Fenestra Privacy Policy

Last updated October 24, 2025

INTRODUCTION

Your privacy matters to us. Designtree AI LLC ("Fenestra," "we," "us," or "our") is committed to protecting your personal information and being transparent about how we collect, use, and protect your data.

This Privacy Policy explains our practices when you use our AI-powered design platform at https://fenestra.app (the "Platform").

About Fenestra: Designtree AI LLC Sharjah Media City, Sharjah, UAE

Email: shaun@fenestra.dev

Our Core Privacy Principles:

If you have questions about this Policy or our privacy practices, contact us at shaun@fenestra.dev.

1. INFORMATION WE COLLECT

1.1 Information You Provide Directly to Us

Account Information:

We do not collect or store passwords. Fenestra has no password to set or reset: you sign in either through Google, or with a one-time code sent to your email address.

Payment and Billing Information:

When you purchase a subscription, our payment processor (Lemon Squeezy) collects:

Your Creative Content:

When you use the Platform, you provide:

Communications with Us:

When you contact us, we collect:

1.2 Information We Collect Automatically

Technical and Device Information:

When you access the Platform, we automatically collect:

Usage Information:

We collect information about how you use the Platform:

Location Information:

We collect:

Cookies and Similar Technologies:

We use cookies, pixels, and similar tracking technologies to collect:

See Section 6 for detailed information about cookies.

1.3 Information from Third-Party Sources

Social Media Login Data:

If you choose to register or log in using google authentication, we receive limited information from that provider, which may include:

We only use this information for account creation and authentication. The specific information shared depends on your privacy settings with the social media provider.

1.4 Information We Do NOT Collect

We do not knowingly collect:

2. HOW WE USE YOUR INFORMATION

2.1 To Provide and Deliver the Services

We use your information to:

2.2 To Improve and Develop the Platform

We use aggregated and anonymized information to:

Critical Clarification:

We analyze usage metrics such as "80% of users prefer the image generation feature" or "average generation time is 15 seconds." This helps us improve the Platform.

We do NOT use your actual uploaded images, videos, prompts, or generated outputs to train our proprietary AI models or improve third-party AI models. Your creative work is never used as training data.

2.3 To Communicate With You

We use your contact information to:

2.4 For Security, Fraud Prevention, and Compliance

We use your information to:

2.5 For Analytics and Advertising

We use your information to:

You can opt out of advertising cookies through your browser settings or by contacting us.

3. UNDERSTANDING AI PROCESSING ON FENESTRA

3.1 How Your Content Flows Through Our System

When you use Fenestra's AI features, your content goes through several steps. Here's exactly what happens:

Step 1 - You Create or Upload

You either upload an image/video/3D file or write a text prompt describing what you want to create.

Step 2 - Secure Storage in Europe

Your content is immediately stored on:

All data is encrypted both in transit (as it moves between your device and our servers) and at rest (while stored).

Step 3 - AI Processing

When you click "Generate," your content and prompts are sent to specialized third-party AI service providers:

Modal Labs:

Replicate:

Fal.ai:

Runway ML:

Step 4 - Output Delivered to You

3.2 Specific AI Models We Use

Our Platform uses the following AI models, all accessed through third-party API services:

Image Generation and Editing Models:

Video Generation Models:

Other AI Services:

3.3 Third-Party AI Provider Data Practices

Important Information About Third-Party Processing:

When you use AI generation features, your Input Content and prompts are temporarily processed by third-party AI service providers. Here's what you need to know:

Replicate (Primary AI Model Platform):

Fal.ai (AI Model Platform):

Modal Labs:

Runway ML:

Google AI (Nano Banana via Replicate):

Black Forest Labs (FLUX models via Replicate):

Qwen/Alibaba (Image Edit models via Replicate):

ByteDance (Seedance video models via Replicate):

Data Processing Location:

Most third-party AI providers operate infrastructure in the United States. When you use AI generation features, your data may be temporarily transferred to US servers for processing, then outputs are returned to our EU storage.

We ensure appropriate safeguards for these transfers (see Section 5).

3.4 Fenestra's Guarantee to You

We promise that Fenestra does NOT:

Your creative work is yours alone. We are merely providing the infrastructure and tools for you to create it.

4. HOW WE SHARE YOUR INFORMATION

4.1 We Do Not Sell Your Personal Data

Fenestra does not and will never sell, rent, lease, or trade your personal information to third parties for their marketing purposes or any other purpose.

4.2 Service Providers Who Process Data on Our Behalf

We share your information with trusted third-party service providers who help us operate the Platform. These providers are contractually obligated to protect your data and use it only for the purposes we specify.

