Skip to content
On this page

Privacy Policy

How ClipVision, Ltd. (operating the Inoue AI platform) collects, uses, shares and protects your personal data, and the rights you have over it under the GDPR, ePrivacy, CCPA/CPRA and the Australian Privacy Principles.

Last updated · v1.0

This Privacy Policy explains how ClipVision, Ltd. (“ClipVision”, “we”, “us”, “our”), the company that operates the Inoue AI platform, processes personal data when you visit our websites, create an account, and use our AI generation, virtual-influencer, content-scheduling, social-publishing, creator-CRM and billing services (together, the “Services”). It also describes the rights you have over your personal data and how to exercise them.

This policy should be read together with our Cookie Policy, our Terms of Service and, for business customers, our Data Processing Addendum. Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Who we are

ClipVision, Ltd. is the data controller responsible for your personal data processed through the Services. ClipVision is a Delaware (United States) C-corporation whose principal place of business and centre of activities is in Italy. Because our central administration is established in the European Union, our lead supervisory authority under the GDPR is the Italian Garante per la protezione dei dati personali (the “Garante”). As an EU-established controller, we are not required to appoint a representative under Article 27 of the GDPR.

Data controller

Controller
ClipVision, Ltd. (operating the Inoue AI platform)
Legal form
Delaware C-corporation, established in the European Union
Principal place of business
Via Giacomo Matteotti 5521020 Barasso (Varese)Italy
Privacy & data-protection requests
[email protected]
Legal notices
[email protected]
General & billing support
[email protected]
Lead supervisory authority
Garante per la protezione dei dati personali (Italy)

We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37 of the GDPR. You may direct all privacy enquiries to [email protected].

2. Scope of this policy

This policy applies to personal data we process about: visitors to our public websites; individuals who register for and use an Inoue AI account (“users”); members of organisations and workspaces that subscribe to the Services; and individuals who contact us for support or other enquiries. It covers both consumer (self-serve) and business use of the Services.

Where an Inoue AI customer uses the Services to process the personal data of third parties — for example, when a creator connects a Fanvue account and exchanges direct messages with their fans through our CRM features — the customer is the controller of that third-party data and we act as their processor. Our processing of that data is governed by our agreement with the customer (including our Data Processing Addendum), and this policy describes it only at a high level (see section 10).

Our Services are not designed for, and we do not knowingly process, the personal data of children (see section 11). The Services may link to third-party websites and platforms (for example the social networks you connect); their processing is governed by their own privacy policies, not this one.

3. Personal data we collect

We collect personal data in three ways: data you provide to us directly, data we collect automatically when you use the Services, and data we receive from third parties (chiefly the platforms you choose to connect and our payment processor). The tables below group the categories of personal data by source.

3.1 Data you provide to us

Personal data you provide directly
CategoryWhat it includes
Account & identityEmail address, display name, and the password you choose (which we store only as a salted Argon2id hash — never in plain text).
Authentication & securityIf you enable two-factor authentication: an encrypted TOTP secret and hashed single-use recovery codes. Email-verification and password-reset tokens (stored as selectors plus a hash, time-limited and single-use).
Profile & preferencesOptional profile details and product preferences (such as your default generation model), and your organisation/workspace memberships and roles.
Prompts, inputs & uploadsThe text prompts, negative prompts, prompt templates, reference images, audio, and other inputs you submit to generate content.
Face, likeness & identity mediaImages and other media you upload to create or train virtual-influencer “models” — including face, body and identity images and associated metadata (file hash, MIME type, dimensions). These may constitute special-category (biometric) data; see section 10.
Generated contentThe images, video, captions, transcripts, voice audio and other assets the Services generate for you, together with their job metadata and status history.
Bring-your-own provider keysIf you supply your own third-party provider credentials (for example an ElevenLabs API key), we store them encrypted at rest and use them only to perform the actions you request.
Support & correspondenceThe content of messages you send us (for example to [email protected]), and any information you choose to include.

