Legal
Privacy Policy
Last updated: July 7, 2026
This Privacy Policy explains how Terrads (“Terrads”, “we”, “us”) collects, uses, and shares information when you use the terrads web application, APIs, and related services (the “Service”). It applies worldwide, with additional rights for users in the European Economic Area (EEA), the United Kingdom, and California described below.
Summary
- We collect account details, billing data, the prompts and reference material you upload, generated outputs, and operational usage data.
- We use it to run the Service, bill you, prevent abuse, improve reliability, and respond to support requests.
- We do not sell your personal information, and we do not use your prompts or generated content to train third-party AI models.
- You can delete your account, request a copy of your data, or ask us what we hold about you — see Your rights.
Who we are
Terradsoperates the terrads Service. For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), Terradsis the data controller of personal information collected through the Service.
Our registered address is available on request — [email protected]. You can reach us at [email protected].
Information we collect
Information you provide
- Account information — your email address, name, profile image, and authentication identifier (if you sign in via Google, the sub-claim and email returned by Google).
- Team information — workspace name, team members you invite, and their roles.
- Billing information — plan selection, billing address, VAT ID, and the last four digits and brand of your payment card. Full card numbers are handled exclusively by Stripe and never stored on our servers.
- Content you upload — prompts, instructions, reference images, brand assets (characters, products, palettes), masks, voice recordings you upload as reference, and any other material you submit to generate or edit ads.
- Support correspondence — messages you send to us and any attachments.
Information we generate about you
- Generated outputs — images, videos, and audio produced by the AI models you invoke, together with the prompts, models, and parameters used.
- Usage data — timestamps, features used, generation counts, credit balance, and in-app events, associated with your account.
- Billing events — successful and failed payments, invoice records, refund events.
- Diagnostic data — error reports captured by Sentry (stack traces, request identifiers, browser and OS strings, approximate IP-derived location). Sensitive form fields and user-content payloads are scrubbed before capture where feasible.
Information from third parties
- Google — if you sign in with Google, we receive your email, name, and profile picture.
- Stripe — we receive payment status, subscription state, and tax identifiers you submit at checkout.
How we use your information
We use the information described above to:
- Provide, maintain, and secure the Service, including authentication, team management, and the generation pipeline.
- Process payments, manage subscriptions and credit packs, issue invoices, and prevent fraud.
- Send transactional messages — sign-in links, invitations, receipts, and notifications about generation jobs, billing events, or material changes to the Service.
- Diagnose errors, monitor reliability, and improve product quality.
- Enforce our Terms of Service, detect misuse, and comply with legal obligations. This may include automated or human review of uploaded content and generated outputs where we have a reasonable belief of a policy violation, and reporting of illegal content to competent authorities as required by law.
- With your consent, send you product updates and marketing. You can opt out at any time using the unsubscribe link in each email.
Legal bases (EEA / UK)
If you are in the EEA or UK, we rely on the following legal bases under the GDPR:
- Contract — to create your account, run generations, process payments, and deliver the features you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, diagnose errors, and communicate with you about the Service.
- Consent — for marketing communications and, if we ever introduce them, non-essential cookies. You can withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, and anti-money-laundering laws.
Your content and AI generations
You retain all rights in the prompts, reference images, and brand assets you upload. We only process them to run the generations you request, to store your outputs in your workspace, and to provide features such as version history and team collaboration.
Generated outputs are stored in your workspace and shown only to you and the members of your team. We do not share them with other customers.
Service providers and subprocessors
We rely on trusted third parties to operate the Service. Each is contractually bound to process personal information only for the purposes described below.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers running the application, database, and job queue | Germany (EU) |
| Cloudflare R2 | Storage of reference images, masks, and generation outputs | Global |
| fal.ai | Running AI generation models | USA / global edge |
| Stripe | Payment processing, subscription management, tax calculation | USA / Ireland |
| Cloudflare, Inc. | Transactional email delivery | USA |
| Sign-in with Google (OAuth) | Global | |
| Sentry | Error monitoring and performance diagnostics | USA |
| Cloudflare | DNS, CDN, DDoS mitigation | Global |
We may update this list as our infrastructure evolves. Material changes will be reflected here with a revised “last updated” date.
International data transfers
The Service uses providers located in the United States and the European Union. If you access the Service from the EEA, the UK, or Switzerland, some of your information will be transferred to and processed in the United States by the providers listed above.
Where required, these transfers are protected by the European Commission’s Standard Contractual Clauses (SCCs) with our providers, and — for US providers — reliance on the EU-US and UK-US Data Privacy Frameworks where certified.
Data retention
- Account data — retained while your account is active, and for 14 days after you request deletion to allow recovery. After that window, your sign-in identity and personal details are removed or anonymised.
- Uploaded content and generations — retained in your workspace until you delete them there. When you delete your account, content in workspaces where you were the only member is permanently deleted (including stored media) once the 14-day recovery window passes; content in workspaces you shared with a team remains with that team.
- Billing records — retained for the period required by tax and accounting laws (typically 7 years).
- Logs and diagnostics — retained for up to 90 days, then aggregated or deleted.
- Support correspondence — retained for up to 3 years to manage follow-ups and recurring issues.
Your rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — delete your account from the Settings page or by emailing us. Your account stays recoverable for 14 days, after which your sign-in identity and personal details are removed or anonymised, and the content of workspaces where you were the only member — uploads, generations, and stored media — is permanently deleted. Content in a workspace you shared with a team remains with that team; to have specific content containing your personal data erased from a shared workspace, email us and we will process the request.
- Data copy — email us and we will provide a copy of your data in a structured, machine-readable format.
- Objection and restriction — object to or restrict certain processing.
- Withdraw consent — where we rely on consent, you can withdraw it at any time.
- Lodge a complaint — with a supervisory authority in the EEA or UK, or the relevant authority in your country.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
California residents
Under the California Consumer Privacy Act (CCPA/CPRA), you have the right to know the categories of personal information we collect and share, to request deletion or correction, and to opt out of the “sale” or “sharing” of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising.
Security
We take technical and organisational measures to protect your information, including TLS for data in transit, encrypted object storage, access controls, and least-privilege credentials. No system is perfectly secure; if we become aware of a breach that affects your personal information, we will notify you and regulators as required by law.
Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through an in-app notice before they take effect. The “last updated” date at the top of this page always reflects the current version.
Contact us
If you have questions about this policy or how we handle your information, please contact us:
- Email: [email protected]
- Data Protection contact: [email protected]
- Postal: Terrads, available on request — [email protected]
Effective date: July 7, 2026. Governed by the laws of Slovenia.