Cloud Infrastructure and Storage:

Amazon Web Services (AWS)

Supabase

CloudFront (AWS)

AI Processing Services:

Modal Labs

Replicate

Fal.ai

Runway ML

Other AI Service Providers (accessed via Replicate or Modal):

Analytics and Performance Monitoring:

Posthog

Data Fast

Advertising and Marketing:

Meta (Facebook) Pixel

Payment Processing:

Lemon Squeezy

Authentication Services:

If you use social login, we share limited data with:

Google authenticates your identity and shares basic profile information with us as described in Section 1.3. If you sign in with a one-time email code instead, no third-party login provider is involved.

We may disclose your information when required or permitted by law:

We will notify you of legal requests for your data unless legally prohibited from doing so.

4.4 Business Transfers

If Fenestra is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction.

We will:

4.5 Aggregated and De-Identified Data

We may share aggregated, de-identified, or anonymized data that cannot reasonably identify you, including:

This data cannot be used to identify you personally and is not considered personal information under data protection laws.

We may share your information with third parties when you explicitly consent to such sharing, such as:

5. INTERNATIONAL DATA TRANSFERS

5.1 Where Your Data is Primarily Stored

Your data is primarily stored in the European Union for privacy protection and GDPR compliance:

5.2 Data Transfers Outside the EU/UK

Some of our service providers operate from or use servers located outside the European Economic Area and United Kingdom, particularly in the United States:

Services Likely Operating from US Infrastructure:

When you use AI generation features, your content is temporarily transferred to these providers' servers for processing (typically seconds to minutes), then outputs are returned to our EU storage. Input data is automatically deleted by AI processors after processing (1 hour to 7 days maximum retention).

5.3 How We Protect International Transfers

For data transfers from the EU/UK to countries that do not provide an adequate level of data protection (such as the United States), we implement appropriate safeguards as required by UK GDPR and EU GDPR:

Legal Mechanisms:

Technical and Organizational Measures:

Transparency:

5.4 Your Rights Regarding International Transfers

If you are in the UK, EU, or Switzerland, you have the right to:

To exercise these rights or request documentation of international transfer safeguards, contact shaun@fenestra.dev.

6. COOKIES AND TRACKING TECHNOLOGIES

6.1 What Are Cookies and Why We Use Them

Cookies are small text files stored on your device when you visit websites. We use cookies and similar technologies (pixels, web beacons, local storage) to:

6.2 Types of Cookies We Use

Essential Cookies (Always Active - Cannot Be Disabled):

These cookies are strictly necessary for the Platform to function:

Without these cookies, core features of the Platform would not work.

Analytics Cookies (Can Be Controlled):

These cookies help us understand and improve the Platform:

Posthog analytics - Tracks which features you use, how long you spend, navigation patterns. Collects anonymized or pseudonymized data to help us improve user experience, fix bugs, and develop new features.

Data Fast analytics - Monitors Platform performance and identifies technical issues. Helps us optimize loading speeds and identify errors.

These cookies collect anonymized or pseudonymized data. We use insights to improve user experience but cannot directly identify you from this data alone.

Advertising Cookies (Can Be Controlled):

These cookies are used for marketing and advertising:

Meta Pixel - Tracks conversions from Facebook/Instagram ads, enables retargeting to show you relevant ads on social media platforms, measures ad campaign effectiveness. Helps us understand which marketing channels work best and optimize advertising spend.

These cookies help us show you relevant ads and understand ROI on marketing investments.

Preference Cookies (Can Be Controlled):

These cookies remember your choices:

Managing Cookies:

You can control cookies through:

Browser Settings: Most browsers allow you to:

Check your browser's help section for instructions (usually found in Settings > Privacy or Security). Note that blocking essential cookies will prevent you from using core Platform features like logging in and saving your work.

Cookie Consent Preferences:

For UK and EU users, we obtain your consent before placing non-essential cookies (analytics and advertising). You can manage your preferences through the cookie consent banner that appears when you first visit the Platform.

Opt-Out of Advertising:

6.4 Do-Not-Track Signals

Some browsers offer "Do-Not-Track" (DNT) signals that request websites not to track browsing activity. Currently, there is no universal standard for how websites should respond to DNT signals.

We currently do not respond to DNT browser signals. If a standardized DNT protocol is established in the future and becomes legally required or widely adopted, we will update our practices accordingly and notify you through this Privacy Policy.

7. DATA RETENTION AND DELETION

7.1 How Long We Keep Your Data

While Your Account is Active:

We retain your account information, Input Content, and Output Content for as long as your account remains active and you wish to keep it. There is no automatic deletion of inactive accounts - your data remains available until you request deletion.