3.2 Data we collect automatically

Personal data collected automatically as you use the Services
CategoryWhat it includes
Device & connectionYour IP address, user-agent string and a device name are recorded against your active sessions. For web-push notifications you opt into, we store the browser push endpoint, its keys and the subscribing user-agent.
Usage & activityRecords of your activity in the Services — audit logs (actor, action, affected resource and contextual metadata), generation/usage ledgers, credit balances and consumption, job status history and revenue events.
Cookies & similar technologiesStrictly-necessary first-party cookies for authentication, session refresh and CSRF/PKCE protection of the social-connection flows. We do not run analytics, advertising or third-party tracking cookies. Full detail is in our Cookie Policy.
Diagnostics & telemetryError and performance telemetry (exception reports, trace and span data) generated when something goes wrong, used to keep the Services secure and reliable.

3.3 Data we receive from third parties

Personal data received from third parties
CategoryWhat it includes
Connected social accountsWhen you connect a social or creator platform (TikTok, Threads and Fanvue are live; Instagram and YouTube clients exist but are not yet enabled), we receive and store, in encrypted form, OAuth access and refresh tokens, and the connected account’s handle, display name and avatar.
Published content & analyticsContent you publish through the Services and the analytics those platforms return on your own connected accounts (for example follower, view, like, comment and share counts).
Creator-CRM messagesFor connected Fanvue accounts, the direct-message conversations and message bodies you exchange with your fans, plus participant data. This includes your fans’ personal data, for which you are the controller and we are your processor (see sections 2 and 10).
Billing identifiersFrom our payment processor (Stripe): billing email, and customer, subscription, invoice, payment-intent, price and product identifiers, together with order amounts and currency. Card details are entered directly into Stripe and never reach our servers.

4. How we use personal data

We use personal data only for the purposes set out below. Each purpose is matched to a lawful basis in section 5.

  • Provide and operate the Services — create and authenticate your account, run AI image, video, voice, transcription and caption generation, manage virtual-influencer models, schedule and publish content, and deliver the results to you.
  • Process payments and manage credits — handle subscriptions, one-off credit bundles, usage metering, refunds and credit reversals, and meet our tax and accounting obligations.
  • Connect and operate third-party integrations — connect the social and creator platforms you authorise, publish on your behalf, retrieve analytics on your own accounts, and power creator-CRM messaging.
  • Communicate with you — send transactional and service emails (email verification, password resets, security and billing notices) and respond to your support requests. These are not marketing emails.
  • Keep the Services secure and reliable — authenticate sessions, rate-limit and detect abuse and fraud, maintain audit logs, monitor errors and performance, and protect the integrity of the platform.
  • Comply with the law and enforce our terms — meet legal, regulatory and tax obligations, respond to lawful requests, and enforce our Terms of Service and Acceptable Use Policy.

5. Legal bases for processing (GDPR Article 6)

Where the GDPR applies, we rely on the following lawful bases for each processing purpose. Where we rely on our legitimate interests, we have balanced those interests against your rights and freedoms and will provide details of that assessment on request.

Processing purposes and their lawful bases
Processing purposeLawful basis
Account creation, authentication, session management and two-factor authenticationPerformance of a contract — Art 6(1)(b)
AI generation, voice, transcription and caption rendering; storing your outputsPerformance of a contract — Art 6(1)(b)
Billing, subscriptions, credits and refundsPerformance of a contract — Art 6(1)(b); and compliance with a legal obligation (tax/accounting) — Art 6(1)(c)
Connecting social/creator accounts, publishing, analytics and CRM messagingPerformance of a contract — Art 6(1)(b)
Strictly-necessary cookies (authentication, session refresh, CSRF/PKCE)ePrivacy “strictly necessary” exemption, supported by Art 6(1)(b)
Security, fraud and abuse prevention, rate-limiting, audit logging, error monitoringLegitimate interests — Art 6(1)(f) (keeping the Services secure and operational)
Processing of face/likeness/identity images for virtual-influencer modelsExplicit consent for special-category data — Art 9(2)(a), in addition to Art 6(1)(b) (see section 10)
Any future analytics or marketing technologiesConsent — Art 6(1)(a) (none are used today; any future use would be gated behind a consent banner)

Today, no processing relies on consent under Article 6(1)(a), because we operate no marketing, advertising or analytics technologies. Should we introduce any in future, we will ask for your consent first and update this policy.

6. How we disclose data — recipients and sub-processors

We do not sell your personal data. We disclose it only to the categories of recipients below, each acting as our processor under contract, or where disclosure is required by law. We engage the following principal sub-processors to deliver specific parts of the Services.

