AIFLUX

AIFLUX

Privacy Policy

Last updated: 30 June 2026

Note for non-EU users: AIFLUX is operated by a company based in the European Union and processes all user data in accordance with the EU General Data Protection Regulation (GDPR). The protections described in this policy — including your rights of access, rectification, erasure, and data portability — apply to all users regardless of their geographic location.

1. Data Controller

The Data Controller for the processing of personal data is AIFLUX (trade name of ForgeAISolution).
VAT no.: IT14088920963
Registered address: Via Derna 28, 20132 Milano (MI), Italy
Contact email: [email protected]

2. Personal Data Collected

AIFLUX collects the following categories of personal data:

  • Registration data: username, email address, password (stored in encrypted form using bcrypt hashing).
  • Payment data: transactions are handled entirely by Stripe, Inc.. AIFLUX does not store credit card data. We only store the payment session identifier, the purchased plan, and the amount.
  • Generated content: text prompts entered by the user and the URLs of images/videos generated by the service.
  • Input files: images, videos, and audio files uploaded by the user as references for content generation. These files are stored on secure cloud infrastructure (Cloudflare R2) to enable the "Repeat" feature and are deleted when the associated generation is deleted or upon account deletion. The user has full control and can delete their data at any time.
  • Age-verification data: when you complete third-party age verification (Yoti), we receive and store only an "over-18: yes/no" result and an opaque, pseudonymous reference — never your name, date of birth, identity document or biometric data. The document scan is performed by Yoti under "double anonymity" (see Section 6b).
  • Content-safety data: for users who have not completed age verification, a classification result from the automated content-moderation system (whether an uploaded or generated item is allowed or blocked, and the triggered category) is stored against the relevant generation.
  • Technical data: IP address, browser user-agent, access timestamps — used exclusively for security purposes and abuse prevention.
  • Technical cookies: session cookies and CSRF tokens strictly necessary for the functioning of the service (see our Cookie Policy).

3. Purposes of Processing

Personal data is processed for the following purposes:

  • Service delivery: account creation and management, AI content generation, credit management.
  • Payments: processing credit purchases through Stripe.
  • Security: account protection, fraud prevention, rate limiting, detection of unauthorized access.
  • Service communications: account verification emails, password resets.
  • Marketing (consent-based only): sending promotional communications. You may withdraw your consent at any time.
  • Age verification and content safety: verifying that users accessing adult (18+) content are of legal age, and screening uploaded and generated media to prevent and detect illegal content, in particular child sexual abuse material.
  • Legal obligations: compliance with legal and tax obligations.

4. Legal Basis for Processing

The processing of personal data is based on the following legal grounds (Art. 6 GDPR):

  • Performance of a contract (Art. 6(1)(b)): for the provision of the service and account management.
  • Consent (Art. 6(1)(a)): for sending marketing communications and acceptance of this privacy policy.
  • Legitimate interest (Art. 6(1)(f)): for the security of the service and abuse prevention.
  • Legal obligation (Art. 6(1)(c)): to comply with legal obligations (e.g., tax regulations), with age verification for access to adult content (AGCOM Resolution 96/25/CONS), and with the detection, blocking and reporting of child sexual abuse material.

5. Data Retention Period

We keep each category of personal data only for as long as necessary for the purpose for which it was collected (Art. 5(1)(e) GDPR). When you delete your account, your data is erased without undue delay (Art. 17 GDPR), except for the limited data we are required or entitled to keep set out below.

  • Account data (username, email, hashed password): for the duration of the account and up to 30 days after deletion (technical wind-down).
  • Input files (uploaded reference images/videos/audio): deleted when the associated generation is deleted, or on account deletion — not retained for any other purpose or to train AI models.
  • Generated content (prompts + output media): until account deletion or upon user request.
  • Payment & accounting records (Stripe session id, plan, amount, invoices): 10 years (Art. 2220 of the Italian Civil Code + tax law — legal obligation; kept even after account deletion).
  • Security logs (IP address, user-agent, access timestamps, abuse/rate-limit events): up to 12 months (legitimate interest — security and abuse prevention).
  • Audit logs (account and safety-relevant actions): up to 24 months for security, accountability and abuse prevention, then deleted or anonymised.
  • Age-verification status (the "over-18" result + opaque reference): stored while valid (you may be asked to re-verify periodically) and cleared on account deletion.
  • Content withheld by moderation: media blocked because it may be unlawful is not published and is kept in restricted storage only as long as necessary for safety and to comply with legal obligations. Material that is, or may be, child sexual abuse material is preserved and, where required by law, reported to the competent authorities — this retention is a legal obligation and applies even after account deletion.

