Privacy
Privacy Policy
This page explains what data AIVIZ keeps, where it lives, how long it's kept, who else processes it, and how to ask for a copy or its deletion. Your use of AIVIZ is also subject to the Terms of Service.
This English version is provided for convenience. The Indonesian version, Kebijakan Privasi, is the governing text under Law No. 24 of 2009 (UU 24/2009). If the two differ, the Indonesian version prevails.
1. What AIVIZ stores on its servers
Your AIVIZ account stores as little as it can, and only what accounts, credits and payments need to work:
- Email address. Used to sign you in, to send payment receipts, and to remind you before your credits expire. AIVIZ sends no email to sign you up or sign you in, and doesn't verify your address by email.
- Password. If you sign up with an email and a password, our account service (Supabase) stores only a one-way hash of it. AIVIZ doesn't store your password and can't read it back.
- Google sign-in. If you sign in with Google, Google tells us your email address and confirms it's yours, along with the name and profile picture your Google account shares. That confirmation is what unlocks the free credits. AIVIZ never receives your Google password and can't access your Google account.
- Terms consent. Your tick accepting the Terms of Service and this Privacy Policy, recorded once with its date and time. Creating an account and buying credits both require it. Nothing else about you is asked for or kept beside it, and personal details an earlier version of this policy asked for, which AIVIZ no longer collects, have been deleted.
- Credit balance and lots. How many credits you have, when they were granted, when they expire and how many are used, so the 30-day validity and every charge can be counted.
- Orders and receipts. Order number, pack, price, payment method, status and payment time, plus any refund. Needed for bookkeeping, handling complaints and tax obligations.
- Image analysis. For every image analyzed: a keyed fingerprint (hash) of the image, not the image itself, and the result of the analysis, so the same image is never read again or counted twice.
- Short technical records. The time and outcome of every render or analysis (how many credits, success or failure), and hashes of the IP address and sign-up email address, to prevent abuse of the free credits. A hash can't be turned back into the original address.
- Device marker. To keep free credits fair, AIVIZ sets one cookie holding a random value and nothing else — no name, no email address, nothing read from your device. What reaches the database is a keyed hash of that value and a keyed hash of your network block, which is how the free credits are counted one per device and per network. A keyed hash can't be turned back into the value it came from. The cookie is first-party and lasts 400 days; it is never used to follow you across other websites, and no advertiser or analytics service receives it. It affects free credits only: your account, your renders and every pack work the same either way.
Source images and renders aren't stored on the server as part of your account; see sections 2 and 3.
2. What stays only in your browser
- Projects, canvases, the images you upload and the renders delivered to the studio are stored in your browser's storage on your device, not on AIVIZ's servers.
- So they belong to one browser on one device. Opening AIVIZ in another browser or on another device won't show the same projects.
- Clearing site data, closing a private window, or removing the browser deletes those projects, uploads and renders for good. AIVIZ keeps no copy, so we can't recover them. Export the projects that matter before you clear your browser.
- Your credit balance, orders and receipts aren't lost: they live in your account on the server and come back as soon as you sign in.
3. Paid renders are kept for 24 hours
- Renders you pay for with credits are kept on the server for up to 24 hours after the render finishes, so they can be sent again if the first download fails or the tab closes before they arrive.
- After 24 hours a scheduled job deletes them from the server, and they can't be sent again. Save what you need before then.
- The source images you upload are sent to the AI model to be rendered or analyzed, and AIVIZ doesn't keep them afterwards.
4. Third parties that process your data
AIVIZ uses the following services, and only the data listed reaches each of them:
- Supabase — database and account service: email address, password hash, Google sign-in details, terms consent, credits, orders and receipts, image analysis results, and the temporary storage of paid renders.
- Google Gemini — the AI model that makes renders and reads images: the source images and render instructions you send. For image analysis, the same data is processed by OpenAI.
- Google — if you choose to sign in with Google: Google checks your account and shares your email address, name and profile picture with our account service. When AIVIZ shows your account's face, your browser loads that profile picture from Google's servers, so Google sees your IP address and browser for that request. A photo you choose on your account page replaces it and stays in your browser only.
- Midtrans — payment processor: order number, amount, payment method and email address, for the payment. Your card or e-wallet details are handled by Midtrans and your payment provider, never by AIVIZ.
- Resend — transactional email: the recipient's address and the email's content (such as receipts and expiry reminders).
- Cloudflare — Turnstile, the "not a robot" check on the sign-in page: your IP address and technical browser signals while the check runs.
AIVIZ doesn't sell, trade or advertise with personal data. Some of the services above process data outside Indonesia.
6. How long data is kept
- Paid renders: 24 hours (section 3).
- Credit lots: until they expire, 30 days after they're granted; the record then stays for bookkeeping.
- Email address, password hash and terms consent: as long as your account exists.
- The device and network hashes kept with your account (section 1): as long as the account exists. The cookie itself lasts 400 days in your browser.
- The record of a free-credit grant is kept for good, including after an account is deleted. It holds the device, network and address hashes the grant was counted under, and the moment: no name, no email address and nothing you have made. It is what keeps one free grant to one, so that deleting an account and opening another does not hand the same credits out again.
- Orders and receipts: as long as bookkeeping and tax obligations require, including after an account is deleted, in as little detail as possible.
- Technical records and image analysis results: up to about one year. Address hashes are kept the same year, except the one in a free-credit record above.
7. Asking for a copy or deletion of your data
- You can ask for a copy of your account data, a correction of anything wrong, or the deletion of your account. Email aivizstudio.id@gmail.com from your account's email address. We answer within 30 days.
- Deleting your account forfeits any unexpired credits. Unused credits are deleted with the account and aren't paid back as money, unless you ask for a refund first, as far as the payment method allows (see Terms of Service section 7). Use your credits or ask for a refund first, then ask for deletion.
- Projects and renders in your browser need no request: you delete them yourself from the storage panel on the Account page or by clearing site data.
- Order and receipt records stay as section 6 says, because bookkeeping law requires them.
- The record of a free-credit grant stays as section 6 says: the three hashes and the moment, nothing else. Keeping it is what keeps one free grant to one.
8. Who can use AIVIZ
- Creating an account and buying credits require accepting the Terms of Service and this Privacy Policy. You accept them with one tick, and AIVIZ records the moment you did. AIVIZ asks for no ID document.
- A blocked account gets no credits and has every payment refunded.
9. Security and changes
- Connections to AIVIZ are always encrypted (https). Payment and database keys live only on the server and are never sent to the browser.
- This policy may change. The date below changes whenever its content does.
10. Contact
For questions about this policy or your data, email aivizstudio.id@gmail.com. The full terms of the service are on the Terms of Service page.
Last updated 24 September 2026