PRIVACY POLICY
Last Updated: January 15, 2026
1. Introduction
This Privacy Policy describes how DecorViz AI ("Company," "we," "us," or "our"), operating at https://decorviz.ai, collects, uses, shares, and protects information in connection with the DecorViz AI platform (the "Service").
Development Stage Notice: This company is currently in development. Final company registration details will be added before public launch.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and our Terms of Service. If you do not agree, you must not access or use the Service.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Room Photos" means photographic images of interior or exterior spaces uploaded by users.
- "Product Images" means photographic images of furniture, decor, or other items uploaded by users for visualization.
- "Previews" or "Generated Previews" means output images generated by our AI systems showing Product Images placed within Room Photos.
- "User Content" means Room Photos, Product Images, and any other content uploaded or provided by users.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
3. Information We Collect
3.1 Account Information
- Email address
- Password (encrypted and hashed)
- Account preferences and settings
- Account creation and login timestamps
3.2 User Content
- Room Photos you upload
- Product Images you upload
- Generated Previews created by our AI
- Upload metadata (file names, timestamps, sizes)
3.3 Payment Information
We use third-party payment processors. We do not store complete credit card numbers or full payment credentials. We may receive:
- Payment processor customer identifiers
- Transaction identifiers and timestamps
- Billing email addresses
- Purchase history and subscription status
- Partial payment method information (last four digits, card brand, expiration)
3.4 Technical Data
- IP addresses
- Browser type, version, and language
- Device identifiers and characteristics
- Operating system information
- Referring and exit pages
- Clickstream data and interaction patterns
- Session information and timestamps
- Error logs and performance data
3.5 Cookies and Tracking
We use cookies, web beacons, and similar technologies:
- Essential cookies: Required for functionality
- Analytics cookies: Usage patterns and performance
- Preference cookies: Settings and preferences
- Marketing cookies: Advertising (where consent obtained)
4. AI-Specific Data Handling
4.1 Processing Purpose
All uploads are processed solely to provide the Service to you through our AI systems and cloud infrastructure.
4.2 No Training on User Data
We do not use identifiable user uploads to train, fine-tune, or improve general-purpose or publicly available AI models.
4.3 Aggregated Data Use
We may use aggregated, fully anonymized, or de-identified data to:
- Monitor Service reliability and performance
- Attempt to improve system quality and accuracy
- Conduct internal research and development
- Generate statistical insights
We make reasonable efforts to ensure anonymization, but provide no guarantee that data cannot be re-identified through external means or future techniques.
4.4 Automatic Deletion
Uploads and Previews are stored temporarily and automatically deleted:
- After a defined retention period (typically 30-90 days from upload or last access)
- Upon account deletion
- Upon explicit user request (subject to technical feasibility)
5. Purposes of Processing
We process Personal Data to:
- Create and manage accounts
- Authenticate users
- Process uploads through AI systems
- Generate and deliver Previews
- Provide customer support
- Process payments and manage subscriptions
- Enforce our Terms and policies
- Detect and prevent fraud and abuse
- Comply with legal obligations
- Analyze usage and improve the Service
- Send transactional and marketing communications (where consented)
6. Legal Bases for Processing
- Contract Performance: Necessary to provide the Service
- Legitimate Interests: Service improvement, fraud prevention, security
- Consent: Where explicitly obtained (may be withdrawn anytime)
- Legal Obligation: Compliance with laws and regulations
7. Data Sharing
7.1 Service Providers
- Cloud infrastructure providers
- AI and image processing providers
- Payment processors
- Analytics providers
- Customer support tools
- Content delivery networks
7.2 Legal Requirements
We may disclose data to comply with laws, enforce our Terms, prevent fraud, or protect rights and safety.
7.3 Business Transfers
In mergers, acquisitions, or business transactions, data may be transferred to the acquiring entity.
7.4 With Your Consent
When you explicitly consent to sharing.
7.5 Aggregated Data
We may share anonymized data that cannot reasonably identify you.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your home jurisdiction. We implement appropriate safeguards including EU Standard Contractual Clauses and other legally recognized mechanisms.
9. Data Retention
- Account Information: Duration of account plus up to 2 years
- User Content: 30-90 days from upload/last access or upon deletion request
- Payment Data: Up to 7 years for compliance
- Technical Data: Aggregated indefinitely; identifiable up to 2 years
10. Data Security
We implement encryption, access controls, security monitoring, and employee training. However, no system is completely secure. You are responsible for maintaining credential confidentiality.
11. Your Rights
Depending on jurisdiction, you may have rights to:
- Access your Personal Data
- Correct inaccurate data
- Request deletion
- Object to or restrict processing
- Data portability
- Withdraw consent
- Lodge complaints with supervisory authorities
Contact us to exercise these rights. We will respond within 30 days and may require identity verification.
12. Children's Privacy
The Service is not intended for anyone under 18. We do not knowingly collect data from minors. If we discover such collection, we will delete it promptly.
13. California Privacy Rights
California residents have additional CCPA/CPRA rights including rights to know, delete, correct, and opt-out. We do not "sell" Personal Data as defined by CCPA. Contact us to exercise rights.
14. Other Jurisdictions
Users in the UK, Brazil, and other jurisdictions have rights under applicable local laws (UK GDPR, LGPD, etc.). Contact us to exercise rights.
15. Third-Party Links
We are not responsible for third-party privacy practices. Review their policies before providing information.
16. Changes to This Policy
We may update this Policy anytime. Material changes will be communicated via prominent notice on the Service or email at least 30 days in advance. Continued use after changes constitutes acceptance.
17. Contact Us
For questions or requests regarding this Privacy Policy:
Website: https://decorviz.ai
Contact Form: https://decorviz.ai/contact/