7.2 When You Request Deletion of Specific Content

If you request deletion of individual images, videos, or projects by contacting shaun@fenestra.dev:

7.3 When You Request Account Deletion

If you request full account deletion by emailing shaun@fenestra.dev:

Within 30 days:

Typically within 90 days:

May be retained longer (only as required by law):

We will confirm completion of deletion via email once the process is complete.

7.4 Third-Party AI Provider Retention

Your data processed by third-party AI services is retained as follows:

This means your content does not remain on third-party AI servers after processing is complete. The automatic deletion is enforced by the AI providers' systems and does not require any action from you.

7.5 Inactive Accounts

Currently, we do not automatically delete inactive accounts. Your account and content remain available indefinitely until you request deletion.

If you no longer use Fenestra, we recommend requesting account deletion by emailing shaun@fenestra.dev to remove your data from our systems.

8. HOW WE PROTECT YOUR DATA

8.1 Technical Security Measures

We implement industry-standard security measures to protect your data:

Encryption:

Access Controls:

Infrastructure Security:

Application Security:

8.2 Organizational Security Measures

Personnel:

Processes:

8.3 Third-Party Provider Security

Our infrastructure providers maintain enterprise-grade security standards:

Amazon Web Services (AWS):

Supabase:

Modal Labs:

8.4 Limitations and Risks

Important Disclosure:

Despite our security measures and those of our service providers, no method of transmission over the internet or electronic storage is 100% secure. We cannot and do not guarantee absolute security.

Risks include:

You transmit data to and from the Platform at your own risk. We strongly recommend:

8.5 Security Breach Notification

In the unlikely event of a security breach that affects your personal information:

We will:

You should:

We take security incidents very seriously and will work diligently to protect your information and minimize any harm.

9. YOUR PRIVACY RIGHTS

The privacy rights available to you depend on where you live. This section explains your rights under various privacy laws around the world.

9.1 Rights for UK and EU Users (UK GDPR / EU GDPR)

If you are located in the United Kingdom, European Economic Area, or Switzerland, you have the following rights under data protection law:

Right of Access (Article 15 GDPR):

You can request a copy of the personal data we hold about you. We will provide:

Right to Rectification (Article 16 GDPR):

You can request correction of inaccurate or incomplete personal data. We will update or correct your information promptly upon verification of the correct information.

Right to Erasure / "Right to be Forgotten" (Article 17 GDPR):

You can request deletion of your personal data in certain circumstances:

We will delete your data unless we have a legal obligation to retain it (such as for tax records, legal proceedings, or regulatory compliance).

Right to Restrict Processing (Article 18 GDPR):

You can request that we limit how we use your data in certain situations:

When processing is restricted, we will store the data but not use it further without your consent (except for legal claims, protecting another person's rights, or important public interests).

Right to Data Portability (Article 20 GDPR):

You can request to receive your personal data in a structured, commonly used, machine-readable format and have the right to transmit that data to another service provider.

We will provide:

This right applies to data you provided to us and where processing is based on consent or contract and carried out by automated means.

Right to Object (Article 21 GDPR):

You can object to:

Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR):

If we make any significant decisions about you based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you, we will:

Currently, we do not make automated decisions that have legal or similarly significant effects on you. AI content generation is based on your explicit requests and creative direction, not automated profiling decisions.

Right to Withdraw Consent:

Where our processing is based on your consent (such as marketing emails or non-essential cookies), you can withdraw that consent at any time. Withdrawal is simple:

Withdrawing consent does not affect the lawfulness of processing that occurred before consent was withdrawn.

Right to Lodge a Complaint:

If you believe we have violated your privacy rights or mishandled your personal data, you can file a complaint with your supervisory authority:

United Kingdom: Information Commissioner's Office (ICO)

Website: ico.org.uk Phone: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

EU Member States: Your national Data Protection Authority Directory: edpb.europa.eu/about-edpb/about-edpb/members_en

Switzerland: Federal Data Protection and Information Commissioner (FDPIC) Website: edoeb.admin.ch

We encourage you to contact us first at shaun@fenestra.dev so we can address your concerns directly. We take privacy complaints seriously and will work to resolve issues promptly.

9.2 Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Right to Know:

You can request information about:

We will provide this information for the 12-month period preceding your request.

Right to Delete:

You can request deletion of your personal information that we have collected from you, subject to certain exceptions allowed by law such as:

Right to Correct:

You can request correction of inaccurate personal information we maintain about you. We will use commercially reasonable efforts to correct the information upon verification.