Principal sub-processors
RecipientPurposeData sharedProcessing region
StripePayments, subscriptions, credit bundles, refunds and billing portalBilling identifiers and email, order amounts (no card numbers)United States and EU (SCCs)
Kie.aiAI image and video generation (our sole generation provider)Prompts, reference/identity images, generated outputsUnited States (SCCs)
ElevenLabsVoice generation, text-to-speech and voice cloningVoice audio, TTS text, voice samples; your provider key if suppliedUnited States (SCCs)
Deepgram / AssemblyAISpeech-to-text transcriptionAudio/video submitted for transcription and the resulting transcriptsUnited States (SCCs)
Remotion (render)Burned-in caption renderingTranscript and media for caption renderingUnited States / AWS region (SCCs)
MotionMuseMotionMuse generation flowGeneration input and output media for that flowPer provider terms (SCCs where outside the EEA)
DigitalOcean SpacesPrimary object storage and CDN origin for your mediaAll user-generated and uploaded media at restEuropean Union — London (“lon1”)
CloudflareAsync-flow dispatch and edge/CDN deliverySigned dispatch payloads, media references, public asset URLsGlobal edge network
ResendTransactional email deliveryRecipient email address and email contentUnited States (SCCs)
SentryError monitoring and performance tracingError/trace telemetry, which may include identifiers and IPUnited States / EU (SCCs where applicable)
TikTok, Threads, Fanvue (live); Instagram, YouTube (planned)Social-account connection, publishing, analytics and CRMOAuth tokens, published content, analytics, CRM messagesUnited States / global (SCCs)

We also rely on infrastructure providers that host our database, cache, message queue and supporting services on our behalf; these are operated as sub-processors and do not act as independent controllers. Business customers can obtain our current, maintained sub-processor list and notice of changes under our Data Processing Addendum. We may also disclose personal data to professional advisers, to authorities where legally required, and to an acquirer in the context of a merger, acquisition or asset sale, subject to this policy.

7. International data transfers

Some of the sub-processors that power generation, voice, transcription, email delivery and error monitoring are located in the United States or process data globally. Where we transfer personal data outside the European Economic Area to a country without an adequacy decision, we put in place an appropriate safeguard — in practice, the European Commission’s Standard Contractual Clauses (SCCs), supplemented by technical and organisational measures — so that your data continues to receive an essentially equivalent level of protection. You may request a copy of the relevant safeguards by emailing [email protected].

8. How long we keep your data

We keep personal data only for as long as necessary for the purposes set out in this policy, or for as long as the law requires. The default periods below apply unless a longer period is required (for example by tax law) or a shorter period is appropriate. When you delete content or close your account, we mark the relevant records as deleted and then reclaim the underlying media on the schedule below.

Default retention periods by data category
Data categoryDefault retention
Account dataKept while your account is active; deleted or anonymised after account closure, subject to the periods below and any legal hold.
Generated and uploaded media (active account)Retained while your account is active. After you delete an asset or close your account, the database record is tombstoned and the stored media is reclaimed within 30 days.
Session records (IP address, user-agent, device)Up to 90 days of inactivity, after which the session is revoked and purged; you can revoke sessions at any time in your account settings.
Audit logs365 days, then deleted, to support security, abuse-prevention and accountability.
Webhook event records (payment and provider callbacks)90 days, then deleted.
Billing and tax recordsRetained for the period required by applicable tax and accounting law (typically several years), independent of account closure.
Unused purchased creditsExpire 12 months after they are granted.
Email-verification and password-reset tokensSingle-use and short-lived (verification 24 hours, reset 1 hour), then consumed or expired.
BackupsOperational backups are kept on a rolling basis (currently 35 days) before they expire, so that deletions propagate out of backups within the backup cycle.

9. Your rights and choices

Subject to the conditions and exceptions in applicable law, you have the following rights over your personal data:

  • Access — obtain confirmation of whether we process your data and a copy of it.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where there is no overriding reason to keep it.
  • Portability — receive the data you provided to us in a structured, commonly-used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Restriction — ask us to limit processing in certain circumstances.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where we rely on consent (for example for biometric/likeness data), withdraw it at any time, without affecting processing already carried out.

