Transtoart Privacy Policy
This Privacy Policy explains how Transtoart, Inc. (“Transtoart,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our websites, applications, APIs, and related services (collectively, the “Services”). The Services include our chat assistant, image and video generation (“Imagine”), character roleplay features, and subscription plans (Lite, Super, Max, and any future tier).
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use the Services. This Policy is incorporated into and forms part of our Terms of Use.
- Information we collect
- How we use information
- AI processing and model providers
- How we share information
- Cookies and similar technologies
- Local storage of your chats
- Data retention
- Security
- International transfers
- Children’s privacy
- Your privacy rights
- Regional disclosures (EEA/UK, California, others)
- Third-party services and links
- Changes to this Policy
- Contact us
1. Information we collect
1.1 Information you provide
- Account information. When you create an account, we collect your email address and, depending on your sign-in method, your name and profile image from your identity provider (for example, Google).
- Authentication data. Authentication is handled by Firebase Authentication (Google LLC). Firebase stores credential hashes, sign-in tokens, and basic device metadata on our behalf.
- Content you submit.Prompts, messages, uploaded files, reference images, character descriptions, ratings, and other inputs you submit to the Services (collectively, “Input”), and the outputs we generate in response (“Output”).
- Payment information. Subscription payments are processed by Paddle. We do not receive or store your full payment card or bank details. We receive a subscription identifier, transaction status, plan, currency, billing country, and payer email.
- Communications. If you contact us by email, support form, or social media, we collect the contents of your message and your contact details.
- Preferences. Language, theme, notification settings, NSFW opt-in status, and other in-product settings.
1.2 Information collected automatically
- Log and device data. IP address, approximate geolocation derived from IP, browser type and version, operating system, device identifiers, referring/exit pages, date and time of requests, and crash diagnostics.
- Usage data. Pages visited, features used, prompts submitted, model selected, time spent, error events, and aggregate metrics.
- Cookies and similar technologies. See Section 5.
1.3 Information from third parties
- Identity providers. If you sign in via Google, we receive basic profile information (email, name, profile picture) consistent with your Google permissions.
- Payment processors. Paddle shares the transaction metadata described above.
- Fraud and abuse signals. We may receive risk signals from anti-fraud and anti-abuse vendors.
2. How we use information
We use the information described above to:
- Provide, operate, maintain, and improve the Services;
- Generate AI responses, images, video, and other content in response to your Input;
- Authenticate you, secure your account, and process subscription payments and refunds;
- Personalize your experience (language, preferences, suggested characters);
- Detect, investigate, and prevent fraud, abuse, security incidents, violations of our Terms of Use, and unlawful activity;
- Comply with legal obligations, respond to law enforcement requests, and enforce our agreements;
- Communicate with you about the Services, including transactional messages, security notices, and, if you have opted in, marketing;
- Conduct analytics, research, and product development, including training and fine-tuning of internal safety classifiers and abuse detectors using aggregated or de-identified data;
- Enforce age and content restrictions, including by reviewing flagged content; and
- For any other purpose disclosed at the time of collection or with your consent.
3. AI processing and model providers
Transtoartuses third-party large-language-model (LLM) and generative-media providers (each a “Model Provider”) to generate Output. The principal Model Provider for chat is xAI Corp. (the developer of the Grok family of models). Image, video, and other modalities may be routed to additional providers, which we list and update at our help center.
- When you submit Input, that Input (and limited session context) is transmitted to the relevant Model Provider so it can return an Output.
- We contractually require Model Providers to process Input only to provide the requested inference and abuse-detection, not for their own model-training, except where specifically permitted by you or by law.
- Model Providers may temporarily log Input and Output for the limited purposes of trust, safety, and legal compliance, in accordance with their own policies.
- You should not submit information you would not want a Model Provider to process. Do not include real account passwords, payment numbers, government IDs, or sensitive health/biometric data in prompts.
4. How we share information
We share personal information only as described below or with your consent.
- Service providers and subprocessors. Vendors that process information on our behalf under written agreements, including:
- xAI Corp. — chat inference and related model services.
- Google LLC (Firebase) — authentication, hosting, storage, and analytics.
- Paddle.com Market Ltd — merchant of record, subscription billing, payment processing, and sales tax.
- Generative-media providers — image and video generation (current list available on request).
- Customer-support and email providers — for transactional and support communications.
- Security, fraud, and analytics vendors — for abuse prevention and product analytics.
- Legal, safety, and compliance. We may disclose information to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Transtoart, our users, or the public. This includes mandatory reporting of suspected child sexual abuse material (CSAM)to the U.S. National Center for Missing & Exploited Children (NCMEC) and to competent authorities in other jurisdictions.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of company assets, or transition of service to another provider, information may be transferred as part of that transaction, subject to standard confidentiality protections.
- Affiliates. We may share information with our parent, subsidiaries, and affiliates for the purposes described in this Policy.
- With your direction. When you publish a character, share a generated image to a public gallery, or otherwise direct us to disclose information.