Right to Opt-Out:

You can opt out of:

To opt out, contact shaun@fenestra.dev or adjust cookie settings in your browser.

Right to Limit Use of Sensitive Personal Information:

We do not collect or process sensitive personal information as defined by CCPA (such as precise geolocation, racial or ethnic origin, religious beliefs, genetic data, biometric data, health data, sex life, or sexual orientation).

Right to Non-Discrimination:

We will not discriminate against you for exercising your CCPA rights. We will not:

However, we may offer financial incentives permitted by law that can result in different prices, rates, or quality levels. Any such incentives will be reasonably related to the value of your personal information.

Authorized Agents:

You may designate an authorized agent to make requests on your behalf. The authorized agent must:

We may deny requests from authorized agents who do not submit proof of valid authorization.

9.3 Rights for Residents of Other US States

If you reside in Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have similar privacy rights under your state's privacy laws.

These generally include rights to:

Specific rights and procedures may vary slightly by state. Contact shaun@fenestra.dev to exercise rights under your state's privacy law.

9.4 Rights for Australian and New Zealand Users

Under Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020:

Right to Access:

Right to Correction:

Right to Complain:

If we deny a request for access or correction, we will provide you with written reasons for the denial and information about how to complain.

9.5 How to Exercise Your Privacy Rights

To exercise any of the rights described above:

Email us at: shaun@fenestra.dev

Subject line: "Privacy Rights Request"

Include in your request:

Our Response Process:

Verification:

To protect your privacy and ensure we provide information only to the correct person, we must verify your identity before processing requests. We may ask you to:

We will only use the information provided in your request to verify your identity and process the request. We will not use it for any other purpose.

Authorized Agents:

You may authorize another person or entity to submit privacy requests on your behalf. The authorized agent must:

For California residents, we may require the authorized agent to provide a power of attorney or we may require you to directly confirm with us that you provided the agent authorization.

9.6 Opting Out of Marketing Communications

To stop receiving marketing and promotional emails from Fenestra:

You will be removed from marketing lists within 10 business days.

Note: You will continue to receive essential service-related communications such as:

These transactional emails cannot be opted out of while you maintain an active account, as they are necessary for us to provide the Services and fulfill our contract with you.

10. CHILDREN'S PRIVACY

10.1 Age Restriction

The Platform is not intended for, and we do not knowingly collect personal information from, anyone under the age of 18.

By using the Platform, you represent and warrant that you are at least 18 years old or the age of majority in your jurisdiction, whichever is greater.

10.2 If We Discover a Child's Information

If we become aware that we have inadvertently collected personal information from someone under 18 without proper parental consent:

10.3 Parental Notice

If you are a parent or guardian and believe your child under 18 has provided personal information to Fenestra without your consent, please contact us immediately at shaun@fenestra.dev with "Underage Account" in the subject line.

We will promptly investigate and take appropriate action, including account deletion and data removal. Please provide:

If you are located in the United Kingdom, European Economic Area, or Switzerland, data protection law requires us to have a valid legal basis for processing your personal information.

We rely on the following legal bases under Article 6 of the UK GDPR and EU GDPR:

11.1 Contractual Necessity (Article 6(1)(b) GDPR)

Processing is necessary to perform our contract with you (the Terms and Conditions) and provide the Platform services you have subscribed to, including:

Without this processing, we cannot provide the Services to you.

11.2 Consent (Article 6(1)(a) GDPR)

Where you have given us explicit, informed, and freely-given consent to process your personal data for specific purposes:

You can withdraw your consent at any time by:

Withdrawing consent does not affect the lawfulness of processing that occurred before consent was withdrawn. It also does not affect processing based on other legal grounds (such as contractual necessity).

11.3 Legitimate Interests (Article 6(1)(f) GDPR)

We process data when necessary for our legitimate business interests, provided those interests do not override your fundamental rights and freedoms:

Platform Security and Fraud Prevention:

Our legitimate interest: Protecting our Platform, users, and business from security threats and fraud.

Service Improvement:

Our legitimate interest: Improving our Platform to better serve users and remain competitive.

Business Operations:

Our legitimate interest: Operating a sustainable and efficient business.

Direct Marketing to Existing Customers:

Our legitimate interest: Informing existing customers about relevant Platform developments.

Before relying on legitimate interests, we conduct a balancing test to ensure our interests do not override your rights and freedoms. We ensure processing is necessary, proportionate, and that you have appropriate safeguards and opt-out rights.

