This Privacy Policy explains how AI Sinful (the “App”) accesses, collects, uses, processes, stores, and shares user data, as well as the privacy rights available to users. This Policy is intended to comply with Google Play requirements and applicable personal data protection laws and regulations in major jurisdictions, including the European Union, California in the United States, and Brazil.
We undertake to use user data only for the lawful purposes disclosed in this Policy and not to process it beyond the disclosed scope.
Before using the App, please carefully read this Privacy Policy and the Terms of Service. By accepting this Privacy Policy and the Terms of Service and using the App, you confirm that you have read, understood, and voluntarily accepted this Policy and consent to our collection, use, and processing of your personal data as described herein. If you do not agree, please do not use the App.
Important Notice: The App is intended exclusively for adults aged 18 or older. We do not provide services to minors and do not knowingly collect personal information from minors.
1. Data Controller and Data Protection Officer
1.1 Data Controller
AIVRA TECHNOLOGY Co., Ltd (“we,” “us,” or “our”) is the sole controller of personal data processing activities conducted through the App and independently assumes the corresponding legal responsibilities under applicable law.
1.2 Registered Business Address
No. 5, Cuu Long Street, Tan Son Hoa Ward, Ho Chi Minh City, Vietnam
1.3 Official Contact Email
1.4 Data Protection Officer
Our Data Protection Officer (“DPO”) is Chloe Bennett.
Users may contact the DPO through the official email address above regarding data compliance, privacy rights, data processing, or related matters. We will respond within the period required by applicable law.
2. Scope and Description of Services
2.1 Scope of Application
This Privacy Policy applies whenever users download, install, or use any feature or service of AI Sinful through Google Play, including free features, paid in-app purchases, AI image creation, and other activities performed within the App.
2.2 Description of the App
AI Sinful is an AI-powered visual creation tool. No photography, editing, or professional creative experience is required. Users can upload images from their devices and select a preferred style to generate dynamic and creative visual content using AI algorithms.
2.3 Payment Mechanism
If applicable, the App may offer paid in-app purchases. Users may choose to purchase exclusive creative features, premium style templates, high-definition export functionality, or other value-added services.
In-app purchase transaction data is used solely to verify orders, provide purchased benefits, and support after-sales services.
3. Types of User Data We Collect and Purposes of Collection
We follow the principles of data minimization, purpose limitation, compliance, and transparency. We collect only the data necessary to provide the App’s core features, maintain stable operation, improve the user experience, and complete in-app purchase services.
We do not collect unnecessary user data unrelated to our services.
3.1 Device and App Information
3.1.1 Permissions and Methods of Collection
The App requires the INTERNET permission to access the internet.
After the user grants the relevant authorization, the App may access and collect basic device information, including the device model, operating system version, unique device identifiers, App installation information, App operation logs, network connection status, and device hardware parameters.
Such data will not be accessed or collected without the required authorization. The INTERNET permission is used to support network connectivity, data transmission, and the proper operation of AI features.
3.1.2 Purposes of Processing
This information is used only to:
- Support the proper launch and operation of the App;
- Ensure feature and device compatibility;
- Diagnose crashes, lag, and other technical problems;
- Improve compatibility and operational stability;
- Prevent security risks arising from malicious devices or abnormal activity; and
- Protect users and the App.
This information will not be used for undisclosed commercial purposes.
3.2 Photo Library and External Storage Data
3.2.1 Permissions and Methods of Collection
The App may access and read images, videos, and other visual materials stored in the user’s device photo library or external storage only after the user grants the READ_EXTERNAL_STORAGE, READ_MEDIA_IMAGES, and/or READ_MEDIA_VIDEO permissions, as applicable.
The App reads only content that the user actively selects and uploads for AI creation. It does not independently access or scan other personal files.
These permissions are necessary for the App’s core services. Without the corresponding authorization, users may not be able to upload materials or use the relevant creative features.
3.2.2 Purposes of Processing
This data is used only to:
- Upload user-selected materials;
- Create AI-generated visual content;
- Preview generated works; and
- Save or export works locally.
Cloud-based temporary cached data will be automatically deleted after the creation process is completed. We do not retain users’ original creative materials in cloud storage on a long-term basis.
3.3 Service Interaction and Transaction Data (If present)
3.3.1 Methods of Collection
When users access App features or initiate in-app purchases, the App may automatically collect interaction and transaction data, including:
- Feature usage records;
- Style preferences;
- Creation history;
- In-app purchase order information;
- Payment confirmations; and
- Duration of service use.
