Skip to main content
Upgrade
Loading account

Legal

Privacy Policy

This policy explains how Nuzza collects, uses, discloses, retains, and protects personal data when you use Nuzza at https://nuzza.ai.

Effective date
August 5, 2026
Policy version
1.0
Last updated
August 5, 2026

1. Scope and definitions

This Privacy Policy applies to the Nuzza website, accounts, image and video tools, generation features, billing, support, and related services (collectively, the “Service”). It does not govern third-party websites or services that publish their own privacy notices.

“Nuzza,” “we,” “us,” and “our” mean Nuzza. “Personal data” means information that identifies, relates to, describes, or can reasonably be linked to a person. “Content” includes prompts, uploaded images and videos, reference media, generated outputs, and associated metadata.

2. Personal data we collect

Account and contact data

  • Email address, display name, profile image, internal account identifier, authentication method, and account settings.
  • Information received from a configured sign-in provider, such as Google, according to the permissions you approve.
  • Support messages, refund requests, feedback, survey responses, and other communications you send us.

Prompts, uploads, and generated content

  • Text prompts, negative prompts, selected models, generation parameters, workflow settings, and task instructions.
  • Images, videos, start and end frames, reference media, and other files you choose to upload.
  • Generated images and videos, previews, task status, creation history, sharing settings, credit usage, and moderation or safety signals.

Usage, device, and diagnostic data

  • IP address, browser and device information, language, approximate location derived from IP, timestamps, referring pages, visited routes, and feature interactions.
  • Cookie, session, and local-storage identifiers used for authentication, preferences, security, fraud prevention, reliability, and analytics.
  • Performance events, task and request logs, error and exception details, security events, and masked session-replay data when the relevant analytics feature is enabled.

Billing and transaction data

  • Selected product, price, billing interval, order and subscription identifiers, payment status, currency, tax information, refund state, and credit ledger events.
  • Payment-card details are handled by Stripe. We do not intentionally store complete card numbers or card security codes on Nuzza systems.

Support, safety, and moderation data

  • Communications and evidence submitted for support, refund, abuse, intellectual-property, or privacy requests.
  • Signals and records used to detect fraud, payment disputes, prohibited content, account compromise, and violations of our Terms and Conditions.

3. Sources of personal data

  • Directly from you when you create an account, submit content, configure a task, make a purchase, publish an output, or contact us.
  • Automatically from your browser, device, and use of the Service.
  • From authentication, payment, analytics, infrastructure, AI-processing, security, and support providers.
  • From another person when they legitimately share content with you or submit information relating to a support, safety, rights, or legal request.

5. AI processing and service providers

When you submit a generation or editing request, Nuzza may store necessary uploaded media in Cloudflare object storage under stable content-delivery URLs so the task, retries, and recreate features can use the same inputs. The file is not placed in Explore merely because the URL exists, but anyone who obtains the exact URL may be able to access it.

To complete a task, we send the prompt, selected settings, and necessary input files or file URLs to fal.ai and the model operator used for the model you selected. The selected model can therefore change which processor receives your content, where it is processed, and the processor's retention practices.

Nuzza does not use customer prompts, uploads, or outputs to train a Nuzza-owned generative model. Third-party model and infrastructure providers apply their own terms, retention periods, safety systems, and model-improvement policies. We do not promise universal zero retention or universal exclusion from provider training unless a specific model or plan expressly says so.

  • Cloudflare: hosting, content delivery, databases, object storage, security, and email-related infrastructure.
  • Google: sign-in and Google Analytics when enabled.
  • Stripe: checkout, subscriptions, payment processing, invoices, refunds, and payment-dispute handling.
  • fal.ai and the selected model operator: AI generation, editing, enhancement, and related task processing.
  • PostHog: product analytics, event and exception monitoring, and masked session replay when configured.

6. When we disclose personal data

We do not sell personal data for money. Depending on local law, disclosure to analytics providers may be treated as a sale, sharing, or targeted-advertising activity even when no money changes hands. You may contact us to exercise any applicable opt-out right.

  • To the providers listed above and other vendors that help operate, secure, support, analyze, or audit the Service.
  • To professional advisers, auditors, insurers, financial institutions, tax services, and fraud-prevention providers where reasonably necessary.
  • When you deliberately publish content, enable sharing, provide a link, or otherwise direct us to disclose information.
  • To comply with law, legal process, or regulatory requests, or to protect rights, safety, property, and the integrity of the Service.
  • In connection with a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the business, subject to appropriate safeguards.
  • With your direction or consent.