11.4 Legal Obligation (Article 6(1)(c) GDPR)

We process data where required to comply with legal or regulatory obligations under EU or UK law:

11.5 Vital Interests (Article 6(1)(d) GDPR)

In rare and exceptional circumstances, we may process data to protect vital interests:

This legal basis is used only when strictly necessary and other legal bases are not appropriate.

12. CHANGES TO THIS PRIVACY POLICY

12.1 When We Update This Policy

We may update this Privacy Policy from time to time to reflect:

12.2 How We Notify You of Changes

When we make changes to this Privacy Policy:

What constitutes a "material change":

12.3 Your Acceptance of Changes

Continued use of the Platform after the effective date of changes constitutes your acceptance of the revised Privacy Policy.

If you do not agree with changes:

We encourage you to review this Privacy Policy periodically (we recommend at least annually or when you receive a change notification) to stay informed about our privacy practices and your rights.

13. CONTACT US

13.1 Privacy Questions and Requests

For questions about this Privacy Policy or to exercise your privacy rights:

Email: shaun@fenestra.dev

Subject Line: "Privacy Inquiry" or "Privacy Rights Request"

Postal Address: Designtree AI LLC Sharjah Media City Sharjah, United Arab Emirates

13.2 Data Protection Inquiries

For inquiries specifically related to UK or EU data protection compliance, GDPR questions, or international data transfers, you may direct correspondence to the email address above with subject line "GDPR Inquiry" or "Data Protection Question."

13.3 Response Time

We aim to respond to:

13.4 What to Include in Your Request

To help us process your request efficiently and verify your identity:

13.5 Complaints and Concerns

If you have concerns about how we handle your personal information, please contact us first at shaun@fenestra.dev. We take privacy concerns seriously and will work to resolve issues promptly and transparently.

We will:

If you are not satisfied with our response, you have the right to contact your local data protection authority:

APPENDIX A: TECHNICAL DATA PROCESSING DETAILS

This appendix provides detailed technical information for enterprise customers, compliance officers, IT professionals, and those conducting vendor security assessments.

A.1 Data Storage Infrastructure

Primary Storage Infrastructure:

Component: Content Storage (Images, Videos, 3D Files, AI Outputs)

Component: Database (Account Data, Metadata, File References)

Component: Content Delivery Network

Component: Backup Storage

A.2 AI Processing Services - Detailed Data Flow

Service: Replicate

Service: Fal.ai

Service: Modal Labs

Service: Runway ML

Service: Google AI (Nano Banana / Gemini 2.5 Flash Image)

A.3 Analytics and Advertising Services

Service: Posthog

Service: Data Fast

Service: Meta Pixel (Facebook/Instagram)

A.4 Payment Processing

Service: Lemon Squeezy

A.5 Data Processing Agreements

For enterprise customers conducting vendor security assessments or requiring formal documentation:

Available Documentation:

To Request: Email shaun@fenestra.dev with subject "Enterprise Compliance Documentation"

A.6 Data Categories and Retention Schedules

Personal Data CategoryData ElementsLegal BasisRetentionDeletion
Account IdentifiersName, email address, account IDContractual necessity, consentWhile account is activeWithin 30 days of account deletion request
Payment InformationBilling address, transaction history (card details stored by Lemon Squeezy only)Contractual necessity, legal obligationTransaction records retained for 7 years for tax complianceTransaction records retained per legal requirements even after account deletion
User Content (Uploads)Images, videos, 3D files uploaded by userContractual necessityWhile account is active or until user requests deletionRemoved from active systems within 30 days, purged from backups typically within 90 days
AI-Generated Content (Outputs)Images, videos, 3D models generated by AI at user's requestContractual necessityWhile account is active or until user requests deletionRemoved from active systems within 30 days, purged from backups typically within 90 days
Usage DataIP address, browser type, device info, feature usage, clicks, page viewsLegitimate interests (security, improvement)Active logs for 12 months, aggregated anonymized data may be retained indefinitelyCan be deleted upon request; anonymized aggregated data retained
CommunicationsSupport tickets, email correspondence, feedbackContractual necessity, legitimate interestsFor duration of issue resolution plus 12 monthsDeleted upon request after issue is resolved (unless required for legal purposes)
Marketing PreferencesEmail marketing consent status, communication preferencesConsentWhile account is active or until consent is withdrawnImmediately upon opt-out or account deletion

A.7 Security Incident Response Procedures

In the event of a security incident or personal data breach:

Detection Phase (0-24 hours):

Containment Phase (24-48 hours):

Notification Phase (Within 72 hours):

Remediation Phase (Ongoing):

Users will be kept informed throughout the process and provided with regular updates on remediation progress.