No separate authorization is required where this collection is necessary to provide the requested services.
3.3.2 Purposes of Processing
This data is used only to:
- Record users’ creative preferences;
- Improve AI algorithms and creative styles;
- Provide purchased features and benefits;
- Verify transaction orders;
- Respond to after-sales inquiries and feedback; and
- Analyze service usage to improve the App.
This information is not used for marketing notifications or unrelated purposes.
3.4 Information Voluntarily Submitted by Users
3.4.1 Methods of Collection
When a user contacts us through our official email address, we collect the message content and contact information voluntarily submitted by the user.
We collect this information only after the user submits it and do not independently access or obtain such information.
3.4.2 Purposes of Processing
This data is used solely to:
- Respond to user inquiries;
- Process complaints;
- Handle privacy rights requests;
- Provide after-sales support; and
- Resolve reported issues.
It is not used for unrelated purposes.
4. Legal Bases for Data Processing
All personal data processing activities are conducted in accordance with applicable laws and regulations. Our primary legal bases are described below.
4.1 User Consent
A user’s acceptance of this Privacy Policy, authorization of device permissions, voluntary upload of materials, and initiation of in-app purchase transactions may constitute the legal basis for the relevant data processing activities.
4.2 Performance of a Contract
Certain processing is necessary to perform the service agreement between the user and us, provide the App’s core creative services, and deliver purchased benefits.
4.3 Legitimate Interests
Where permitted by applicable law and where users’ fundamental privacy rights are not adversely affected, we may process data where reasonably necessary to:
- Maintain the secure operation of the App;
- Improve our products and services;
- Prevent violations and fraudulent conduct; and
- Protect the App against malicious activity and attacks.
4.4 Compliance with Legal Obligations
We may process or retain data where necessary to comply with applicable legal obligations, including transaction record retention, regulatory compliance, auditing, and lawful government requests.
5. Data Sharing, Sale, and Opt-Out Mechanisms
This section describes users’ data rights and is intended to address applicable requirements under laws including the GDPR, LGPD, CCPA, CPRA, and VCDPA.
5.1 Data-Sharing Rules
We do not share users’ personal data without limitation. We share limited data with third parties only in the lawful circumstances described below.
Where required, third parties must enter into appropriate confidentiality and data protection agreements, comply with applicable privacy laws, and use shared data only for authorized purposes.
5.1.1 Hosting and Technology Service Providers
Third-party technology providers that support App operation, AI computing resources, and data storage receive only the minimum amount of data necessary to provide their services.
They may use such data only to support the operation of the App and may not use it for unrelated purposes.
5.1.2 Payment Service Providers
Authorized payment institutions that process in-app purchases and verify orders process only transaction-related data.
They may use this data solely to process or verify transactions and provide purchased benefits. They do not receive or retain users’ creative materials or private content unless such processing is separately disclosed and lawfully authorized.
5.1.3 Legal and Regulatory Requirements
We may disclose data in response to lawful requests from courts, judicial authorities, law enforcement agencies, or regulatory bodies, or where necessary to comply with applicable laws, legal proceedings, or regulatory requirements.
Such disclosures will be limited to what is reasonably necessary to comply with the relevant legal obligation or request.
Except in the circumstances described above, we do not disclose users’ personal data to commercial entities or third-party organizations for unrelated purposes.
5.2 Third-Party SDKs and AI Integration
The App may incorporate third-party software development kits (“SDKs”) and third-party AI services, collectively referred to as “Third-Party Code and Services,” to support functions such as App operation, AI computing, payment transactions, and service optimization.
We take reasonable steps to ensure that data processing conducted through Third-Party Code and Services complies with this Privacy Policy, applicable law, and relevant Google Play requirements.
5.2.1 Third-Party Compliance Controls
We select third-party providers based on their ability to comply with applicable Google Play policies and privacy requirements.
Where appropriate, third parties must enter into confidentiality and data protection agreements prohibiting them from selling, renting, or trading users’ personal data or sensitive data and requiring them to comply with data-use limitations, transparency, and consent requirements.
5.2.2 Data Processing Rules
Third-Party Code and Services may process user data only within the scope authorized by us and only as necessary to provide the App’s functions.
Processing must be limited to the minimum amount of data necessary to provide the relevant service. Third parties may not collect, use, store, or share user data beyond the authorized scope.
