Your privacy,
explained clearly.
What data we collect, why we need it, who we share it with, and how you can exercise your rights over it.
Introduction
How and why we process your information.
BlitzArt.app ("BlitzArt", "we", "the platform") is committed to protecting the privacy of its users. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use our AI image and text generation service.
By using BlitzArt.app you accept the practices described in this Policy and in our Terms of Service. If you don't agree, please don't use the service.
Information we collect
Categories of personal data we process.
2.1 Account and profile
- Full name or username
- Email address
- Password (hashed and salted with bcrypt/Argon2)
- Country of residence (detected from IP or self-declared)
- Preferred language, signup date, last login
2.2 Identity and age verification data
For users requesting access to Advanced Models (uncensored AI models):
- Through the provider (Onfido / Persona): ID document image, live selfie, extracted data (name, date of birth, document number), biometric scores.
- Through BlitzArt: verification status (verified/rejected/pending/ revoked), timestamp, document type and country, confirmed age, number of attempts.
2.3 Usage and generated content
- Prompts, generation parameters, models used
- Generated images (temporary storage based on plan)
- Custom configurations (styles, references, LoRAs)
- UI interactions (clicks, session time)
2.4 Payment and billing
- Billing data: name, address, postal code, country
- Cards: NOT stored. Processed by Stripe/PayPal via tokenization.
- Transaction and subscription history
2.5 Technical data
- IP address (anonymized after 30 days), browser and version
- OS, device type, screen resolution
- Cookies and similar identifiers
How we use your information
Purposes and limits of data processing.
3.1 Primary purposes
- Provide, maintain, and improve the service
- Process payments and prevent fraud
- Verify identity and age for Advanced Models
- Moderate content per our Acceptable Use Policy
- Meet legal obligations and respond to court orders
- Send technical and marketing communications (with consent)
3.2 Use of biometric data
Verification data is used exclusively to:
- Confirm age of majority
- Verify match between person and document
- Prevent impersonation and fraud
3.3 Use of generated images
We may use anonymized images to train moderation systems, improve in-house models, and for aggregate statistics. Opt-out is available in your settings panel.
Legal basis (GDPR / LFPDPPP)
Legal grounds for each processing activity.
| Legal basis | Applies to |
|---|---|
| Contract performance | Service, account, subscription, payments |
| Legal obligations | Age verification, CSAM/deepfake retention, court orders, AML |
| Legitimate interest | Security, moderation, aggregate analytics, payment fraud prevention |
| Explicit consent | Biometrics for Advanced Models, marketing, non-essential cookies |
You can withdraw consent at any time from Settings or by writing to privacy@blitzart.app. Withdrawal does not affect the lawfulness of prior processing.
Retention and deletion
How long we keep each category of data.
| Category | Retention |
|---|---|
| Account data (name, email, profile) | Account lifetime + 2 years |
| Prompt history | 90 days from generation |
| Standard Models images | 30 days or active plan duration |
| Advanced Models images | 90 days mandatory |
| Audit logs (Advanced) | 7 years (legal compliance) |
| Verification data | 2 years post-verification |
| Payment data (tokenized) | 7 years (tax obligation) |
| Banned account (illegal content) | 7 years (evidence) |
| Technical logs (IP, UA) | 30 days, then anonymized |
| Cookies and tracking | 13 months max |
6.2 Account deletion
- Profile: anonymized or deleted in 30 days
- Standard images: deleted immediately
- Advanced images: 90 additional days for traceability
- Audit logs: 7 years (not deleted)
- Payment: 7 years per tax obligations
Your rights
Access, rectification, deletion, objection, and more.
Under GDPR, LFPDPPP, CCPA and other applicable laws, you have the following rights over your personal data:
How to exercise your rights
Send your request to privacy@blitzart.app with the subject "Data Subject Request" or "GDPR Request". We respond within 20-30 days depending on jurisdiction.
Information security
Technical and organizational measures.
Technical
- TLS 1.3 in transit and AES-256 at rest
- Password hashing with bcrypt/Argon2 + salt
- Optional MFA on Pro/Ultimate/Creator plans
- WAF, DDoS protection, annual penetration testing
Organizational
- Least privilege and continuous training
- NDAs with employees and contractors
- Cyber insurance
International data transfers
How we protect data when it leaves your country.
Your data may be transferred to:
- United States (AWS us-east, Stripe, OpenAI, Persona)
- European Union (AWS eu-west, Onfido)
- United Kingdom (Onfido)
- China (Qwen, Hunyuan — anonymized prompts only, no account data)
Minors
Minimum age and protection of minors.
Standard Models: minimum age 13 (with parental consent for 13-17). Advanced Models: strictly 18+ with identity verification.
Parents and guardians: contact privacy@blitzart.app if your child under 13 created an account.
Third-party links
BlitzArt may contain links to third-party sites. This Policy does not apply to those sites. We recommend reviewing each site's privacy policy.
Changes to this policy
We may update this Policy periodically. Minor changes take effect immediately; substantial changes are notified by email and banner at least 30 days in advance.
The "Last updated" date at the top indicates the current version. Continued use after changes constitutes acceptance.
Jurisdiction-specific provisions
GDPR, LFPDPPP, CCPA/CPRA, UK GDPR.
European Union (GDPR)
Right to lodge a complaint with the supervisory authority of your member state of residence.
Mexico (LFPDPPP)
ARCO rights with response within 20 business days. Authority: INAI.
California (CCPA/CPRA)
Right to know, delete, opt-out (BlitzArt does not sell data), non-discrimination, and correct data.
United Kingdom (UK GDPR)
Post-Brexit UK GDPR applies.
Contact
How to reach our privacy team.
Response time: 20-30 business days depending on jurisdiction and complexity.
Annex A — KYC providers
Current providers: Onfido / Persona.
- Onfido — onfido.com/legal/privacy
- Persona — withpersona.com/legal/privacy-policy
The provider retains images for 30-90 days according to their policy and then deletes them. BlitzArt only receives the result, score, document type and country, and date.
Annex B — AI providers
| Provider | Data shared | Servers | DPA |
|---|---|---|---|
| OpenAI | Prompts, parameters | US | Yes |
| Black Forest Labs | Prompts, parameters | US / EU | Yes |
| Ideogram | Prompts, parameters | US | Yes |
| Krea | Prompts, parameters | US | Yes |
| Recraft | Prompts, parameters | US / EU | Yes |
| Alibaba (Qwen) | Anonymized prompts | China / Singapore | Yes |
| Tencent (Hunyuan) | Anonymized prompts | China | Yes |
| xAI (Grok) | Prompts, parameters | US | Yes |
| Lustify / Seedream / Chroma | Prompts (Pro+) | TBD | Yes |
Got questions?
Our privacy team answers any question about how we process your data within 20-30 business days.