Your privacy matters to us. Designtree AI LLC ("Fenestra," "we," "us," or "our") is committed to protecting your personal information and being transparent about how we collect, use, and protect your data.
This Privacy Policy explains our practices when you use our AI-powered design platform at https://fenestra.app (the "Platform").
About Fenestra: Designtree AI LLC Sharjah Media City, Sharjah, UAE
Transparency: We clearly explain what we do with your data
User Control: You decide what to share and can request deletion of your data anytime
No Training on Your Work: We do not use your creative content to train AI models
Security First: We protect your data with industry-standard security measures
Global Compliance: We follow UK GDPR, EU GDPR, CCPA, and international data protection standards
If you have questions about this Policy or our privacy practices, contact us at shaun@fenestra.dev.
1. INFORMATION WE COLLECT
1.1 Information You Provide Directly to Us
Account Information:
When you create a Fenestra account using Google authentication, we receive:
Your name (provided by Google from your profile)
Email address (provided by Google)
Profile picture (optional, from Google)
When you create a Fenestra account using email sign-in, we receive:
Your email address, to which we send a one-time sign-in code
We do not collect or store passwords. Fenestra has no password to set or reset: you sign in either through Google, or with a one-time code sent to your email address.
Payment and Billing Information:
When you purchase a subscription, our payment processor (Lemon Squeezy) collects:
Payment card details (we do not store complete card numbers on our servers)
Billing address
Transaction and purchase history
Your Creative Content:
When you use the Platform, you provide:
Images you upload for editing or as reference
Videos you upload for processing
3D model files you upload
Text prompts you write for AI generation
Project files, folders, and organizational data
Titles, descriptions, and metadata you add
Communications with Us:
When you contact us, we collect:
Support requests and correspondence
Feedback, questions, and survey responses
Your communication preferences (marketing opt-ins/opt-outs)
1.2 Information We Collect Automatically
Technical and Device Information:
When you access the Platform, we automatically collect:
IP address (used to determine approximate location)
Browser type and version
Device type and operating system
Screen resolution and device identifiers
Referring website or source
Date and time of access
Usage Information:
We collect information about how you use the Platform:
Pages and features you visit and use
Time spent on different pages
Which AI generation features you use most frequently
Number of images/videos generated
Credit usage and consumption patterns
Search queries within the Platform
Clicks, interactions, and navigation patterns
Error logs and diagnostic information
Location Information:
We collect:
Approximate location derived from your IP address (city and country level)
We do NOT collect precise GPS location data
Cookies and Similar Technologies:
We use cookies, pixels, and similar tracking technologies to collect:
Session information for authentication
User preferences and settings
Analytics data about Platform usage
Advertising effectiveness metrics
See Section 6 for detailed information about cookies.
1.3 Information from Third-Party Sources
Social Media Login Data:
If you choose to register or log in using google authentication, we receive limited information from that provider, which may include:
Your name
Email address
Profile picture
Public profile information as permitted by the provider's privacy settings
We only use this information for account creation and authentication. The specific information shared depends on your privacy settings with the social media provider.
1.4 Information We Do NOT Collect
We do not knowingly collect:
Sensitive personal data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, or data concerning sex life or sexual orientation
Financial information beyond what is necessary for billing (payment processing is handled entirely by Lemon Squeezy)
Government-issued identification numbers, social security numbers, or passport numbers (except where legally required for tax compliance, handled by payment processor)
Precise geolocation data (GPS coordinates)
Information from children under 18 years of age
2. HOW WE USE YOUR INFORMATION
2.1 To Provide and Deliver the Services
We use your information to:
Create, maintain, and authenticate your user account
Process your AI generation requests (images, videos, 3D models)
Store and organize your projects and creative content
Process subscription payments and manage billing
Provide customer support and respond to your inquiries
Send you important service-related notifications (one-time sign-in codes, security alerts, billing confirmations)
Deliver the features and functionality you request
2.2 To Improve and Develop the Platform
We use aggregated and anonymized information to:
Analyze usage patterns to understand which features are most valuable
Identify and fix technical bugs, errors, and performance issues
Optimize Platform speed, reliability, and user experience
Conduct internal research and development for new features
Test new AI models and capabilities
Critical Clarification:
We analyze usage metrics such as "80% of users prefer the image generation feature" or "average generation time is 15 seconds." This helps us improve the Platform.
