1. Introduction
Smoothie AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered visual content generation service ("the Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
- Name
- Email address
- Password (encrypted)
- Company name (optional)
- Billing information (processed by Stripe)
Content Data:
- Images you upload
- Generated images and projects
- Project names and descriptions
- Export preferences and settings
Communication Data:
- Support tickets and inquiries
- Feedback and suggestions
- Newsletter subscriptions
2.2 Information Collected Automatically
Usage Data
- Features used and frequency
- Generation parameters and preferences
- Time spent on the platform
- Error logs and performance data
Device and Browser Information
- IP address
- Browser type and version
- Operating system
- Screen resolution
- Time zone and language preferences
Cookies and Tracking Technologies:
- Session cookies for authentication
- Preference cookies for user settings
- Analytics cookies (if consented)
- Local storage for application state
2.3 Information from Third Parties
Payment Information:
- Transaction details from Stripe
- Subscription status and history
OAuth Information (if applicable):
- Basic profile information from Google/social login providers
- Email address for account creation
3. How We Use Your Information
3.1 To Provide the Service
- Process your images and generate content
- Maintain your account and projects
- Provide customer support
- Process payments and manage subscriptions
3.2 To Improve the Service
- Analyze usage patterns and trends
- Develop new features and improvements
- Optimize AI model performance
- Fix bugs and technical issues
3.3 To Communicate with You
- Send service-related notifications
- Provide customer support
- Send marketing communications (with consent)
- Notify you of policy changes
3.4 For Legal and Security Purposes
- Comply with legal obligations
- Protect against fraud and abuse
- Enforce our Terms of Service
- Protect our rights and property
4. Data Sharing and Disclosure
4.1 Service Providers
We share data with trusted third-party service providers:
Infrastructure
- Vercel (hosting and deployment)
- Firebase (database and authentication)
- Cloud storage providers (image storage)
Payment Processing
- Stripe (payment processing)
- No direct access to credit card information
Analytics (with consent)
- Usage analytics tools
- Performance monitoring services
4.2 Legal Requirements
We may disclose information if required by:
- Law or legal process
- Government authorities
- To protect rights, property, or safety
- In connection with legal proceedings
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
4.4 With Your Consent
We my share information with your explicit consent or at your direction.
5. Data Security
5.1 Security Measures
We implement industry-standard security measures:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Regular security audits and updates
- Access controls and authentication
- Regular backups and disaster recovery
5.2 Data Breach Response
In the event of a data breach:
- We will notify affected users within 72 hours
- We will provide information about the breach
- We will offer guidance on protective measures
- We will cooperate with relevant authorities
6. Your Rights and Choices
6.1 Access and Portability
You have the right to:
- Access your personal data
- Receive a copy of your data
- Export your generated content
6.2 Correction and Deletion
You may:
- Update your account information
- Request correction of inaccurate data
- Request deletion of your account and data
6.3 Communication Preferences
You can:
- Opt-out of marketing emails
- Manage notification preferences
- Unsubscribe from newsletters
6.4 Cookie Choices
You can:
- Manage cookie preferences
- Use browser settings to block cookies
- Clear cookies and local storage
7. Data Retention
7.1 Active Accounts
We retain your data while your account is active and as necessary to provide the Service.
7.2 After Account Deletion
Account data: Deleted within 30 days
Generated content: Deleted within 90 days
Backup data: Deleted within 180 days
Legal records: Retained as required by law
7.3 Aggregated Data
We may retain aggregated, anonymized data indefinitely for analytics and improvement purposes.
8. International Data Transfers
8.1 Data Location
Our servers are located in the United States. By using the Service, you consent to the transfer of your data to the United States.
8.2 Compliance
We comply with applicable data protection laws regarding international data transfers.
9. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected such information, we will delete it immediately.
10. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act:
- Right to know about personal information collected- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination
To exercise these rights, contact us at support@getsmoothie.ai.
11. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have rights under the General Data Protection Regulation:
- Right to access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
Legal Basis for Processing
We process your data based on:
- Contract performance (to provide the Service)
- Legitimate interests (to improve the Service)
- Legal obligations
- Your consent (for marketing and analytics)
12. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via:
- Email notification
- In-app notification
- Website banner
The "Effective Date" at the top indicates the last revision date.
14. Contact Information
For privacy-related questions or concerns:
Email: support@getsmoothie.ai
Website: https://getsmoothie.ai
For general inquiries: support@smoothie.ai
15. Data Protection Framework
15.1 Privacy by Design
We incorporate privacy considerations into our product development process.
15.2 Regular Audits
We conduct regular privacy and security audits to ensure compliance.
15.3 Employee Training
Our team receives regular training on privacy and data protection.
15.4 Vendor Management
We carefully select and monitor third-party vendors for privacy compliance.