Privacy Policy
Effective Date: July 23, 2026
Last Updated: July 25, 2026
Index
- Introduction
- Scope
- Information We Collect
- How We Use Information
- Legal Bases for Processing
- AI Processing
- Biometric Data
- Model Training
- Cookies and Similar Technologies
- Sharing and Service Providers
- Data Retention
- Data Security
- International Data Transfers
- Children's Privacy
- Your Rights
- Account and Content Deletion
- Communications
- Grievance Redressal
- Changes to This Policy
- Contact
1. Introduction
This Privacy Policy explains how Inferon Techlabs Private Limited ("Company", "Inferon", "we", "our", or "us") collects, uses, stores, shares, and protects personal information when you use our websites, applications, APIs, products, and services (collectively, the "Services").
We are incorporated in India and act as the Data Fiduciary for the personal data described in this policy under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Where the EU or UK General Data Protection Regulation applies, we act as the controller. Terms such as "Data Principal", "data subject", and "consumer" refer to you.
We believe privacy should be understandable. This policy explains our practices in clear language while helping you understand your rights and choices.
2. Scope
This Privacy Policy applies to:
- Our marketing website and blog
- Our web application
- Our APIs and developer tools
- Account registration and authentication
- Paid subscriptions, credit purchases, and free trials
- Customer support
Additional product-specific privacy disclosures may supplement this policy. Where there is a conflict, the product-specific disclosure takes precedence for that product.
This policy does not apply to personal data we process on behalf of a business customer under an enterprise agreement. In that case, the business customer determines the purposes of processing and you should direct requests to them. Our obligations in that role are set out in our Data Processing Addendum.
3. Information We Collect
Information You Provide
- Name and email address
- Username and account credentials, handled by our authentication provider
- Company or organization details
- Billing and tax information
- Support requests and correspondence
- Feedback and survey responses
Content You Submit
- Prompts and text instructions
- Images, video, and audio files you upload
- Reference material for avatars, voices, and custom models
- Generated Outputs and their associated metadata
- Project, workspace, and asset organization data
Uploaded files may contain embedded metadata, such as capture time, device information, and location, which is transmitted with the file.
Information Collected Automatically
- IP address and approximate location derived from it
- Browser type, device information, and operating system
- Language and time zone
- Pages visited, features used, and navigation paths
- Session information and authentication events
- Referring URLs
- Crash reports, error traces, and performance metrics
Usage and Billing Records
- Generation history, including the model used and credits consumed
- Subscription status and credit balance
- Rate limit and quota consumption
- API key usage
Payment Information
Payments are processed by our third-party payment provider. We do not store complete card numbers on our servers. We receive transaction records, the last four digits of the payment instrument, and billing metadata necessary for invoicing, tax, and accounting.
4. How We Use Information
We use information to:
- Provide, operate, and maintain the Services
- Authenticate users and secure accounts
- Process generations and deliver Outputs
- Process payments, manage credits, and issue invoices
- Enforce rate limits and usage quotas
- Provide customer support
- Detect, investigate, and prevent fraud, abuse, and policy violations
- Operate safety and content moderation systems
- Monitor reliability, diagnose errors, and improve performance
- Understand feature usage in order to improve and develop the Services
- Send service, security, and billing communications
- Comply with legal obligations and respond to lawful requests
- Establish, exercise, or defend legal claims
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
5. Legal Bases for Processing
Where the GDPR or a similar law applies, we rely on the following bases:
| Purpose | Legal basis | | --- | --- | | Providing the Services you request | Performance of a contract | | Billing, tax, and accounting | Contract and legal obligation | | Security, fraud prevention, and abuse detection | Legitimate interests | | Product analytics and improvement | Legitimate interests, or consent where required | | Non-essential cookies and marketing | Consent | | Processing biometric data | Explicit consent | | Responding to legal requests | Legal obligation |
Under the DPDP Act, we process personal data on the basis of your consent, or where a legitimate use permitted by the Act applies. You may withdraw consent at any time as described in Section 15, and withdrawal does not affect processing already carried out.
6. AI Processing
The Services are built on artificial intelligence models. When you use a generation feature, we process your prompt and any uploaded files in order to:
- Generate the images, video, audio, avatars, or text you request
- Route your request to the appropriate model and provider
- Apply safety filters and content moderation
- Record the credits consumed
- Diagnose failures and maintain service quality
Some requests are processed by third-party model providers. Your prompt and input files are transmitted to the selected provider for the duration necessary to produce the Output. The provider for each model is identified in our Model Usage Policy and our Subprocessors list.
7. Biometric Data
Avatar, voice cloning, and lip-sync features process facial geometry and voice characteristics, which are treated as biometric data under several laws and as sensitive or special category data under others.
Because of the additional protections that apply, this processing is described separately in our Biometric Data Policy, which explains what we derive, why, how long we keep it, and the consent we obtain before we begin.
8. Model Training
We do not use your content or your Outputs to train our own general-purpose or foundation models.
We process your content to train a model only where you expressly request a custom or fine-tuned model. That model is provisioned for your use and is not used to serve other customers.
We process content through automated moderation systems, and we may retain material associated with a suspected policy violation in order to investigate and enforce our terms.
Third-party model providers process your submissions under their own terms. We select providers that offer non-training or zero-retention handling for API traffic where such terms are available.
9. Cookies and Similar Technologies
We use cookies, local storage, session storage, and security tokens to keep you signed in, remember preferences, secure the Services, measure performance, and understand usage.
