Privacy Policy
Privacy Policy
Aificient Studio is a desktop app you run yourself, with your projects saved to your Aificient account in our EU-hosted database — while your social-media logins stay on your own device. Here is exactly what we store, why, and the rights you have over it, in plain language.
The company responsible for your data.
Who we are
Aificient Studio is made by Concord Software SL, an independent software company based in Santander, Spain. For anything we do process, Concord Software SL is the data controller, and this policy explains what that involves under the EU General Data Protection Regulation (GDPR) and other applicable law.
The short version is that Aificient is built to keep the sensitive parts of your work with you. You can reach us about privacy any time at [email protected].
Your work is saved to your Aificient account.
Where your projects are stored
Aificient Studio is a desktop app you install and run on Windows or macOS. Your projects — scripts, scenes, characters, voices, and the images and videos you generate — together with your account details are stored in your Aificient account, in our database, so your work is saved and waiting for you when you come back. That database is hosted within the European Union.
We hold this data to provide the service to you, we treat it as yours, and you can export or delete it at any time, as your rights below explain.
We store your work to run the app — and nothing else.
What we don't do with your content
We store your projects to provide Aificient to you, and for nothing else. We do not use your content to train AI models, we do not sell or rent personal data to anyone, and we run no analytics or profiling. The only third-party tags we use are the Google Ads and Meta conversion measurement tags, described in section 09. We keep the personal data we hold to the minimum the service needs.
Your platform logins never reach us.
Publishing uses your own signed-in sessions
When you connect TikTok, Instagram, or YouTube, you sign in inside the app, in your own session on your device. We use that session only to publish the posts you create and to fetch the data needed to compose them — for example a real trending sound from TikTok’s own catalogue.
Your account passwords and login sessions are never sent to or stored on Aificient’s servers — publishing runs from the session on your own device.
Those platforms are separate controllers of the data you share with them; their handling of it is governed by their own privacy policies, including TikTok, Instagram / Meta, and YouTube / Google.
We tell you exactly where the work runs.
Rendering, and the compute you choose
Video generation can run on your own GPU or, for heavier scenes, on a rented cloud GPU you choose to attach. That compute processes only the content you send to render, for as long as the render takes.
Because a rented GPU may be involved, we will never claim that nothing ever leaves your computer — we will only ever tell you exactly where the work runs. The provider of any GPU you attach processes that content as a service provider, under its own terms.
We keep your message to reply, nothing more.
When you contact us
If you email us at [email protected] or use a contact form, we receive your email address and whatever you choose to write, and we use it only to answer you and keep a record of the conversation. We rely on our legitimate interest in responding to you, and we keep support correspondence only as long as we need it.
A payment processor handles your card — not us.
Payments, when paid plans arrive
Subscriptions and rented cloud compute are paid through a third-party payment processor (such as Stripe). You enter your card details with the processor, not with us; we never see or store your full card number. We will receive only the limited billing information we need to provide the service and to meet our tax and accounting obligations, which we keep for as long as the law requires.
Delivering the app needs basic request data.
Downloads, updates and licensing
When you download the app or it checks for updates, our hosting and content-delivery providers necessarily process basic request data — such as your IP address and the file requested — to deliver the download and to keep the service secure against abuse.
If the app uses a licence or activation key, we process that key to confirm your access. We rely on legitimate interests, and where relevant on performing our agreement with you, for this.
No analytics. One advertising measurement tag.
This website runs no analytics
The site you are reading runs no analytics and builds no profile of you. Our web host may keep short-lived server logs (including IP addresses) to deliver pages and protect the site, which is a standard security measure based on our legitimate interests.
We advertise on Google. To know whether those ads work, we use the Google Ads conversion tag (Google tag, gtag.js) in three places:
- this website;
- two pages of our API (api.aificient.io) that both the web app and the desktop app open in your browser: the sign-in confirmation page shown when you create an account with Google or Apple, and the checkout confirmation page shown after a payment;
- the web app, once, right after you create an account with an email code.
If you visit from the European Economic Area, the United Kingdom or Switzerland, the tag does nothing until you answer the cookie notice shown on your first visit. Elsewhere, where the law does not require asking first, it is enabled unless you opt out from the “Cookies” link in the footer. We tell the two apart from the country of your connection.