7. Public content, sharing, and file visibility

Your generated content is not listed in Explore unless you deliberately use a publishing feature that makes it public. Public content may be viewed, copied, downloaded, indexed, reshared, or captured by other people and services. Removing it from Nuzza may not remove copies already made elsewhere.

Content kept out of Explore is not publicly listed, but an uploaded or generated file may still be reachable by a person who has its exact content-delivery URL. Do not upload highly confidential material unless you accept this link-based access model.

Use the available content controls to remove an item from your history or public areas. Some operational, provider, backup, moderation, or legal copies may remain for the periods described below.

8. Cookies, local storage, and analytics

We use cookies and similar browser storage for sign-in sessions, security, preferences, product functionality, and fraud prevention. Disabling essential storage may prevent parts of the Service from working.

On production pages, Google Analytics may collect page and device information. When configured, PostHog may collect page views, feature events, exceptions, and masked session-replay information. Session replay is intended to mask typed text and sensitive elements, but you should not submit secrets that are unnecessary for the Service.

You can use browser controls, content blockers, or provider opt-out tools to limit non-essential analytics. Nuzza does not currently expose a separate in-product analytics preference panel. Depending on where you live, you may also request an applicable opt-out by emailing privacy@nuzza.ai.

9. Data retention and account deletion

We keep account data while your account is active and for as long as reasonably necessary to provide the Service, meet contractual and legal obligations, prevent fraud, resolve disputes, and enforce agreements. Retention depends on the data, the purpose, legal requirements, and whether a dispute or security issue is open.

Prompts, input media, generated outputs, and creation history may remain until you delete individual items, request account deletion, or they are removed under an operational or legal retention rule. Deleting an item from the interface may not immediately remove provider, backup, security, or legally required copies.

Account deletion removes sign-in sessions, connected login accounts, verification data, and the user profile, and attempts to remove the profile image. The account identifier and email are anonymized so the account can no longer be used. Generation history, credit records, payment records, and audit records may be retained under an internal identifier for fraud prevention, financial reconciliation, dispute handling, security, and legal compliance, but they are no longer available through the deleted account.

Our providers may keep copies under their own retention, backup, security, and legal rules. We delete or anonymize data when it is no longer reasonably needed, unless retention is required or permitted by law.

10. Security

We use technical and organizational measures intended to protect personal data, including access controls, server-side credential separation, authentication, event auditing, protected payment processing, and service monitoring. No internet service, transmission, or storage system can be guaranteed completely secure.

If you believe your account or data is at risk, contact privacy@nuzza.ai promptly.

11. International data transfers

Nuzza and our providers may process data outside your country. Where applicable law requires it, we use recognized transfer mechanisms, contractual protections, and supplementary safeguards appropriate to the destination and data.

12. Your privacy rights

Depending on where you live, you may have rights to know or access personal data, correct inaccurate data, delete data, restrict or object to processing, receive a portable copy, withdraw consent, opt out of certain sales, sharing, profiling, or targeted advertising, and appeal a decision about a request.

To make a request, email privacy@nuzza.ai from the address associated with your account and describe the right you want to exercise. We may verify your identity and may deny or limit a request where law permits. Authorized agents may be asked to provide proof of authority. We will not unlawfully discriminate against you for exercising a privacy right.

You may also complain to your local data-protection authority or regulator. If we deny an appeal right available under local law, our response will explain how to escalate the matter.

13. Regional privacy disclosures

For residents of jurisdictions with category-based privacy notices, the categories collected during the preceding 12 months may include identifiers; customer records; commercial and transaction information; internet or electronic activity; approximate geolocation; audio, visual, or similar content; and inferences from product use. We use and disclose these categories for the business and commercial purposes described in Sections 4 through 6.

The recipient categories may include cloud and AI processors, analytics providers, authentication providers, payment and fraud services, professional advisers, authorities, corporate transaction participants, and other recipients you direct. We do not knowingly sell or share the personal data of people under 18.

Local law may provide additional rights or exceptions. The rights request process in Section 12 applies to these requests.

14. Children

The Service is not directed to anyone under 18, and you must be at least 18 to create an account. We do not knowingly collect personal data from children below the applicable minimum age. If you believe a child has provided data, contact privacy@nuzza.ai so we can investigate and take appropriate action.

15. Changes to this policy

We may update this policy as the Service, providers, or legal requirements change. We will update the effective date, last-updated date, and version above, and provide additional notice when a change is material.

16. Contact

Privacy questions and requests may be sent to privacy@nuzza.ai. General support questions may be sent to support@nuzza.ai.