Privacy Policy

Last updated: 17 July 2026

This Privacy Policy explains how Blackace ("we", "us") collects, uses and protects your personal data when you use Blackace (the "Service"). We act as the data controller. We comply with the EU General Data Protection Regulation (GDPR).

1. Data we collect

  • Account data: name, email address, country, sign-in method, and profile picture if you upload one.
  • Content data: the requests, context, messages and instructions you submit, and the text and images generated for you.
  • Billing data: subscription status and history. Card details are collected and stored by Stripe — we never see or store your full card number.
  • Technical data: basic logs needed to operate and secure the Service (for example authentication and error logs).

2. How we use your data

  • to provide the Service and generate the Output you request;
  • to process payments and manage your subscription;
  • to send you service and transactional emails;
  • to secure the Service, prevent abuse and comply with the law;
  • to improve and support the Service;
  • to train, develop and improve our own AI models, agents and features (see "AI processing and training" below).

3. Legal bases

We process your data to perform our contract with you (providing the Service and billing), to comply with legal obligations (for example accounting), and based on our legitimate interests in securing and improving the Service. Where required, we rely on your consent, which you may withdraw at any time.

4. AI processing and training

To generate Output, the content you submit is sent to our AI provider, OpenAI, for processing. OpenAI processes this data as our sub-processor to return results and does not use data submitted through its API to train its models.

We store all of your conversations with our AI agents — including your requests, context, follow-up messages and the Output generated for you — and may use them to train, develop and improve our own AI models, agents and features in the future. Where we use conversation data for training, we take steps to reduce the personal data involved (for example by aggregating or de-identifying it) wherever practical. Please avoid submitting sensitive personal data you do not want stored or used in this way.

5. Service providers (sub-processors)

We share data with trusted providers only as needed to run the Service:

  • OpenAI — AI text and image generation;
  • Supabase — authentication, database and file storage;
  • Stripe — payment processing and billing;
  • Resend — transactional email delivery;
  • Vercel — application hosting.

Some providers may process data outside the EU/EEA; where they do, they rely on appropriate safeguards such as the EU Standard Contractual Clauses. We do not sell your personal data.

6. Data retention

We keep your account and content data for as long as your account is active. When you delete your account, your profile, tasks, conversations and generated images are permanently removed and your subscription is cancelled. Some records (for example billing/accounting records held by Stripe) may be retained where required by law. Conversation data that has already been aggregated or de-identified and incorporated into training datasets or improved models may be retained, as it can no longer be linked back to you.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. You can access and update much of your data in the app, and delete your account from Settings. To exercise any right, contact us at the address below. You also have the right to lodge a complaint with your supervisory authority — in Portugal, the CNPD (www.cnpd.pt).

8. Cookies

We use only the cookies necessary to keep you signed in and to operate the Service securely. We do not use advertising cookies.

9. Security

We use industry-standard measures to protect your data, including access controls, encryption in transit, and database-level isolation so each customer can only access their own data. No method of transmission or storage is completely secure, but we work to protect your information.

10. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children.

11. Changes

We may update this Policy from time to time. If we make material changes, we will notify you before they take effect.

12. Contact

Blackace
Email: legal@blackace.ai