1. Scope and baseline explanation
This Privacy Policy applies to information processing activities related to your access to and use of BoxTale AI, including account features, image generation, style reference, multi-image fusion, image editing, video generation, history, downloads, and related support workflows. Unless a specific feature states otherwise, this policy also applies to later capabilities released within the same product ecosystem.
In this policy, “personal information” or “personal data” means information that identifies you, relates to you, or can reasonably be linked to you. We process such information only where it is necessary to provide the service, comply with legal obligations, protect security, improve the product, or otherwise rely on a lawful basis.
Your use of BoxTale AI is also subject to the Terms of Service and any in-product disclosures that apply to specific features. Where a feature-specific notice applies, it will govern within that feature's scope to the extent permitted by law.
2. Categories of information we may collect
Account and identity information: when you register, log in, or manage your account, we may collect your email address, password credentials, optional phone number, account ID, sign-in timestamps, account status, and information related to credits or entitlements. For security, password data is stored in hashed form rather than as plain text.
Content you submit: when you upload product images, reference images, editing inputs, prompts, revision instructions, layering requests, generation parameters, or other workflow materials, we process those materials to fulfill your requests. Generated outputs, thumbnails, selected parameters, and timestamps may also be included in your history.
Technical and usage information: we may collect information related to your device, browser, language preference, access time, request outcomes, error context, operational logs, and basic interaction activity. We also use session cookies to maintain login state and may store language preference or similar lightweight settings in browser storage.
Communications and transaction information: if you contact support, submit feedback, report abuse, or discuss commercial matters, we may process your contact details and the content of those communications. If paid features, subscriptions, invoicing, or settlement workflows are introduced, we may also process the records necessary to manage orders, balances, credit usage, and payment status.
3. How we obtain information
We obtain information mainly in three ways: directly from you, such as when you create an account, log in, upload files, enter prompts, delete history, or contact support; automatically when you use the service, such as through session cookies, timestamps, error logs, and usage records; and from necessary infrastructure or service providers, such as authentication results, object-storage responses, model outputs, or billing state.
Some information is necessary for the service to function. If you choose not to provide required fields, such as the email address needed for authentication, the files needed for generation, or the parameters needed to process a request, we may be unable to provide the relevant feature or may provide only a limited experience.
4. How we use information
We use information to create and manage accounts, authenticate users, maintain sessions, allocate and deduct credits, process generation or editing requests, keep history, provide downloads, and support your ability to review, delete, or otherwise manage available account data.
We also use information to keep the service stable and secure, including for troubleshooting, rate limiting, abuse prevention, anomaly detection, logging, performance review, and protecting against unauthorized access, scraping, fraud, or other harmful activity.
Where reasonable and necessary, we may use aggregated, statistical, or de-identified data to evaluate feature quality, infrastructure demand, model fit, and product direction. That does not mean we automatically use your raw content for public showcases or external marketing unrelated to service delivery.
5. AI processing, model providers, and user-content boundaries
To provide image generation, style transfer, editing, layering, video generation, and related intelligent workflows, your input content, prompts, parameters, and intermediate results may be sent to third-party model or infrastructure providers for processing. Based on the current implementation, those providers may include cloud storage, cloud compute, error monitoring, account database services, and third-party providers of model and inference services.
That processing is generally limited to what is necessary to deliver the service to you, cache tasks, generate outputs, preserve history, troubleshoot failures, or meet security and compliance obligations. Your use of the service does not automatically transfer ownership of your uploaded or generated content to us.
Unless we separately disclose otherwise and, where required, obtain the necessary permission or consent, we do not use your content for public case studies, advertising, or model-training purposes that clearly go beyond what is necessary to provide the requested service. If a future feature uses data under materially different rules, we will disclose that through a feature notice, product prompt, or policy update.
6. Sharing, processing by vendors, and external disclosure
We do not sell your personal information. We may share, delegate processing of, or disclose necessary information only in limited circumstances: to storage, database, authentication, logging, monitoring, model-inference, email, or payment providers as needed to operate the service; to comply with law, regulation, court order, or government request; to protect the rights, safety, and property of BoxTale AI, our users, or the public; or with your direction, consent, or authorization.
