Privacy Policy

Effective: 18 June 2026 · Last updated: 30 June 2026

This is the binding privacy policy for Influspot. It explains how OUTSI sp. z o.o. collects, uses, shares, and protects your personal data when you use Influspot to build, generate content for, and grow an AI persona. Please read it together with our Terms of Service.

Who we are / Data controller

Influspot is operated by OUTSI sp. z o.o. (OUTSI Spółka z ograniczoną odpowiedzialnością), registered in Poland. Registered office: Kartuska 2, 83-334 Miechucino, Poland. KRS: 0000935494, NIP: 5892069190. Influspot is governed by Polish law. OUTSI sp. z o.o. is the GDPR data controller responsible for the personal data processed through Influspot.

For any privacy matter, contact us at privacy@influspot.com.

What we collect

Depending on how you use the service, we collect the following categories of data:

  • Account and identity data — your email address and authentication details. Sign-in is handled through Supabase and, if you choose it, Google OAuth.
  • Persona inputs — the persona reference images and the prompts you upload or enter to generate content.
  • Generated content — the photos and videos produced for your personas.
  • Billing data — handled by Stripe. We do not store full card numbers; Stripe processes your payment details directly.
  • Connected-account data — the social-account access tokens and handles needed to publish on your behalf, managed via Zernio.
  • Usage and analytics data — how you interact with the marketing pages and the product.
  • Device and log data — technical information such as IP address, browser type, and request logs.
  • Error-diagnostics data — crash and error reports collected via Sentry to keep the service reliable.

Special-category & biometric data

Persona reference images of real, identifiable people may, depending on their content and processing, constitute special-category or biometric data under Article 9 GDPR. You are solely responsible for ensuring you have a valid lawful basis and any required consent for uploading and using any real person's likeness. We process such inputs only to operate the service for you — to generate and manage your persona content — and do not use them to uniquely identify individuals for our own purposes. If you do not have the necessary rights or consent, you must not upload that material.

How we use your data & legal bases (GDPR)

We process your personal data on the following legal bases under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)) — operating the service: account management, content generation, scheduling, auto-posting to your connected accounts, and billing.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse and fraud, improving the product, and basic analytics.
  • Consent (Art. 6(1)(a)) — marketing and conversion analytics where applicable; you can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — keeping tax and accounting records and responding to lawful requests from authorities.

Cookies & analytics

We use first-party cookies strictly to keep you authenticated and to maintain your session. For measurement we rely on the following tools:

  • PostHog (EU) — privacy-friendly website and product analytics, in production only.
  • Meta Pixel + Conversions API (CAPI) — an advertising and marketing measurement technology used for conversion tracking, in production only.

There is no separate cookie consent banner because we do not set non-essential first-party tracking cookies; the only first-party cookies we use are strictly necessary for authentication and session management. The named third-party tools run exactly as described above.

Sub-processors / who we share data with

We share data with the following service providers, each only to the extent needed for the stated purpose:

  • Supabase — database, authentication, and storage.
  • Stripe — payment processing.
  • fal.ai and WaveSpeed — AI image and video generation.
  • Zernio — social auto-posting to Instagram and TikTok.
  • PostHog — website and product analytics (EU region).
  • Meta — Pixel and Conversions API advertising measurement.
  • Resend — transactional email.
  • Sentry — error monitoring (EU region).
  • Google — OAuth sign-in.
  • Cloudflare Turnstile — anti-bot and abuse prevention.
  • Vercel — hosting.

Some of these processors are located outside the European Economic Area (EEA). Where that is the case, such transfers rely on Standard Contractual Clauses (SCCs) or an applicable adequacy decision.

International transfers

Your data may be transferred to and processed in countries outside the EEA. We safeguard such transfers through Standard Contractual Clauses (SCCs) or by relying on adequacy decisions adopted by the European Commission.

Data retention

We keep personal data only as long as needed for the purposes described in this policy, then delete or anonymise it. The specific periods below are illustrative where exact figures are not legally fixed:

  • Account and persona data — kept while the account is active; after the account is closed, deleted or anonymised within approximately 30–90 days.
  • Billing and tax/accounting records — retained as required by Polish law (accounting records are generally kept for around 5 years).
  • Error logs and diagnostics — short-lived, typically retained only for a limited period needed to keep the service reliable and secure.

Your GDPR rights

You have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data, as well as the right to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — Prezes UODO).

To exercise any of these rights, email privacy@influspot.com.

Automated decision-making (Art. 22 GDPR)

Certain abuse, fraud, and content-safety checks may be partly automated to keep the service safe and SFW. These checks do not produce legal effects concerning you or similarly significantly affect you without human involvement. If you want to query an automated check or request human review, contact privacy@influspot.com.

Security

We protect your data with encryption in transit, access controls, and Row-Level Security (RLS) that isolates each user's data so that one user cannot access another user's personas, content, or account data.

Children / 18+

Influspot is not intended for anyone under the age of 18. The service is strictly for adults, and we do not knowingly collect personal data from minors.

Changes to this policy

We may update this policy from time to time. We will communicate material changes, and the Effective date at the top of this page always reflects the latest version.

Contact

For privacy questions or data requests, contact privacy@influspot.com. To report a safety concern, contact safety@influspot.com. You can also write to us by post: OUTSI sp. z o.o., Kartuska 2, 83-334 Miechucino, Poland.