting mechanism.


20. Your Privacy Rights

Your rights depend on your location and applicable law. You may contact us to request: confirmation of whether we process your personal data; access to personal data; correction of inaccurate or incomplete data; deletion or destruction of personal data; restriction of processing; objection to certain processing; withdrawal of consent; a copy of certain personal data; data portability where applicable; information about recipients of personal data; objection to certain automated processing; and opt-out from applicable advertising-related sale or sharing.

Requests should be sent to non-gaming@jaitech.ai. Response times:


21. Rights Under KVKK

Under Article 11 of KVKK, data subjects may: learn whether personal data is being processed; request information regarding processing; learn the purpose of processing and whether data is used accordingly; learn the third parties to whom data is transferred in Türkiye or abroad; request correction of incomplete or inaccurate data; request deletion or destruction where conditions are met; request that correction, deletion, or destruction be communicated to relevant third parties; object to results arising through exclusively automated systems; and claim compensation where damage is suffered due to unlawful processing.

Requests may be submitted to:

JAI UYGULAMA VE YAPAY ZEKA TEKNOLOJİLERİ ANONİM ŞİRKETİ
Reşitpaşa Mah. Katar Cad. Arı 2 Binası, No: A Blok / 4 / 1 İç Kapı 501, 34467 Sarıyer / İstanbul, Türkiye
Email: non-gaming@jaitech.ai


22. Additional Rights for EEA, UK, and Swiss Users

Where GDPR or equivalent legislation applies, you may: access your personal data; correct inaccurate data; request deletion; restrict processing; object to processing based on legitimate interests; withdraw consent; receive certain data in a structured, commonly used, machine-readable format; request transmission of eligible data to another controller; lodge a complaint with the relevant supervisory authority; and receive information about applicable safeguards for international transfers. You may object to direct marketing at any time.


23. California Privacy Notice

This section applies only where the California Consumer Privacy Act, as amended (CCPA/CPRA), applies to us and to the relevant processing activity. California residents may: know the categories and specific pieces of personal information collected; know the sources, purposes, and recipients; request deletion; request correction; opt out of the sale or sharing of personal information; limit certain uses of sensitive personal information where applicable; and receive equal service without discrimination for exercising privacy rights.

We do not sell personal information for monetary payment. We do not knowingly sell or share the personal information of individuals under 13. We comply with the Children's Online Privacy Protection Act (COPPA) with respect to users under 13 in the United States. We do not knowingly sell or share the personal information of individuals under 16. California privacy requests may be sent to non-gaming@jaitech.ai.


24. Complaints

You may contact us first regarding any privacy concern at non-gaming@jaitech.ai.

Users in Türkiye may submit a complaint to the Turkish Personal Data Protection Authority (KVKK):
Nasuh Akar Mah. Ziyabey Cad. 1407. Sok. No: 4, 06520 Balgat / Ankara, Türkiye
🌐 www.kvkk.gov.tr

Users in the EEA, United Kingdom, Switzerland, California, or another jurisdiction may also have the right to complain to the competent privacy or data protection authority in their place of residence.


25. Third-Party Links and Services

The App may contain links or integrations that direct you to third-party services. Third parties process personal data according to their own terms and privacy policies. We do not control the independent privacy practices of Apple, Google, social media platforms, app marketplaces, or websites that you access outside the App. You should review the applicable third-party privacy policy before providing personal data directly to such a third party.


26. Changes to This Privacy Policy

We may update this Privacy Policy to reflect product changes, new features, new service providers, changes in data practices, legal or regulatory developments, or security or operational changes. When we update this Privacy Policy, we will revise the "Last Updated" date and version number. Where required by law or where changes materially affect your rights, we may provide additional notice through the App, email, push notification, a consent or acknowledgment screen, or another appropriate method.


27. Contact Us

JAI UYGULAMA VE YAPAY ZEKA TEKNOLOJİLERİ ANONİM ŞİRKETİ
Reşitpaşa Mah. Katar Cad. Arı 2 Binası, No: A Blok / 4 / 1 İç Kapı 501, 34467 Sarıyer / İstanbul, Türkiye
Email: non-gaming@jaitech.ai