Privacy Policy

Last updated: 7/27/2025

Data Controller

MPH GL GmbH
Panoramaweg 1
CH-8274 Tägerwilen, Switzerland
Swiss Commercial Register: CHE-458.462.294

We are committed to protecting your privacy and handling your data transparently.

Information We Collect

We collect the following information:

  • Account Information: Email address and name when you register
  • Usage Data: How you interact with our service
  • AI Processing: Your prompts and usage when using AI features
  • Authentication: IP addresses and browser information for security
  • Two-Factor Authentication: Encrypted backup codes (if enabled)

Cookies

We use the following cookies:

  • NEXT_LOCALE: Stores your language preference (1 year)
  • Session Cookie: Maintains your login state (persistent)
  • OAuth State Cookies: Temporary authentication tokens (1 hour)
  • Analytics Cookies: Google Analytics, Umami, and Vercel Analytics

Third-Party Services

We use these services to operate our platform:

  • Vercel: Hosts our website and provides analytics (US-based)
  • Neon: Stores your data securely (US-based)
  • Paddle: Acts as Merchant of Record for payments - handles all payment data (UK-based)
  • Resend: Sends transactional emails (US-based)
  • OpenAI: Processes AI requests (US-based)
  • Google Analytics & Umami: Website analytics
  • OAuth Providers: Google and Facebook for authentication

Payment Processing

Paddle acts as Merchant of Record, meaning:

  • We don't store your payment details
  • Paddle handles all payment processing and invoicing
  • We only receive transaction confirmations
  • Your payment data is governed by Paddle's privacy policy

Data Retention

  • Account data: Retained until you delete your account
  • Authentication logs: Retained for 90 days
  • AI usage data: Retained for service operation
  • Session data: Cleared periodically

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account
  • Request data deletion

Security

We use industry-standard encryption for data transmission and storage. All connections are secured with HTTPS.

Contact

For privacy concerns, contact us at: privacy@getimagify.com