- Aggregated or de-identified data. We may share information that has been aggregated or de-identified such that it can no longer reasonably identify you.
5. Cookies and similar technologies
We use a small number of cookies and browser-storage mechanisms (including localStorage and IndexedDB) to:
- Keep you signed in and protect against session theft;
- Remember your language, theme, NSFW opt-in, and notification preferences;
- Store your conversation history locally on your device (see Section 6);
- Measure aggregate product performance and reliability; and
- Detect fraud, automation, and abuse.
Where required by law, we present a cookie banner or consent control. You may also disable non-essential cookies through your browser; some features will not function correctly without essential cookies.
6. Local storage of your chats
By design, Transtoart stores most of your conversation history, generated images and videos, and personalization preferences in encrypted browser storage (IndexedDB) on the device you use. This means:
- We generally do not retain a full server-side copy of your private chats or your Imagine gallery beyond what is needed to deliver an ongoing request or to operate optional sync/backup features.
- If you clear your browser data, switch devices, or sign in from a private window, your local history may be lost. We are unable to recover data that was only stored on your device.
- Encrypted chat backup and restore is available with eligible paid plans. If you enable it, an encrypted copy of your chats is stored with our subprocessors under keys that we cannot use to read your content for purposes other than restoration.
7. Data retention
We retain personal information only for as long as is necessary for the purposes set out in this Policy, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.
- Account data is retained for the life of your account.
- Server-side logs and security events are typically retained for up to 90 days, except where a longer period is required for security, audit, or legal reasons.
- Billing and tax recordsare retained for the period required by applicable tax and accounting law (typically 7–10 years).
- Trust and safety records (including data about CSAM, terrorism, and serious abuse) are retained for as long as required by law or as needed to cooperate with law enforcement.
When you delete your account, we will delete or de-identify your account data within a reasonable period, except where retention is required for the purposes described above.
8. Security
We implement commercially reasonable technical, administrative, and organizational measures designed to protect personal information, including encryption in transit, encryption at rest for sensitive stores, access controls, secure development practices, and routine review of our subprocessors.
No method of transmission or storage is 100% secure. You are responsible for keeping your account credentials confidential and for notifying us promptly of any unauthorized use of your account.
9. International transfers
Transtoart is headquartered in the United States. When you use the Services, your personal information may be processed in the United States and in other countries where our service providers operate. The laws of those countries may differ from those of your country of residence.
Where required, we rely on lawful transfer mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary measures.
10. Children’s privacy
The Services are not directed to children under the age of 13 (or the higher minimum age required in your jurisdiction). We do not knowingly collect personal information from children under 13.
Users aged 13–17 may use the general Services only with the consent and supervision of a parent or legal guardian. Adult/NSFW features and content are strictly limited to users who are at least 18 years old (or the age of majority in their jurisdiction, whichever is higher), and require an explicit opt-in.
If you believe a child has provided us with personal information, please contact us at privacy@transtoart.com and we will take appropriate steps to delete it.
11. Your privacy rights
Subject to applicable law and verification of your identity, you have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or outdated information;
- Delete your account and associated personal information;
- Port certain information to another service;
- Restrict or object to certain processing;
- Withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing);
- Lodge a complaint with a data-protection authority.
To exercise any of these rights, email privacy@transtoart.com. We will not discriminate against you for exercising your rights.
12. Regional disclosures
12.1 European Economic Area, United Kingdom, and Switzerland
For users in the EEA, UK, or Switzerland, Transtoartis the “data controller” of your personal information. Our legal bases for processing include: (a) performance of a contract (providing the Services you request); (b) our legitimate interests (operating, securing, and improving the Services, fraud prevention, business development) where not overridden by your rights; (c) compliance with legal obligations; and (d) your consent (for example, for optional marketing and certain cookies). You have the rights described in Section 11, and the right to lodge a complaint with your local supervisory authority.
12.2 California
Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, California residents have the right to know what personal information we collect, use, disclose, and (if applicable) sell or share; the right to delete; the right to correct; the right to opt-out of sale or sharing for cross-context behavioral advertising (we do not sell or share for that purpose); the right to limit use of sensitive personal information; and the right to non-discrimination. The categories of information we collect and disclose are described in Section 1 and Section 4.
12.3 Other U.S. states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws have similar rights. To exercise them, contact privacy@transtoart.com.
12.4 Other regions
If you reside in another region (including Brazil, Canada, Japan, Korea, Australia, or the broader Asia-Pacific), you may have additional rights under local law. We honor verified requests consistent with applicable law.
13. Third-party services and links
The Services may contain links to or integrate with third-party sites and services (including payment processors and identity providers). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will provide notice through the Services or by email and, unless a shorter period is required by law, the changes will take effect no earlier than 30 days after notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
15. Contact us
If you have questions about this Privacy Policy or how we handle your information, please contact:
- Privacy: privacy@transtoart.com
- Legal & compliance: legal@transtoart.com
EEA/UK residents may also contact our designated representative at eu-rep@transtoart.com.