If we are involved in a merger, acquisition, restructuring, asset sale, financing, or change of control, relevant information may be transferred as part of diligence or completion of that transaction. In that case, we will seek to require the receiving party to continue handling the information under standards materially consistent with this policy or otherwise provide notice where required.
7. Cookies, local storage, and similar technologies
We use necessary cookies to maintain login sessions, protect account security, and support core site functionality. If you disable those cookies in your browser, some features may not work properly, including staying signed in or completing certain protected actions.
We may also use browser local storage or similar technologies to remember language preference, interface state, or other lightweight user-experience settings. That data is typically stored on your device, and if you clear it, certain preferences may reset.
8. Retention periods, history, and deletion
We retain information for a reasonable period tied to the purposes described in this policy. The exact duration may vary depending on the type of data, product design, technical cost, dispute handling, audit needs, security requirements, and legal obligations. For example, account information is typically retained while your account remains active, and history, generated outputs, thumbnails, and parameters may remain available until you delete them, close the account, we clean them up, or the retention purpose otherwise ends.
The product currently supports deletion of some history records. In practice, deletion may first operate as a logical delete or removal from the main interface rather than immediate erasure from every backup, log, cache, or replicated copy. Where necessary for audit, abuse prevention, dispute resolution, or legal compliance, we may keep limited records for a reasonable period.
Some uploaded or generated files may be stored at object-storage URLs used for delivery and download. These URLs are not intended as public galleries, but technically, anyone who obtains a valid URL may be able to access the file while the URL remains usable and the file remains stored. You should therefore avoid uploading highly sensitive, unauthorized, or unsuitable cloud-processed materials to the service.
9. Security measures
We use reasonable technical and organizational measures designed to reduce the risk of unauthorized access, disclosure, alteration, loss, or misuse. These measures may include access controls, credential management, server-side authentication, password hashing, controlled logging, upload validation, randomized storage paths, baseline monitoring, and error alerting.
No internet transmission, third-party infrastructure stack, or electronic storage system can be guaranteed to be absolutely secure. You remain responsible for protecting your account, devices, downloaded files, and any links or outputs you choose to share with others.
10. International transfers
Because we rely on cloud infrastructure, model services, and technical vendors that may operate in different countries or regions, your information may be transferred to, stored in, or processed outside the jurisdiction where you reside. Data-protection standards in those jurisdictions may differ from those in your own location.
Where applicable law requires it, we take reasonable steps intended to support an appropriate level of protection, such as contractual restrictions, service configuration choices, access controls, or other practical safeguards suitable to the nature of the processing.
11. Your rights and choices
Depending on where you are located and subject to applicable law, you may have rights to access, copy, correct, supplement, delete, restrict, object to, withdraw consent for, or port certain personal information. Those rights are not absolute and may be limited by identity verification, technical feasibility, the rights of others, contractual necessity, dispute handling, or legal obligations.
You can generally exercise available controls by stopping use of the service, deleting visible history, updating account information, or contacting us through the contact page. To protect account security and the rights of others, we may ask for reasonable verification before acting on a request and may keep minimal records needed to document how the request was handled.
12. Children's privacy
BoxTale AI is intended for users who have the legal capacity and practical authority to handle the relevant materials, brand assets, and commercial content they submit. We do not knowingly target children or encourage minors to use the service independently without appropriate authorization.
If you believe a child or unauthorized minor has provided personal information to us, please contact us. After verification, we will take reasonable steps to delete or otherwise handle the information in accordance with applicable law.
13. Policy updates
We may update this Privacy Policy to reflect product changes, new service scope, infrastructure adjustments, legal developments, or risk-control needs. The revised version will be posted on this page and will become effective when posted or on the date stated in the update.
If an update materially affects your rights or materially changes how we use or share information, we may provide additional notice through in-product messaging, your account email, or another appropriate channel where reasonably practicable. Continued use of the service after an update generally means you understand and accept the revised policy.
14. Contact us
If you have questions about this Privacy Policy, your personal information, deletion requests, infringement complaints, or security issues, please contact us through the contact page. To help us process the request efficiently, include your account email, the relevant page or feature, the approximate time involved, a description of the issue, and the action you want us to take.
We will review and respond within a reasonable time, but we may need to verify identity, confirm the scope of the request, or assess whether legal, security, or operational reasons require us to retain certain information.