AISelfie
AISelfie

Privacy Policy

Last updated: April 13, 2026

This Privacy Policy explains how Aifnet Ltd. ("Company", "we", "us", "our") collects, uses, and protects your personal data when you use AISelfie ("Service"). We are committed to complying with the General Data Protection Regulation (GDPR), applicable Bulgarian data protection laws, and other relevant EU legislation.

Data Controller

Legal Name
Aifnet Ltd.
Registration Number
205591406
VAT ID
BG205591406
Address
1680 Sofia, Bulgaria, Bulgaria Blvd 88, Ent. 3 - offices, fl. 2, ap./office 6

What We Collect

Data You Provide

Account info
Name, email, password
Payment info
Billing details via Stripe (we never store card numbers)
Uploaded images
Images you submit for processing
Communications
Support messages you send us

Collected Automatically

IP address
At registration, for fraud prevention
Usage data
Credit consumption and transaction history
Technical data
Browser, OS, device info via server logs
Cookies
Essential only — no tracking or ads

Your Images

Uploaded images are sent to third-party AI processing APIs (such as Fal.ai) solely to perform the requested operation.

We do not use your images for AI model training.

We do not share your images with third parties beyond what is necessary to provide the Service.

Processed images are stored temporarily and deleted after a reasonable period.

Data Sharing & Transfers

Third-Party Recipients

We share personal data only to the extent necessary with:

Stripe
Payment processing
Fal.ai
AI image processing
Hosting providers
Infrastructure & databases
Legal authorities
When required by law

We do not sell your personal data to any third party.

International Transfers

Some providers may process data outside the EEA. Where this occurs, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions are in place.

Data Retention

Account data
While active + reasonable post-deletion period
Payment records
5-10 years (tax requirements)
Uploaded images
Temporary, then deleted
Server logs
Up to 90 days

Your Rights (GDPR)

Art.15
Right of access
Obtain a copy of your data
Art.16
Right to rectification
Correct inaccurate data
Art.17
Right to erasure
Request deletion ("right to be forgotten")
Art.18
Right to restriction
Restrict how we process your data
Art.20
Right to portability
Receive data in machine-readable format
Art.21
Right to object
Object to legitimate interest processing

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Security & Other

Cookies

We use only essential cookies required for the Service to function (session management, authentication, CSRF protection). These are strictly necessary and do not require consent under the ePrivacy Directive. We do not use analytics, advertising, or third-party tracking cookies.

Security Measures

We implement appropriate technical and organizational measures including encryption in transit (TLS/HTTPS), secure password hashing, and access controls. No system is completely secure, and we cannot guarantee absolute security.

Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

Policy Changes

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the Service or by email. Continued use constitutes acceptance.

Supervisory Authority

You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) at 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria — www.cpdp.bg — or the supervisory authority of your EU member state of residence.

Questions about your privacy?

We take your data seriously. Reach out and we'll respond promptly.

[email protected]