You can exercise many of these rights directly in your account settings (for example updating your profile, revoking sessions, or deleting your account), or by emailing [email protected]. We will respond within the timeframes required by law (under the GDPR, normally within one month). We do not charge a fee for a reasonable request, and we will not discriminate against you for exercising your rights.

10. Biometric, likeness and creator-CRM data

Inoue AI lets you create and train virtual-influencer “models” from images you upload, which may include faces, bodies and other identity media. Depending on how it is processed, this media may constitute special-category (biometric) personal data under Article 9 of the GDPR.

  • Legal basis — we process face/likeness/identity media on the basis of your explicit consent under Article 9(2)(a) of the GDPR, given when you upload such media to build or train a model, in addition to the contractual basis in Article 6(1)(b).
  • Your representations — you must hold all necessary rights and consents in any face or likeness you upload, including the consent of any identifiable person depicted. You must not upload another person’s likeness without their authorisation. See our Acceptable Use Policy.
  • Retention and deletion — identity media is retained while your model and account are active and is deleted on the schedule in section 8 when you remove it or close your account. You may withdraw your consent at any time, after which we will stop the relevant processing and delete the associated media.

10.1 Creator-CRM messages (your fans’ data)

When you connect a creator platform such as Fanvue and use our CRM features, we process the direct messages and participant data you exchange with your fans. With respect to that third-party data, you are the controller and we act as your processor: you are responsible for providing any notice to, and obtaining any consent from, your fans, and for the lawfulness of that messaging. Our handling of that data is governed by our agreement with you, including our Data Processing Addendum.

11. Children

The Services are intended for adults and are not directed to children. We do not knowingly collect personal data from anyone under 16 in the EEA (or under the applicable digital-consent age in your country, which is not below 13), nor from anyone under 13 in the United States. If you believe a child has provided us with personal data, please contact [email protected] and we will take steps to delete it.

12. How we protect your data

We maintain technical and organisational measures appropriate to the risk, including: hashing of passwords with Argon2id; encryption at rest of sensitive secrets such as two-factor secrets and connected-account tokens; encryption in transit (TLS); strict access controls and least-privilege access; row-level access controls in our database; rate-limiting and abuse detection; audit logging; and error and security monitoring. No method of transmission or storage is completely secure, but we work to protect your data and to detect, contain and notify you of any personal-data breach as required by law.

13. Cookies and similar technologies

We use only strictly-necessary, first-party cookies — for authentication, session refresh and CSRF/PKCE protection of the social-connection flows. We do not use advertising, analytics or third-party tracking technologies. For the full list of cookies, their purposes and lifespans, and how to manage your choices, see our Cookie Policy.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our Services, our processors, or the law. When we make material changes, we will update the effective date and version shown at the top of this policy and, where appropriate, notify you by email or in-product. We encourage you to review this policy periodically.

15. Contact us

If you have any questions about this policy or how we handle your personal data, or if you wish to exercise your rights, please contact us:

Privacy & data-protection requests
[email protected]
Legal notices
[email protected]
General & billing support
[email protected]
Controller
ClipVision, Ltd.Via Giacomo Matteotti 5521020 Barasso (Varese), Italy

16. Regional supplements

16.1 European Economic Area and United Kingdom

If you are in the EEA or the UK, the GDPR (and the UK GDPR) governs our processing. Our lead supervisory authority is the Italian Garante; you may also contact your local authority. The lawful bases, rights, retention periods and transfer safeguards described above apply to you.

16.2 United States — California (CCPA/CPRA) and other state laws

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct it, and to opt out of any “sale” or “sharing” of personal information and of certain profiling.

We honour the Global Privacy Control (GPC) browser signal as a valid opt-out request. You may exercise your California rights, including “Your Privacy Choices”, by emailing [email protected]; we will verify your request and will not discriminate against you for exercising your rights. You may use an authorised agent to submit a request on your behalf. Residents of other U.S. states with comprehensive privacy laws have comparable rights, which we extend to them where those laws apply.

16.3 Australia (Privacy Act and Australian Privacy Principles)

If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles. You may request access to, or correction of, your personal information by emailing [email protected]. If you are not satisfied with how we have handled a privacy matter, you may complain to us first and then, if unresolved, to the Office of the Australian Information Commissioner (OAIC).