Who we are
Vitonize ([[LEGAL ENTITY NAME]], [[REGISTERED ADDRESS]], company number [[OIB / COMPANY NUMBER]]) is the controller of the personal data described here. Write to info@vitonize.com with any question about it.
What we collect
Only what the service needs to run. There is no analytics package, no advertising pixel and no third-party tracker anywhere on this site — we do not measure your behaviour and we have nothing to sell to anyone who would.
- Account details. Your name, your email address, and a password stored only as a scrypt hash with a random salt. We never hold your password itself and cannot recover it.
- Sign-in with Google. If you use it, Google returns your name, email address and profile picture. We do not receive your Google password.
- Images and prompts you submit. The photographs you upload and the text you write, for as long as it takes to produce your result.
- Session tokens. A random string per device, so you stay signed in. It identifies the session, not you.
Your photographs, and where they go
This is the part worth reading closely. When you generate anything, the image you uploaded and the prompt you wrote are sent to fal.ai, our AI processing provider, whose servers are in the United States. This is a transfer of personal data outside the European Economic Area.
If your photograph shows a person, that photograph is personal data about them as well as about you. Before uploading a picture of someone, you need their permission — the Acceptable Use Policy covers this and it is not a formality.
We do not use your images to train any model, and we do not offer them to anyone else for that purpose. fal.ai process them to fulfil your request under our instructions.
Who else processes your data
- fal.ai (United States) — runs the image and video generation. Receives your uploads and prompts.
- Google Ireland Limited — only if you choose to sign in with Google.
- Resend (United States) — sends account emails. Receives your name and email address.
- [[HOSTING PROVIDER AND COUNTRY]] — stores the site and account data.
Transfers to the United States rely on the EU–US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses otherwise. Ask us and we will tell you which applies to a given provider.
Why we are allowed to hold it
- To perform our contract with you — your account, your generations, your files.
- Our legitimate interest — keeping the service secure, and stopping abuse.
- Legal obligation — invoices and tax records.
How long we keep it
- Account details: until you delete the account, then removed within 30 days.
- Generated images and the files behind them: according to the history window on your plan — 7 days on Free, 90 days on Starter, unlimited on Plus and Ultra.
- Invoices: as long as tax law requires, currently [[RETENTION PERIOD — typically 11 years in Croatia]].
What is stored in your browser
The studio keeps your preferences in your browser's local storage rather than in cookies: the theme you chose, your last model and prompt, whether the sidebar is collapsed, and your session token. None of it is sent to advertisers, because there are none. Clearing your browser data removes all of it and signs you out.
Your rights
Under the GDPR you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Write to info@vitonize.com and we will answer within one month.
If you think we have handled your data badly, you can complain to the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb — or to the authority where you live.
Security, honestly stated
Passwords are hashed with scrypt and a per-account salt, and compared in constant time. Account data is held outside the published site directory. No system is perfect; if we ever discover a breach affecting your rights, we will tell you and the supervisory authority as the law requires.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect.