Privacy Policy

Learn what information ColabaseAI collects, how we use and protect it, who processes it, how long we retain it, and which privacy rights you can exercise.

2026/05/21

Version: 1.0 · Effective date: 2026-05-21 · Last updated: 2026-05-21

1. About This Policy and Who We Are

This Privacy Policy explains how ColabaseAI ("we", "us", or "our") collects, uses, shares, and protects personal information when you use ColabaseAI (the "Service").

The Service is operated by Shanghai Fortune Singularity Tech Co., Ltd., a company registered in Shanghai, China. We act as the data controller for personal information processed in connection with the Service.

For all privacy-related inquiries, including to exercise the rights described in Section 8, you can contact us at legal@colabase.ai.

This Policy should be read together with our Terms of Service and Cookie Policy.

2. Information We Collect

We collect the following categories of information:

2.1 Information you provide directly

  • Account information: email address, display name, profile image. Where you sign in via Google OAuth, we receive these from Google in accordance with the permissions you grant during sign-in.
  • Payment information: when you make a payment, billing details are collected by our payment provider (Stripe or Creem, depending on your account configuration). We do not store full payment card numbers. We receive metadata about the transaction (such as the amount, currency, transaction ID, and last four digits of the card) for billing, fraud prevention, and customer support purposes.
  • Content you submit: prompts, reference images, generation settings, and other inputs you provide to the Service.
  • Generated content: images and outputs created by the Service in response to your inputs.
  • Communications: messages you send us via email, customer chat (Crisp, where enabled), or support forms.

2.2 Information collected automatically

  • Usage data: pages visited, features used, time spent, model selections, generation metadata.
  • Device and connection data: IP address, browser type, operating system, device identifiers, and approximate geographic location derived from IP address.
  • Logs: API requests, system events, errors, and security-relevant events.
  • Cookies and similar technologies: see our Cookie Policy for details.

2.3 Information from third parties

  • Authentication providers: where you sign in via Google OAuth, Google shares with us the information you authorized.
  • Payment providers: transaction status, dispute and chargeback information, and fraud-prevention signals.
  • Affiliate and analytics services (where enabled): referral source and conversion events.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide and operate the Service: account creation and sign-in, image generation, payment processing, customer support, billing.
  • Secure the Service: detect and prevent fraud, abuse, security incidents, and violations of our Terms of Service. We are implementing CSAM detection and related safety controls with the goal of covering reference image uploads, prompts, and generated outputs.
  • Improve the Service: measure performance, route model selections, analyze cost, evaluate model quality, identify popular use cases.
  • Communicate with you: send service-related notices, respond to your support requests, send transactional emails (for example, password resets, payment receipts).
  • Internal review of generations for potential Gallery features: our operations team may, in limited circumstances, view generations to identify content that may be suitable for future Gallery, marketing, or promotional features. We will not publicly use any of your generations without your separate, explicit consent (see Terms of Service Section 6.3). Where we wish to contact you for this purpose, we use the email address associated with your account.
  • Comply with legal obligations: respond to lawful requests, comply with applicable laws (including China's Interim Measures for the Administration of Generative Artificial Intelligence Services and equivalent rules in other jurisdictions), and defend our legal interests.

We do not currently use your generated images, reference images, or prompts to train AI models. If we ever introduce such use, we will obtain your separate, explicit consent first.

4. Service Providers (Subprocessors)

We use trusted service providers to operate the Service. We require these providers to handle personal information only on our instructions and to apply appropriate security measures.

A summary of the categories of providers we may use is below. The list of providers actually in use at any given time, including their roles and locations, is published at /legal/subprocessors.

Core providers (used by default)

  • Cloudflare (United States / global): infrastructure (Workers, R2 storage, D1 database, CDN, email routing).
  • fal.ai (United States) and the underlying model providers it routes to, which may include OpenAI, depending on the model you select: AI image generation.
  • Stripe (Ireland / United States) or Creem, operated by Armitage Labs OÜ (Estonia), depending on your account configuration: payment processing.
  • Resend (United States): transactional email delivery.
  • Google (United States): OAuth authentication.

Conditional providers (used only where enabled or configured)

  • Crisp (France): in-page customer chat support.
  • Analytics providers, where configured by us: Google Analytics, Microsoft Clarity, Plausible, or Umami.
  • Affiliate and referral providers, where configured by us: Affonso, PromoteKit.
  • Newsletter providers, where configured by us: Resend, Beehiiv.
  • Internal operations notification: Discord and/or Feishu webhooks (used for limited operational alerts that may include user identifiers such as user name, customer id, or session id).

Where required by applicable law, we have entered into appropriate data processing agreements with these providers. Public DPA and privacy resources for each provider are linked from /legal/subprocessors.

5. International Data Transfers

Because we use service providers in various countries, your personal information may be transferred to and processed in countries other than the country where you reside, including the United States, Ireland, Estonia, France, and other jurisdictions where our providers operate.

We rely on appropriate safeguards for these transfers, including contractual measures with our providers.

Notice for users in mainland China. Where required by China's Personal Information Protection Law (PIPL), additional safeguards apply to cross-border transfers of your personal information. We are working towards full implementation of PIPL Article 38 requirements, including (as applicable) standard contractual clauses, security assessments, and separate consent mechanisms. By using the Service while these implementations are in progress, you acknowledge that transfers to providers outside mainland China may occur as described in this Policy.

6. Cookies and Similar Technologies

We use cookies and similar technologies on the Service. For details on the categories of cookies we use, the scripts we load, and how to manage your preferences, please see our Cookie Policy.

We obtain your consent for non-essential cookies before loading them, in accordance with applicable law.

7. Data Retention

We retain personal information for as long as it is needed to provide the Service to you and to fulfill the purposes described in this Policy. Specific retention periods include:

  • Account information: retained for as long as your account is active. After you delete your account, see Section 9.
  • Generated content (images): retained according to the lifecycle described in our Terms of Service. Free-tier images are retained for 30 days from generation; paid-tier images are retained for 1 year from generation, after which they enter a grace period and are eventually archived and purged. Archived images are not served via the public CDN.
  • Reference images: stored privately in our internal storage and retained only as long as needed for the Service, support, security, or the account-deletion lifecycle (see Section 9).
  • Generation metadata (prompt, model, timestamp, cost): retained while your account is active for analytics and reverse-UGC operations. After account deletion, see Section 9.
  • Billing and financial records: retained for up to 7 years, as required by applicable accounting and tax laws.
  • Security and abuse logs: retained for up to 12 months, as required by applicable cybersecurity laws.
  • API call logs: retained for up to 6 months.
  • Consent records for public use of your content: retained for at least 5 years, or longer where the relevant content is still in public display or where there is a dispute, complaint, or pending legal request relating to it.
  • Aggregated, anonymous statistics: retained indefinitely. These do not identify you.

8. Your Rights

Depending on where you live, you may have the following rights with respect to your personal information:

  • Access: you can request a copy of the personal information we hold about you.
  • Rectification: you can ask us to correct inaccurate or incomplete information.
  • Erasure: you can ask us to delete your personal information, subject to applicable exceptions (such as billing, security, and legal-compliance retention described in Section 7).
  • Restriction and objection: you can ask us to restrict or object to certain processing of your personal information.
  • Portability: you can ask us to provide your personal information in a portable, machine-readable format.
  • Withdraw consent: where processing is based on your consent (for example, public use of your content under Section 6.3 of our Terms of Service), you can withdraw it at any time.

To exercise any of these rights, please contact legal@colabase.ai. We will respond within the timeframes required by applicable law.

You also have the right to lodge a complaint with a competent data protection authority in your jurisdiction.

9. Account Deletion

When you submit a request to delete your account, your data is processed in three phases:

  • Day 0 (request received). Your account enters a recovery state. You can cancel the deletion request within the recovery period. The Service is no longer available to you in active mode.
  • Day 30 (end of recovery period). Your generated images are taken offline from the public CDN. Your account is marked for final cleanup.
  • Day 60 (final cleanup). Identifiable personal information (including the link between your user_id and your email, display name, OAuth identifiers, and other directly identifying fields) is deleted. Raw prompts are deleted. Reference images are deleted. Certain row-level metadata (such as model used, use case, aspect ratio, cost, generation month, status, region bucket) is retained in a de-identified form for up to 24 months for cost accounting and product analysis. Aggregated, anonymous statistics are retained indefinitely.

Some data is retained beyond Day 60 where required by law or to defend legal claims: billing and financial records, security and access logs, and consent records relating to public use of your content (see Section 7).

You can submit a deletion request from your account settings (where available) or by emailing legal@colabase.ai.

10. Children's Privacy

The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a child under 18 has provided personal information to us, please contact legal@colabase.ai and we will take appropriate steps to remove it.

11. Security

We use reasonable technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, and destruction. No method of transmission or storage is 100% secure, however, and we cannot guarantee absolute security.

If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law.

12. Changes to This Policy

We will reflect changes by updating the Effective date at the top of this page and recording a corresponding entry in the Changelog below.

For material changes (changes that meaningfully affect the categories of personal information we collect, the purposes for which we use it, with whom we share it, your rights, or the duration we retain it), we will provide reasonable advance notice and may notify you by email, in-product notice, or other reasonable means before the change takes effect.

Non-material changes (clarifications, formatting, typo fixes) will be reflected only by an updated Last updated date.

13. Contact

For privacy questions or to exercise your rights:


Changelog

  • 2026-05-21 · v1.0 — Initial version.