Where a longer retention is required by a legal obligation, or to establish, exercise or defend a legal claim (Art. 17(3) GDPR), the relevant data is kept only for that purpose and for the period strictly necessary (e.g. until the applicable limitation period expires), and is then deleted or anonymised.

6. Recipients and Extra-EU Transfers

Personal data may be disclosed to the following third parties:

  • Stripe, Inc. (USA) — payment processing. Stripe adheres to the EU-US Data Privacy Framework. Stripe Privacy Policy.
  • WaveSpeed AI (USA) — image and video generation through AI models, and automated content moderation (uploaded and generated media is screened to detect prohibited content). Prompts and media are sent to their servers for processing.
  • Google Gemini API (USA) — content processing through generative artificial intelligence models. Text prompts and associated data are transmitted to Google servers for processing. Google acts as a data processor. Google Privacy Policy.
  • RunPod, Inc. (USA) — audio (TTS) and animated video generation on serverless GPU infrastructure. Input audio/image files and prompts are sent to their servers for processing and deleted at job completion. RunPod Privacy Policy.
  • Atlas Cloud (USA) — video generation through dedicated AI models (e.g. Seedance 1.5 Spicy). Reference images and prompts are transmitted to their servers for the duration of processing. Atlas Cloud Privacy Policy.
  • Neon Tech, Inc. (USA) — database hosting. Data is stored on cloud infrastructure with at-rest encryption.
  • Cloudflare, Inc. (USA) — CDN, DDoS protection, object storage (R2). Adheres to the EU-US Data Privacy Framework.
  • PostHog, Inc. (USA) — product analytics (page views, usage events, anonymous session identifier). The script is loaded only after the user's explicit consent to the "Analytics" category via the cookie banner; no data is sent without consent. PostHog Privacy Policy.
  • Yoti Ltd (United Kingdom) — third-party age verification (document scan). Operates under "double anonymity": Yoti processes the identity document to derive an over-18 result and returns only that result to AIFLUX, without disclosing your identity. The UK benefits from a European Commission adequacy decision. Yoti Privacy Policy.
  • Hetzner Online GmbH (Germany) — application server hosting, with data centers in the EU.

Transfers to the USA are carried out on the basis of the EU-US Data Privacy Framework or, where not applicable, on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission.

6b. Age Verification and Automated Content Moderation

Age verification. Access to adult (18+) content requires age verification through our partner Yoti, in compliance with AGCOM Resolution 96/25/CONS. The check is performed under "double anonymity": AIFLUX receives only an over-18 result and never your identity, document or biometric data.

Automated content moderation. To protect minors and prevent illegal content, media uploaded or generated by users who have not (yet) completed age verification is automatically screened by an AI content-moderation system (WaveSpeed). Content classified as prohibited is blocked before generation (inputs) or withheld and not shown (outputs). This involves automated processing within the meaning of Art. 22 GDPR; the measure is necessary to comply with our legal obligations and to ensure the safety of the service. You may request human review and contest a decision by writing to [email protected], and you can lift the restriction at any time by completing age verification.

EU AI Act. The moderation system is used solely to detect and block unlawful content; its outputs are subject to human oversight and do not produce legal effects beyond restricting access to certain features of the service.

Child sexual abuse material (CSAM). AIFLUX operates a zero-tolerance policy. Any content detected or reported as CSAM is blocked, preserved in restricted storage and, where required by law, reported to the competent authorities.

7. Your Rights

In accordance with the GDPR (Articles 15-22), you have the right to:

  • Access — obtain confirmation of processing and a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request the deletion of your data.
  • Restriction — restrict processing in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Withdrawal of consent — withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.

To exercise your rights, write to [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it).

8. Minors

The service is intended only for adults: you must be at least 18 years of age (the age of majority) to create an account, consistent with our Terms of Service. Access to adult (18+) content additionally requires third-party age verification (see Section 6b). We do not knowingly collect data from anyone under 18. AIFLUX operates a zero-tolerance policy on child sexual abuse material: any such content is blocked, preserved and, where required by law, reported to the competent authorities. If you believe a minor has provided personal data, please contact us for removal.

9. Changes to This Policy

We reserve the right to update this privacy policy. In the event of substantial changes, we will notify you through the service or by email. The date of the last update is indicated at the top.

10. Contact

For any questions regarding the processing of your personal data:
AIFLUX (ForgeAISolution) — VAT IT14088920963
Via Derna 28, 20132 Milano (MI), Italy
Email: [email protected]