r
renvido

Privacy Policy

Last updated: 21 sierpnia 2026

This English text is a convenience translation. In case of any discrepancy, the Polish-language version is legally binding.

1. Data controller

The controller of the personal data of Renvido users is LNBC Consulting sp. z o.o., with its registered office at ul. Polna 35, 97-200 Tomaszów Mazowiecki, Polska, VAT ID 118-229-28-93. Contact for data protection matters: contact@renvido.com.

2. What data we process

  • Account data: email address, display name, Google account identifier (with Google sign-in).
  • Organization and brand data: brand name, website, social profiles, logo, brand description, colors.
  • Uploaded materials: product photos, graphic templates and other files uploaded to perform a generation.
  • Generated content and generation parameters.
  • Billing data: purchase history, subscription status, Stripe customer identifier. We do not store payment card data — Stripe handles it.
  • Technical data: server logs, IP address, basic device data — to the extent necessary for security and diagnostics.

3. Purposes and legal bases

  • providing the service and managing the account — Art. 6(1)(b) GDPR (contract);
  • billing, invoices, tax obligations — Art. 6(1)(c) GDPR (legal obligation);
  • security, abuse prevention, pursuing claims — Art. 6(1)(f) GDPR (legitimate interest);
  • service messages about your account and use of the service (e.g. a reminder to finish setup or use your credits) — Art. 6(1)(f) GDPR (legitimate interest);
  • marketing communication (including win-back emails) — only with separate consent and with the option to unsubscribe at any time (Art. 6(1)(a) GDPR).

4. Data recipients and AI processing

We use trusted providers who process data on our behalf:

  • Google Ireland / Google Cloud (Firebase) — authentication, database, file storage;
  • Vercel — application hosting;
  • Stripe — payments and invoicing;
  • wFirma.pl (WEB INNOVATIVE SOFTWARE) — issuing invoices (purchaser billing data);
  • Resend — sending emails (account notifications, support replies, marketing messages with your consent); the email address and message content are processed;
  • Anthropic — analysis of uploaded photos and caption generation (Claude model);
  • Google (Gemini API) — image generation;
  • Meta Platforms Ireland — browser pixel — loaded only if you consent to marketing cookies (Meta Pixel, section 7);
  • Meta Platforms Ireland — server-side measurement — a separate processing, independent of your choice in the consent banner. When you register an account, start a checkout, make a purchase (including starting a subscription), or download or export generated material for the first time, we send Meta: a hashed email address, a hashed account identifier, hashed first and last name, a hashed country code, your IP address, browser data (user agent), the address of the page the event was sent from, and — for payments — the transaction amount and currency. If you have already accepted marketing cookies, we also include the identifiers from Meta's cookies (_fbp and _fbc), set by the pixel described below in section 7 — without that consent, those cookies simply do not exist. Purpose: measuring the effectiveness of our ads on Facebook and Instagram. The basis is our legitimate interest (Article 6(1)(f) GDPR). Data is transferred outside the European Economic Area (USA) under the same transfer mechanisms described below;
  • Functional Software, Inc. (Sentry) — monitoring of technical application errors. When an error occurs, technical event data is recorded (error type, page address, request identifier); the tool is not used to track or profile users.

Important: uploaded photos and captions are passed to AI model providers (Anthropic, Google) solely to perform the requested generation. Some providers process data outside the European Economic Area (including in the USA) — transfers take place under approved mechanisms such as Standard Contractual Clauses or the EU-US Data Privacy Framework.

5. Retention period

  • account data — for as long as the account exists;
  • uploaded materials and generated content — until deleted by the user or until the account is deleted;
  • billing data — for the period required by tax law (generally 5 years);
  • technical logs — up to 12 months;
  • input material kept for failure diagnosis and generation quality control — up to 360 days from the generation (see section 11); after you delete an upload, we keep the file itself for up to 360 more days for the same purpose.

