BlitzArt
Log in
Legal · Privacy Policy

Your privacy,
explained clearly.

What data we collect, why we need it, who we share it with, and how you can exercise your rights over it.

Last updated: June 5, 2026Version 1.0privacy@blitzart.app
01

Introduction

How and why we process your information.

BlitzArt.app ("BlitzArt", "we", "the platform") is committed to protecting the privacy of its users. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use our AI image and text generation service.

By using BlitzArt.app you accept the practices described in this Policy and in our Terms of Service. If you don't agree, please don't use the service.

Data controller: BlitzArt.app · privacy@blitzart.app
02

Information we collect

Categories of personal data we process.

2.1 Account and profile

  • Full name or username
  • Email address
  • Password (hashed and salted with bcrypt/Argon2)
  • Country of residence (detected from IP or self-declared)
  • Preferred language, signup date, last login

2.2 Identity and age verification data

For users requesting access to Advanced Models (uncensored AI models):

  • Through the provider (Onfido / Persona): ID document image, live selfie, extracted data (name, date of birth, document number), biometric scores.
  • Through BlitzArt: verification status (verified/rejected/pending/ revoked), timestamp, document type and country, confirmed age, number of attempts.
BlitzArt does NOT store the document image or the selfie. The provider retains them for 30-90 days and then deletes them. BlitzArt only receives the result.

2.3 Usage and generated content

  • Prompts, generation parameters, models used
  • Generated images (temporary storage based on plan)
  • Custom configurations (styles, references, LoRAs)
  • UI interactions (clicks, session time)

2.4 Payment and billing

  • Billing data: name, address, postal code, country
  • Cards: NOT stored. Processed by Stripe/PayPal via tokenization.
  • Transaction and subscription history

2.5 Technical data

  • IP address (anonymized after 30 days), browser and version
  • OS, device type, screen resolution
  • Cookies and similar identifiers
03

How we use your information

Purposes and limits of data processing.

3.1 Primary purposes

  • Provide, maintain, and improve the service
  • Process payments and prevent fraud
  • Verify identity and age for Advanced Models
  • Moderate content per our Acceptable Use Policy
  • Meet legal obligations and respond to court orders
  • Send technical and marketing communications (with consent)

3.2 Use of biometric data

Verification data is used exclusively to:

  • Confirm age of majority
  • Verify match between person and document
  • Prevent impersonation and fraud
We do NOT use biometric data to train facial recognition models, create marketing profiles, or share with unauthorized third parties.

3.3 Use of generated images

We may use anonymized images to train moderation systems, improve in-house models, and for aggregate statistics. Opt-out is available in your settings panel.

05

Who we share with

Authorized data processors.

5.1 AI model providers

When you generate an image, your prompt is sent to the selected model's provider. We never share your name, email, or account data with them.

  • Black Forest Labs (Flux), OpenAI (DALL·E, GPT-4o), Ideogram, Krea, Recraft
  • Alibaba (Qwen), Tencent (Hunyuan), xAI (Grok)
  • Advanced Models providers under specific agreements

5.2 Identity verification (KYC)

  • Onfido Ltd. (United Kingdom)
  • Persona Identities Inc. (United States)

5.3 Payment processors

  • Stripe, PayPal, and specialized processors for adult content

5.4 Infrastructure

  • AWS (servers), Cloudflare (CDN/DDoS), Vercel (hosting), MongoDB/PostgreSQL

5.5 Competent authorities

We share when legally required: valid court orders, requests from law enforcement, mandatory NCMEC reports, fraud investigations.

BlitzArt does NOT sell, rent, or trade personal data for third-party marketing.
06

Retention and deletion

How long we keep each category of data.

CategoryRetention
Account data (name, email, profile)Account lifetime + 2 years
Prompt history90 days from generation
Standard Models images30 days or active plan duration
Advanced Models images90 days mandatory
Audit logs (Advanced)7 years (legal compliance)
Verification data2 years post-verification
Payment data (tokenized)7 years (tax obligation)
Banned account (illegal content)7 years (evidence)
Technical logs (IP, UA)30 days, then anonymized
Cookies and tracking13 months max

6.2 Account deletion

  • Profile: anonymized or deleted in 30 days
  • Standard images: deleted immediately
  • Advanced images: 90 additional days for traceability
  • Audit logs: 7 years (not deleted)
  • Payment: 7 years per tax obligations
07

Your rights

Access, rectification, deletion, objection, and more.