Whether user data is transmitted through code embedded in the App or sent to third-party servers, the processing must comply with this Privacy Policy and applicable requirements.
5.2.3 Requirements for AI Integrations
We take reasonable steps to ensure that third-party AI providers process user data only to provide the App’s AI visual creation features.
Third-party AI providers may not use user data for their own model training, commercial promotion, or unrelated purposes unless the user has been separately informed and a valid legal basis has been established.
Relevant AI-related processing is disclosed through this Privacy Policy.
5.2.4 Responsibility for Third-Party Processing
If we determine that a Third-Party Code or Service provider has violated applicable requirements or processed user data beyond its authorized scope, we may terminate the relationship, require corrective action, and take reasonable measures to protect users’ data and legal rights.
5.3 Data Sales and Opt-Out Rights
We do not sell, rent, or commercially trade users’ personal data.
We do not use users’ personal information, creative materials, device information, or usage records for commercial data sales.
Where applicable regional law defines certain data disclosures, transfers, or targeted advertising activities as a “sale” or “sharing,” users may have the right to opt out of those activities.
5.4 How to Opt Out of Data Sharing or Sales
Users may exercise applicable opt-out rights through the following methods.
5.4.1 Device Settings
Users may disable the App’s access to their photo library, storage, or device information through their device settings.
Disabling a permission will stop future collection through that permission but may prevent the relevant App features from functioning properly.
Uninstalling the App will stop future local data collection by the App but may not automatically delete data already retained on our servers where retention is permitted or required by law.
5.4.2 Email Request
Users may send a request to [email protected] with the subject or message “Terminate Data Sharing/Opt Out of Data Transfers.”
Users should provide sufficient information for us to identify and verify the request. We will process verified requests within 15 business days or within another period required by applicable law.
6. Privacy Rights for Users in Different Regions
The App is intended to comply with privacy laws in multiple jurisdictions. Rights may differ depending on the user’s location and the applicable law.
Subject to applicable exceptions, users may exercise their privacy rights free of charge.
6.1 Users in the European Union and European Economic Area
Subject to the General Data Protection Regulation (“GDPR”), eligible users may have the right to:
- Access their personal data;
- Correct inaccurate personal data;
- Request deletion of personal data;
- Restrict processing;
- Object to certain processing;
- Receive portable copies of eligible data;
- Withdraw consent; and
- Lodge a complaint with a competent supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing performed before the withdrawal.
6.2 Users in Brazil
Subject to Brazil’s General Data Protection Law (“LGPD”), eligible users may have the right to:
- Confirm whether their personal data is being processed;
- Access their personal data;
- Correct incomplete, inaccurate, or outdated data;
- Request anonymization, blocking, or deletion of unnecessary or unlawfully processed data;
- Receive information about third parties with whom data has been shared;
- Request data portability where applicable; and
- Withdraw consent or object to certain processing where permitted by law.
6.3 Users in California
Subject to the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), eligible California users may have the right to:
- Know what personal information is collected, used, disclosed, sold, or shared;
- Access specific pieces of personal information;
- Request deletion of personal information;
- Request correction of inaccurate personal information;
- Opt out of the sale or sharing of personal information;
- Limit certain uses or disclosures of sensitive personal information, where applicable; and
- Exercise their rights without unlawful discrimination.
6.4 Users in Virginia
Subject to the Virginia Consumer Data Protection Act (“VCDPA”), eligible Virginia users may have the right to:
- Access their personal data;
- Correct inaccurate personal data;
- Request deletion of personal data;
- Obtain a portable copy of eligible personal data;
- Opt out of targeted advertising;
- Opt out of the sale of personal data;
- Opt out of certain profiling activities; and
- Appeal a decision concerning a privacy request.
6.5 Users in Other Regions
Users in other countries and regions may have additional rights under applicable local personal data protection laws.
We will process eligible requests in accordance with the laws applicable to the relevant user and processing activity.
7. Data Storage, Retention, and Security
7.1 Data Storage and Retention Periods
7.1.1 Creative Materials
Materials uploaded by users and AI-generated works may be stored locally on users’ devices.
Where cloud processing is necessary for real-time AI creation, the relevant data may be temporarily cached on our servers or those of our service providers. Temporary cached data will be deleted or anonymized after it is no longer necessary for the relevant processing purpose, subject to technical, security, and legal requirements.
We do not retain users’ original creative materials in cloud storage on a long-term basis unless otherwise disclosed to and authorized by the user.
