Legal
Privacy Policy
Last updated: July 7, 2026
1. Who we are
Visuan, operated by Tetiana Zhydkova, Individual Entrepreneur, registered in Lutsk, Ukraine (“Visuan”, “we”, “us”), is the data controller for the personal data described in this policy. You can reach us at [email protected].
2. Data we collect
- Account data — name, email, profile image, authentication identifiers (provided via Clerk).
- Content — the brand inputs, prompts, generated proposals, and uploaded assets you submit to the Service.
- Usage data — log data, device/browser information, IP address, and basic interaction events used to operate and secure the Service.
- Billing data — handled by our payment processor; we receive metadata (plan, status, last 4) but not full card numbers.
3. Why we use it (lawful bases)
- Contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent abuse, and improve product quality.
- Consent — for non-essential cookies and any optional analytics; you can withdraw consent at any time from the Cookie Policy page.
- Legal obligation — to comply with tax, accounting, and other applicable laws.
4. Subprocessors
We share data only with vendors needed to run the Service. Current subprocessors:
- Clerk — authentication and account management
- OpenRouter and its model providers (including Anthropic) — AI generation of proposal content
- Paddle — payment processing, as merchant of record
- Hetzner (Germany) — application hosting and data storage
- Cloudflare — content delivery and network security
- PostHog (EU Cloud) — product analytics; loaded only with your consent
- Sentry (EU region) — error monitoring; receives technical diagnostics when something breaks. Email, cookies, and authorization headers are scrubbed before transmission.
5. International transfers
Some subprocessors are located outside the EEA. Where required, we rely on Standard Contractual Clauses or equivalent safeguards to protect your data on transfer.
6. Retention
We keep account data for as long as your account is active. When you delete your account, we delete or anonymise personal data within 30 days, except where law requires longer retention (e.g. invoices).
One exception, kept for fraud prevention on the basis of our legitimate interest: if you had used part of the free allowance, we retain an irreversible one-way hash of your email address alongside a count of how much of that allowance was used. It contains no readable personal data and cannot be used to contact you or to recover your account — its only purpose is to stop the free allowance being reset by deleting and re-creating an account. These records are deleted after 24 months.
7. Your rights
If you are in the EEA, UK, or another jurisdiction with comparable laws, you have the right to access, correct, delete, port, or object to the processing of your personal data, and to withdraw consent. Contact us at [email protected] to exercise these rights. You also have the right to lodge a complaint with your local data protection authority.
8. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, scoped access, and audit logging. No service is 100% secure; if we become aware of a breach that affects you, we will notify you in line with applicable law.
9. Changes
We may update this policy. Material changes will be flagged in-product or by email at least 14 days before they take effect.
10. Contact
Privacy questions: [email protected].