Under GDPR, LFPDPPP, CCPA and other applicable laws, you have the following rights over your personal data:

Access
Get a copy of the data we hold
Rectification
Correct inaccurate data
Deletion
Erase your data (right to be forgotten)
Objection
Object to specific processing
Restriction
Limit processing
Portability
Receive your data in JSON/CSV
Automated decisions
Request human review
Withdraw consent
Revoke permissions any time

How to exercise your rights

Send your request to privacy@blitzart.app with the subject "Data Subject Request" or "GDPR Request". We respond within 20-30 days depending on jurisdiction.

08

Cookies and tracking

Technologies we use and how to control them.

CategoryExamplesDurationConsent
EssentialSession, auth, CSRFSession / 1 yearNo
PerformanceCloudflare, speed1 monthNo
AnalyticsGA, Posthog, Mixpanel13 monthsYes (opt-in)
MarketingMeta, TikTok, Google Ads13 monthsYes (opt-in)
PreferencesTheme, filters, favorite model1 yearNo

Configure your preferences in Settings → Privacy → Cookies.

09

Information security

Technical and organizational measures.

Technical

  • TLS 1.3 in transit and AES-256 at rest
  • Password hashing with bcrypt/Argon2 + salt
  • Optional MFA on Pro/Ultimate/Creator plans
  • WAF, DDoS protection, annual penetration testing

Organizational

  • Least privilege and continuous training
  • NDAs with employees and contractors
  • Cyber insurance
Security breach: in case of an incident affecting you, we notify within 72 hours with the nature, affected data, measures taken, and steps to protect yourself.
10

International data transfers

How we protect data when it leaves your country.

Your data may be transferred to:

  • United States (AWS us-east, Stripe, OpenAI, Persona)
  • European Union (AWS eu-west, Onfido)
  • United Kingdom (Onfido)
  • China (Qwen, Hunyuan — anonymized prompts only, no account data)
We apply EU Standard Contractual Clauses (SCCs), DPAs with all providers, and verify certifications (SOC 2, ISO 27001, GDPR).
11

Minors

Minimum age and protection of minors.

Standard Models: minimum age 13 (with parental consent for 13-17). Advanced Models: strictly 18+ with identity verification.

If we discover a minor accessed Advanced Models with false data, the account is suspended and the data is kept for investigation. We report to authorities if illegal content was generated.

Parents and guardians: contact privacy@blitzart.app if your child under 13 created an account.

13

Changes to this policy

We may update this Policy periodically. Minor changes take effect immediately; substantial changes are notified by email and banner at least 30 days in advance.

The "Last updated" date at the top indicates the current version. Continued use after changes constitutes acceptance.

14

Jurisdiction-specific provisions

GDPR, LFPDPPP, CCPA/CPRA, UK GDPR.

European Union (GDPR)

Right to lodge a complaint with the supervisory authority of your member state of residence.

Mexico (LFPDPPP)

ARCO rights with response within 20 business days. Authority: INAI.

California (CCPA/CPRA)

Right to know, delete, opt-out (BlitzArt does not sell data), non-discrimination, and correct data.

United Kingdom (UK GDPR)

Post-Brexit UK GDPR applies.

15

Contact

How to reach our privacy team.

Response time: 20-30 business days depending on jurisdiction and complexity.

A

Annex A — KYC providers

Current providers: Onfido / Persona.

The provider retains images for 30-90 days according to their policy and then deletes them. BlitzArt only receives the result, score, document type and country, and date.

B

Annex B — AI providers

ProviderData sharedServersDPA
OpenAIPrompts, parametersUSYes
Black Forest LabsPrompts, parametersUS / EUYes
IdeogramPrompts, parametersUSYes
KreaPrompts, parametersUSYes
RecraftPrompts, parametersUS / EUYes
Alibaba (Qwen)Anonymized promptsChina / SingaporeYes
Tencent (Hunyuan)Anonymized promptsChinaYes
xAI (Grok)Prompts, parametersUSYes
Lustify / Seedream / ChromaPrompts (Pro+)TBDYes

Got questions?

Our privacy team answers any question about how we process your data within 20-30 business days.