7.1.2 Operational and Transaction Data
App operation logs, interaction records, and in-app purchase order data are retained only for as long as reasonably necessary to provide the services, resolve disputes, prevent fraud, and satisfy applicable legal or compliance obligations.
After a verified deletion request, we will delete or anonymize eligible data within the period required by applicable law, unless continued retention is legally permitted or required.
7.1.3 Legally Required Retention
Certain transaction and log data may be retained for the minimum period required by law, regulation, auditing, tax, accounting, security, or compliance obligations.
Such data will be securely deleted or anonymized when the applicable retention period expires and continued retention is no longer necessary.
7.2 Data Security Measures
We use reasonable administrative, technical, and organizational safeguards designed to protect user data against unauthorized access, disclosure, alteration, loss, or destruction.
These safeguards may include encryption, secure transmission protocols, access controls, and data isolation measures.
Access to user data is limited to authorized personnel and service providers who require access for legitimate business purposes and are subject to appropriate confidentiality obligations.
No method of transmission or storage is completely secure. Users are also responsible for maintaining the security of their devices, credentials, and device permissions.
8. Right to Lodge Complaints
If users believe that our data processing activities violate this Privacy Policy or applicable privacy laws, they may contact us using the information provided below.
Where permitted by applicable law, users may also lodge a complaint with the competent data protection or regulatory authority in their jurisdiction.
We will cooperate with lawful investigations and take appropriate corrective measures where non-compliant data processing is identified.
9. In-App Purchase Data (If present)
9.1 Payment Information
During in-app purchase transactions, we do not directly collect sensitive payment credentials such as full bank card details or payment passwords.
Payments are processed by authorized payment service providers. We generally receive only the transaction information necessary to verify and manage the purchase, such as order numbers, payment status, and purchased-benefit activation status.
9.2 Purposes of Transaction Data Processing
Transaction data is used to:
- Verify purchased benefits;
- Provide order and customer support;
- Prevent fraud;
- Maintain legally compliant accounting records; and
- Comply with applicable legal obligations.
Transaction data is not used for unrelated marketing, commercial data sales, or unauthorized third-party sharing.
9.3 Access and Deletion Requests
Users may request access to or deletion of eligible in-app purchase transaction records.
Certain records may not be deleted immediately where retention is required for legal, tax, accounting, fraud-prevention, dispute-resolution, or regulatory purposes.
10. Updates to This Privacy Policy
10.1 Reasons for Updates
We may revise this Privacy Policy in response to:
- Changes to the App’s features;
- Changes to our business operations;
- Changes to applicable laws or regulations;
- Changes to Google Play requirements; or
- Changes to our data processing practices.
10.2 Notification of Updates
Where required, we will notify users of material changes through an in-app notice, pop-up message, or another appropriate method.
The updated Policy will take effect on the date stated in the updated version.
Where applicable law requires additional consent, we will request that consent before the relevant processing begins. If a user does not agree to the updated terms, the user may stop using and uninstall the App.
11. Limitations and User Responsibilities
11.1 User Disclosures and Device Security
To the extent permitted by applicable law, we are not responsible for privacy incidents caused solely by:
- A user voluntarily disclosing personal data to another party;
- A user independently authorizing an unrelated third party to access their data; or
- Unauthorized access resulting from the user’s failure to take reasonable measures to secure their device or account.
Nothing in this section excludes or limits liability that cannot lawfully be excluded or limited.
11.2 Legal and Regulatory Changes
We may modify our data processing practices where necessary to comply with changes in law, regulatory policy, binding government requirements, or circumstances beyond our reasonable control.
Such changes will be handled in accordance with applicable notification and consent requirements.
11.3 Use by Minors
The App is not intended for persons under 18 years of age.
If we learn that we have collected personal data from a minor, we will take reasonable steps to delete it, subject to applicable law. Parents or legal guardians who believe that a minor has provided personal data to us may contact us using the information below.
12. Contact Us
For questions concerning this Privacy Policy, data processing, privacy rights requests, complaints, or suggestions, please contact us using the following information:
- Company Name: AIVRA TECHNOLOGY Co., Ltd
- Data Protection Officer: Chloe Bennett
- Email: [email protected]
- Business Address: No. 5, Cuu Long Street, Tan Son Hoa Ward, Ho Chi Minh City, Vietnam
We will investigate and respond to verified requests within 15 business days or within another period required by applicable law.