Where required by law, we request consent before setting non-essential cookies, and you can change or withdraw your preferences at any time through our consent manager.
Full detail is in our Cookie Policy.
10. Sharing and Service Providers
We share personal information in the following circumstances.
Service Providers
We work with providers that help operate the Services, covering authentication, payments, cloud hosting and storage, AI model inference, email delivery, analytics, error monitoring, and consent management. They receive only the information reasonably necessary to perform their function and are bound by contractual confidentiality and data protection obligations.
Our current providers are listed, by category and location, in Subprocessors.
Other Users of Your Workspace
If you belong to a shared workspace or organization, other members and administrators of that workspace may see your name, email address, and the assets and generation activity you contribute to it.
Legal and Safety
We may disclose information where we believe in good faith that it is necessary to comply with applicable law or a lawful request, to enforce our terms, to protect the rights, property, or safety of our users or the public, or to investigate suspected fraud or abuse.
Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honour this policy or provide notice of any material change.
With Your Direction
We share information with third parties where you instruct us to, such as when you connect an external account or publish content to another platform.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy.
| Category | Retention | | --- | --- | | Account records | For the life of the account | | Uploaded content and Outputs | Until you delete them, or the account is closed | | Content deleted by you | Removed from active systems promptly; residual copies purged from backups within 90 days | | Closed accounts | Content made inaccessible immediately; purged within 90 days | | Biometric templates | As set out in the Biometric Data Policy | | Generation and credit history | Retained for billing, tax, and audit purposes | | Invoices and financial records | As required by Indian tax and company law | | Security and audit logs | Retained for a limited period for security investigation | | Records of policy violations | Retained as necessary to enforce our terms and prevent repeat abuse |
Where information is no longer required, we delete or anonymize it. Where immediate deletion is not technically possible, such as in backup archives, we isolate the information from further processing until deletion occurs.
12. Data Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, encryption at rest where appropriate, access controls, audit logging, authentication safeguards, security monitoring, and regular software updates.
Our practices are described in more detail in our Security Policy.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We maintain procedures for handling personal data breaches and will notify you and the relevant authority where required by applicable law.
13. International Data Transfers
We are based in India and serve customers globally. Your information may be processed in countries other than your own, including by model providers and cloud infrastructure operating in the United States, the European Union, and elsewhere.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, which may include Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or a finding of adequacy.
You may contact us for information about the specific mechanism used for a given transfer.
14. Children's Privacy
The Services are not directed to children and are not available to anyone under 18 years of age.
We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will delete it and terminate the associated account.
Uploading images, video, or audio of a minor is prohibited under our Acceptable Use Policy, regardless of who holds parental rights.
15. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your information
- Restrict or object to certain processing
- Port a machine-readable copy of information you provided
- Withdraw consent where processing is based on consent
- Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act
- Not be discriminated against for exercising your rights
To exercise a right, contact privacy@inferon.ai from the email address associated with your account. Most access, correction, and deletion actions can also be performed directly in your account settings.
We may ask you for information needed to verify your identity. We respond within the period required by applicable law, and in any event within 30 days, and will tell you if we need longer for a complex request.
If we decline a request, we will explain why, subject to any legal restriction on doing so.
If You Are in Europe
You have the right to lodge a complaint with your local supervisory authority. A list of EEA authorities is available from the European Data Protection Board, and UK residents may contact the Information Commissioner's Office. We ask that you contact us first so we can try to resolve the matter.
If You Are in India
You may raise a grievance with our Grievance Officer as described in Section 18, and you may subsequently complain to the Data Protection Board of India.
Do Not Track
We do not currently respond to browser "Do Not Track" signals. You can manage tracking through our consent manager and your browser settings.
16. Account and Content Deletion
You may delete individual assets and projects at any time from within the Services.
You may request deletion of your account at any time. Deleting your account removes access to uploaded content, generated content, project history, avatars and voices you have created, remaining credits, and account settings. Unused credits are forfeited and are not refunded.
Content you delete is removed from active systems promptly and purged from backups within 90 days.
Certain information may be retained beyond deletion where necessary for legal compliance, tax and financial records, fraud prevention, security investigations, or the enforcement of our terms.
17. Communications
We may send you:
- Security notifications
- Billing notices and receipts
- Service announcements and incident notices
- Product updates
- Support correspondence
Service, security, and billing messages are part of the Services and cannot be opted out of while your account is active.
Marketing communications are sent only where permitted by law and, where required, with your consent. You may unsubscribe at any time using the link in the message or by contacting us.
18. Grievance Redressal
As required by the DPDP Act and India's information technology rules, you may contact our Grievance Officer with any complaint about our handling of your personal data.
Grievance Officer
Inferon Techlabs Private Limited
E8, Netaji Hills, Kolar Road, Bhopal, Madhya Pradesh 462042, India
Email: privacy@inferon.ai
Phone: +91 70006 28459
We acknowledge grievances promptly and aim to resolve them within 30 days.
19. Changes to This Policy
We may update this Privacy Policy periodically.
When we make material changes, we will update the "Last Updated" date and provide notice by email or within the Services where required by law. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
20. Contact
For privacy questions or requests:
Company: Inferon Techlabs Private Limited
Address: E8, Netaji Hills, Kolar Road, Bhopal, Madhya Pradesh 462042, India
Privacy and data protection: privacy@inferon.ai
Legal: legal@inferon.ai
Support: support@inferon.ai
Website: https://inferon.ai