This policy explains how VimiraAI processes data to provide AI image creation, accounts, credits and payment services.
01
Data categories and use
Account and identity data, including email, Supabase identifiers, sign-in method, public profile, display ID and session security data, support registration, authentication, account display and abuse prevention.
Creative and file data, including prompts, reference images, generated images, workspace documents, model parameters and saved state, support generation, editing, workspace recovery, history and asset management.
Task and transaction data, including job state, credit debits and refunds, packages, amounts, currencies, Dodo Checkout sessions and payment status, support fulfillment, reconciliation and payment disputes. VimiraAI does not store full card numbers.
Operations and security data, including request time, network and device information, error logs, audit events and admin actions, support reliability, troubleshooting, security investigation and compliance review.
Contact data submitted through /contact, including name, contact details, project notes and attachments, support responses, support requests and complaints.
02
Storage and third-party processors
Supabase Auth handles sign-in and sessions; Supabase Postgres stores account, task, credit and business records; Supabase Storage stores references and generated files; Supabase Realtime sends authenticated users their generation state.
Dodo Payments handles one-time credit package checkout and payment events. Dodo provides the payment page and processes payment instrument data under its own policy.
Google Fonts serves page fonts. Google receives the IP, browser and request information needed to complete a font request, but not your prompts, images or account records.
To complete a creation request, necessary prompts, model parameters and references may be sent to the enabled model provider. The backend configuration determines the provider, including OpenAI-compatible image APIs, ToAPIs async image APIs and a DeepSeek-compatible Design Agent planning API.
If you choose Google sign-in, Google and Supabase process the data needed for OAuth. We send only data needed for the stated purpose.
03
Asset visibility and model processing
Reference images are stored in private account-isolated storage. Generated images are stored in a publicly readable bucket, so anyone with an object URL may access a file; we do not add it to public cases or the inspiration gallery unless you publish or authorize it.
Model providers may process requests briefly under their security and abuse-prevention rules. VimiraAI does not use your private assets to train general models; provider-side handling follows the enabled provider's terms.
Do not upload confidential information you do not want a third-party model to process, and do not put unnecessary personal information in prompts or images.
04
Retention
Account data, workspaces, task history and undeleted assets generally remain until you delete the data or close the account. Online data is cleaned after a valid deletion request; encrypted database backups rotate through 14 daily, 8 weekly and 12 monthly backups, while Storage backups rotate through 30 daily and 12 weekly backups, so deleted data may remain in isolated backups for up to 12 months or 12 weeks. Backups are not used for daily product access and expire through rotation.
AI run traces in the database are generally retained for 180 days and contact requests for 2 years. Process-level diagnostic logs rotate briefly in the deployment environment and are not long-term account archives, except where needed for an active security, fraud or incident investigation.
Payment, credit, refund and necessary audit records are retained for tax, accounting, fraud prevention and dispute handling, generally no longer than 7 years from the transaction or account closure. After closure, these records are isolated from daily product data and de-identified where feasible.
Legal holds, regulatory requirements or active disputes may extend retention; deletion follows when the preservation purpose ends.
05
Export, deletion and account closure
After signing in, use /account/data to request an export of account and creative records, delete all creative assets or start account closure. Asset deletion and closure require a second confirmation and recent authentication to prevent impersonation.
Account closure stops new generation, handles active tasks and deletes removable account data and Storage objects; payment, credit and audit records remain under the retention rules above. Public URLs, browser caches or copies saved by others may not be retractable by VimiraAI.
If you cannot sign in, dispute processing or want to exercise a correction or restriction right, contact us at /contact. We verify account ownership and provide a traceable status.