If it is enabled, it does the following, so Google can attribute those events to the ad:
- If you arrived from a Google ad, it stores the ad-click identifier in a first-party cookie on aificient.io for up to 90 days.
- When you create an account, it reports to Google that a sign-up happened, with an anonymous account reference.
- If you later start a free trial, it reports that a trial started.
- If you buy a plan, it reports that a purchase happened, the plan price, whether it is your first paid plan with us, and an anonymous transaction reference.
With those events it also sends a hashed version of your email address. The address is scrambled in your browser with SHA-256 before anything leaves the page, so Google receives a code rather than the address, and uses it only to match the sign-up or purchase to your click when the cookie alone cannot, for example on another device.
If you reject, it stores nothing, sends no email hash, and sends Google only a cookieless signal with the click identifier removed. It never sends your name, your address in the clear or what you create, and it is never used to personalise ads. Google processes this data under its own privacy policy.
We also advertise on Facebook and Instagram, and we measure those ads the same way with the Meta Pixel, on the same pages and under the same cookie notice and the same country rule. Until it is enabled it stays completely off: no cookie, no request to Meta.
If it is enabled:
- It records a visit to this site and stores a browser identifier and, if you arrived from a Meta ad, the ad-click identifier, in first-party cookies on aificient.io for up to 90 days.
- When you create an account, it reports to Meta that a sign-up happened; when you start a free trial, that a trial started; and when you buy a plan, that a purchase happened and the plan price.
- Each of those events carries an anonymous reference and a hashed version of your email address, scrambled in your browser with SHA-256 before it is sent, so Meta receives a code rather than the address.
If you reject, it sends nothing at all. It never sends your name, your address in the clear or what you create, and it is never used to personalise ads. Meta processes this data under its own privacy policy.
Your answer to the cookie notice is kept in a cookie on aificient.io for up to 400 days, and you can change it at any time from the “Cookies” link in the footer. The site and the app work the same either way.
Why we're allowed to process the little we do.
The legal bases we rely on
Under the GDPR, the limited processing described above rests on one of these grounds:
- Performance of a contract — to provide the app, downloads, and any paid service you ask for;
- Legitimate interests — to answer your messages, deliver and secure the service, and prevent abuse, balanced against your rights;
- Consent — for the Google Ads and Meta measurement cookies and the hashed email sent with them, which you give or refuse in the cookie notice and can change at any time from the “Cookies” link in the footer;
- Legal obligation — to keep the billing and tax records we are required to keep.
We keep it while your account is active.
How long we keep your data
We keep your projects and account data for as long as your account is active, so your work is there when you return. You can delete individual projects or your whole account at any time, and we will delete the associated data — except for limited records, such as billing, we are required to keep for as long as the law says.
Support emails are kept only as long as needed to help you, and security logs for a short period; when we no longer need something, we delete or anonymize it.
We guard the data you trust us with.
How we keep your data secure
We use reasonable technical and organizational measures to protect the data in our care — including encryption in transit and at rest, access controls, and EU-based hosting — and we keep what we hold to a minimum. No system is ever perfectly secure, but we work to keep your projects safe and to limit who can reach them.
The one thing we deliberately never hold is your social-platform logins: those stay in your own session, on your device.
Access, correct, delete, object — just ask.
Your privacy rights
Wherever the law gives them to you, you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent at any time.
To exercise any of these, write to [email protected] and we will respond within the time the law allows. You also have the right to complain to a data-protection authority — in Spain that is the Agencia Española de Protección de Datos (AEPD), or you can contact the authority in your own country.
Aificient isn't for children.
Children's privacy
Aificient Studio is meant for adults and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under the minimum age in your country). If you believe a child has provided us data, contact us and we will delete it.
We'll date every update.
Changes to this policy
We may update this policy as Aificient grows or the law changes. When we do, we will change the “last updated” date below, and for material changes we will try to give clearer notice in the app or by email. Continuing to use Aificient after an update means you have seen the current version.
Questions about your data?
Write to us — a human will answer.
Ask us anything about your privacy or these terms and a real person will reply — no ticket queue, no bot.
EU-hosted · Windows & macOS · Concord Software SL, Santander, Spain.