6. Your rights

You have the right to: access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent at any time. We handle requests at contact@renvido.com. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (uodo.gov.pl).

7. Cookies and similar technologies

The Service uses the following categories of technologies:

  • Essential (always on): maintaining the login session (Firebase Authentication), remembering the application state and your cookie decision. They operate on the basis of legitimate interest — without them the Service does not work.
  • Performance (no cookies): anonymous measurement of traffic and page speed (Vercel Analytics, Speed Insights) — they use no cookies and do not track the user across pages.
  • Marketing (only with consent): Meta Pixel (Meta Platforms Ireland) — measures the effectiveness of our ads on Facebook and Instagram. It is loaded only after clicking “Accept” in the consent banner. Meta may combine this data with your account in its services — see Meta's privacy policy for details. Independently of this pixel, we also run server-side measurement — described in section 4.

You can change or withdraw consent at any time — click “Cookie settings” in the page footer and choose “Only necessary”.

8. Likeness of people in uploaded photos

If uploaded materials contain the likeness of people — in particular children — the user is responsible for the lawfulness of their use (including the required consents), in accordance with the Terms. The Service is not intended for creating content depicting real people without their consent.

9. Connecting Instagram and Facebook (publishing)

If you choose to connect your Meta account (a Facebook Page and the linked Instagram Business/Creator account) in order to publish content directly from Renvido, we process for this purpose:

  • the identifier and name of your Facebook Page and the linked Instagram account;
  • access tokens issued by Meta, required to publish on your behalf — stored in encrypted form and accessible only on the server side;
  • the content you choose to publish (image and caption).

We use this data solely to publish content you request and for no other purpose. The recipient is Meta Platforms Ireland — to the extent necessary to perform the publication. You can revoke the connection at any time in: Settings → Social media → Disconnect; disconnecting deletes the stored tokens and revokes the permissions on Meta's side. You may also request their deletion by writing to contact@renvido.com.

10. Security

We apply technical and organizational measures appropriate to the risk: transport encryption (TLS), access control based on authentication, restricting data access on the server side, and separating service keys from client-side code.

11. Product analytics

To improve the application and better tailor it to users' needs, we analyze how you use Renvido — e.g. which features you launch, which parameters you choose when generating, and at which stage you stop the setup. By parameters we also mean the content of the free-text fields you fill in yourself (e.g. your wish for the scene, product details, the goal of the post) — so that we can see what users expect from a generation and improve its quality. We also store the result of each generation (the generated image and caption together with its parameters) so you can return to your earlier work. This also covers content prepared for marketplace listings (title, description, tags and the titles fitted to each sales platform) — we store it as the model returned it, together with technical parameters of the call, in order to control quality and diagnose failures of this feature. We also store the input material of a generation (the product photos you upload) together with its parameters — including when the generation fails — and a technical excerpt of the model's response. This serves failure diagnosis and quality control only, and we keep such material for no longer than 360 days from the generation. We treat photos you delete from your view the same way — including ones you never used for a generation. They disappear from the application immediately and their existing download links stop working, but we keep the file itself for up to 360 days for that same, purely technical purpose; after that we delete it permanently. Deleting your account removes this material right away. On your first visit we additionally store — in a first-party cookie — the source you came from (campaign parameters in the URL, the referring page, and the country derived from your IP address). In a second, separate first-party cookie we remember the address of the last information page you visited, so that after signing up we can open the part of the application that page was about. This second cookie has a shorter lifetime and expires on its own.

The basis is our legitimate interest (Art. 6(1)(f) GDPR) in developing, securing and measuring the effectiveness of the service. We do not use this data for advertising profiling, nor do we share it with third parties for that purpose. Analytics data is linked to your account identifier and deleted when your account is deleted. You can object to this processing at any time by writing to contact@renvido.com.

12. Changes to this policy

We will inform you of significant changes to this policy in the Service or by email. The date of the last update is shown at the top of the document.