This Privacy Policy explains how InMedia Developer AI ("we", "us") collects, uses, shares, and protects personal data when you use inmediapro.app and related services (the "Service"). If you are in the European Economic Area, the United Kingdom, or Switzerland, we are the data controller for personal data described here.
1. Data We Collect
1.1 Account data
Name, email address, password hash (or OAuth identifier for Google), profile image, and workspace membership.
1.2 Content data
Projects, prompts, files, source code, environment variable ciphertext, chat messages, and AI output you generate or upload.
1.3 Billing data
Subscription status, plan, credit balance and ledger entries, and Stripe customer ID. We never store your full card number; payment credentials are handled by Stripe.
1.4 Usage & device data
IP address, browser, operating system, referring URL, pages viewed, timestamps, error logs, and API request metadata. Used for security, abuse prevention, and product improvement.
1.5 Cookies
We use strictly necessary cookies for authentication, session, and CSRF protection. Analytics or advertising cookies, if introduced later, will be gated behind explicit consent where required.
2. How We Use Data
- Provide, secure, and operate the Service and your account;
- Execute AI requests, run sandboxes, and store your projects;
- Process payments, manage subscriptions, and administer credits;
- Send transactional messages (verification, password reset, billing receipts, security alerts, product notices);
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our Terms of Service;
- Improve reliability, performance, and features through aggregated analytics.
3. Legal Bases (GDPR)
- Contract — to provide the Service you have signed up for.
- Legitimate interests — security, fraud prevention, service improvement, and direct communications about your account.
- Legal obligation — tax, accounting, and lawful requests from authorities.
- Consent — where required (e.g. non-essential cookies, optional marketing).
4. AI Processing & Sub-processors
To generate AI Output we transmit your prompts and relevant context to third-party model providers (currently OpenAI, Google, and Replicate). Sandboxed code execution runs on E2B. Payments are processed by Stripe. Email delivery is provided by our transactional email provider. Authentication and database storage are provided by Supabase infrastructure. These providers act as processors on our behalf under contractual data-protection terms.
We do not use your Content to train third-party foundation models. Where a provider offers a zero-retention or no-training mode, we enable it by default.
5. Data Sharing
We do not sell personal data. We share personal data only:
- with the sub-processors described above, strictly to operate the Service;
- with other members of a workspace you belong to, for content you share into that workspace;
- with authorities when required by law or to protect rights, safety, or security;
- in connection with a merger, acquisition, or asset sale, subject to equivalent privacy protections.
6. International Transfers
Personal data may be processed in countries outside your own, including the United States. Where required, we rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism.
7. Retention
We retain account and Content data for as long as your account is active. When you delete your account, we delete or anonymize personal data within 30 days, except where longer retention is required for legal, tax, security, or dispute-resolution purposes. Backups are purged on a rolling schedule.
8. Your Rights
Subject to applicable law (including the GDPR, UK GDPR, and CCPA/CPRA), you have the right to access, rectify, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent at any time without affecting prior lawful processing. To exercise these rights, email privacy@inmediapro.app. You also have the right to lodge a complaint with your local data-protection authority.
9. Security
We use encryption in transit (TLS) and at rest, row-level security in our database, scoped access tokens, application-level encryption for stored secrets, HMAC-verified webhook signatures, and audit logging. Access to production systems is restricted and monitored. Despite these measures, no method of transmission or storage is completely secure.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this Policy from time to time. Material changes will be communicated by email or in-product notice. The "Last updated" date reflects the most recent revision.
12. Contact
For privacy inquiries, contact privacy@inmediapro.app.