Privacy Policy

Last updated 2026-08-08

Who we are

imu studio (“imu”, “we”) is a generative media atelier: you write a prompt, we run it against third-party AI models, and the resulting image, video, audio, or depth output is stored in your library. This engineering draft explains what data the shipping software handles. It is not legal advice and requires final human/legal approval before public launch. We do not run ads, and we do not sell your data.

Data we collect

  • Account and identity information. Authentication is managed through Firebase Authentication. The Firebase UID is the canonical account identity used by the backend. Depending on the client and provider you choose, sign-in can use Google, Sign in with Apple, or email/password. We receive account identifiers such as Firebase UID, email address, provider identifiers, verification state, and name information when a sign-in provider supplies it or the app requests it. We do not collect your contacts.
  • Your prompts and generated content. The prompts you type or speak, prompt templates, saved prompt memory, model parameters, job/session metadata, generation threads, and generated media are stored so your library and workflow persist across devices. Library records are tied to your Firebase UID. Durable media URLs are bearer-by-URL/public-read so a file link can be viewed by anyone who has that URL.
  • Uploaded media. Images, video, or audio you upload as generation inputs, edit sources, profile avatars, or references can be stored temporarily in private upload staging, copied into durable session storage when a job runs, or retained as account content where the product feature requires it.
  • Billing records. RevenueCat and the app stores process purchases for Apple, Google, and web payment channels. imu stores RevenueCat customer links, provider event IDs, product IDs, transaction IDs, subscription state, credit ledger entries, reservations, refunds/reversals, debts, and reconciliation records. imu does not store raw payment-card credentials.
  • Moderation reports. When you report generated output, we store the reporter account identifier, report reason and comment, reported session/artifact/job context, status, duplicate count, audit events, operator review status, notes, and resolution.
  • Crash and error reports. We use Sentry to collect web, backend, and mobile crash or diagnostic data so we can fix bugs. The SDKs are configured with default PII collection disabled, but events can include account IDs, email when explicitly attached by the app, request IDs, device/app context, breadcrumbs, stack traces, and sanitized API failure metadata.
  • Infrastructure diagnostics. Production backend observability can send traces, logs, metrics, and continuous profiling data to Grafana Cloud.
  • Service logs. Standard request logs (timestamps, request IDs, route names, status/error codes, job state, provider state, and operational metadata) are retained for debugging, security, billing integrity, moderation, and abuse prevention.

We do not collect your precise location, contacts, browsing history, or advertising identifiers. There is no ad SDK in our apps.

How your data is used

  • To authenticate you and keep your library tied to your account.
  • To run your generation requests: your prompt and any input media are sent to the AI model provider or hosted inference backend selected for that job.
  • To reserve credits before paid generation, debit final costs after completion, refund failed or cancelled generations, ingest purchase events, reconcile billing state, and handle refunds or reversals.
  • To receive and review user-submitted output reports.
  • To diagnose crashes, debug failures, and prevent abuse.
  • Never for advertising, and never sold or rented to anyone.

Third-party processors

We rely on a small set of infrastructure and model providers. Each receives only what is needed to provide its service:

  • Google Cloud Platform — hosting, storage of your library (Google Cloud Storage), private upload staging, provider scratch storage, Firebase Authentication, Firebase/Google sign-in, Firestore job-status mirroring when enabled, Pub/Sub/Cloud Tasks style job infrastructure, and Vertex AI model processing.
  • Google (Vertex AI / Gemini) — processes prompts and input media for Google models (Imagen, Veo, Lyria, Nano Banana).
  • WaveSpeed — hosted inference for third-party models. Your prompt and input media for those models are processed by WaveSpeed and the upstream model provider (for example ByteDance for Seedream/Seedance, OpenAI for Sora).
  • RunPod / ACE-Step — processes music and ComfyUI image/video requests for the self-hosted RunPod backends when you choose those models.
  • OpenRouter — processes prompt randomizer and text completion requests for prompt-library Flow features, and video generation requests (prompt and input media) for models routed through OpenRouter hosted inference.
  • RevenueCat — purchase, subscription, entitlement, refund, reversal, and reconciliation metadata for Apple, Google, and web payment channels.
  • Apple and Google — platform authentication and in-app purchase processing where those sign-in or payment methods are used.
  • Sentry — crash and performance reporting, with PII filtering and app-side redaction applied.
  • Grafana Cloud — backend logs, metrics, traces, and profiles for production operations.

Model providers process your prompts under their own terms and content policies; we do not grant them rights to your account data beyond fulfilling the generation request.

Retention and deletion

Your prompts, generated media, uploads, collections, prompt templates, chat sessions, routines, generation threads, profiles, jobs, and API keys are retained while your account is active unless you delete specific content sooner. When you delete your account in the app under Account Settings - Delete account, the backend blocks new owner writes, cancels active jobs, deletes owned sessions and media it controls, removes owner-scoped library records, purges signed-upload staging records, revokes API keys, deletes the Firebase user, and redacts your direct UID from moderation report history. We may retain records that are legally or operationally necessary, such as billing ledger and transaction records, refund/reversal/debt records, security logs, moderation audit records with redacted reporter identifiers, durable account-deletion tombstones, and backup copies until normal backup expiry.

Security

All traffic is encrypted in transit (TLS). Data at rest is stored on Google Cloud infrastructure with encryption at rest. Access to your library requires your authenticated session; per-user ownership is enforced on every request.

Children

imu is not directed at children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Changes

We will update this page when our practices change and revise the date above. Material changes will be announced in the app.

Contact

support@imu-studio.com