We do NOT use your actual uploaded images, videos, prompts, or generated outputs to train our proprietary AI models or improve third-party AI models. Your creative work is never used as training data.
2.3 To Communicate With You
We use your contact information to:
Send service-related notifications (account updates, new features, security alerts)
Respond to your support requests and questions
Notify you of changes to our Terms, Privacy Policy, or pricing
Send marketing and promotional emails (only with your consent - you can opt out anytime)
Request feedback about your experience with Fenestra
Conduct user research and surveys (optional participation)
2.4 For Security, Fraud Prevention, and Compliance
We use your information to:
Detect and prevent fraudulent activity, unauthorized access, or abuse
Monitor for violations of our Terms and Conditions
Enforce our policies and protect our legal rights
Comply with legal obligations, court orders, and regulatory requirements
Investigate security incidents or suspected illegal activity
Maintain audit logs for security purposes
2.5 For Analytics and Advertising
We use your information to:
Understand how users interact with the Platform through analytics tools (Posthog, Data Fast)
Measure the effectiveness of our marketing campaigns
Deliver relevant advertising through Meta Pixel on Facebook and Instagram
Generate de-identified, aggregated statistics for business planning
Optimize our marketing spend and user acquisition strategies
You can opt out of advertising cookies through your browser settings or by contacting us.
3. UNDERSTANDING AI PROCESSING ON FENESTRA
3.1 How Your Content Flows Through Our System
When you use Fenestra's AI features, your content goes through several steps. Here's exactly what happens:
Step 1 - You Create or Upload
You either upload an image/video/3D file or write a text prompt describing what you want to create.
Step 2 - Secure Storage in Europe
Your content is immediately stored on:
Amazon Web Services (AWS) S3 cloud storage - London, UK region (eu-west-2)
Supabase database - AWS Ireland region (eu-west-1) for metadata and file references
All data is encrypted both in transit (as it moves between your device and our servers) and at rest (while stored).
Step 3 - AI Processing
When you click "Generate," your content and prompts are sent to specialized third-party AI service providers:
Modal Labs:
Purpose: Fenestra's internal AI rendering and image processing service
What happens: Processes your request and returns generated output to our AWS storage
Data retention: Inputs and outputs deleted after maximum 7 days
Training: Does not use your inputs to train models
Certification: SOC 2 Type 2 certified
Replicate:
Purpose: Hosts and executes various AI models from multiple providers
What happens: Receives your input, runs the AI model you selected, returns output to our AWS storage
Data retention: Inputs and outputs automatically deleted after 1 hour for API users
Training: Does not use your inputs to train models
Fal.ai:
Purpose: AI model hosting and execution platform for various generative AI models
What happens: Receives your input, runs the selected AI model, returns output to our AWS storage
Data retention: Inputs and outputs automatically deleted after 1 hour for API users
Training: Does not use your inputs to train models
Important Information About Third-Party Processing:
When you use AI generation features, your Input Content and prompts are temporarily processed by third-party AI service providers. Here's what you need to know:
Replicate (Primary AI Model Platform):
Hosts multiple AI models from various providers
API usage: Automatically deletes all inputs, outputs, and logs after 1 hour
Verification: Confirmed through Google Gemini API Additional Terms of Service
Black Forest Labs (FLUX models via Replicate):
Model Access: Commercial use permitted when accessed via Replicate's paid API (which Fenestra uses)
Generated Outputs: Full commercial use rights - no restrictions
User Rights: You own all outputs created with FLUX models
Verification: Confirmed through FLUX license documentation and Replicate commercial terms
Qwen/Alibaba (Image Edit models via Replicate):
Apache 2.0 license (open source)
Full commercial use permitted for both model and outputs
No licensing fees or restrictions
Verification: Confirmed through Qwen licensing documentation
ByteDance (Seedance video models via Replicate):
Commercial use of generated videos explicitly permitted
Users retain full ownership and rights
No training on user inputs
Verification: Confirmed through multiple sources including fal.ai documentation
Data Processing Location:
Most third-party AI providers operate infrastructure in the United States. When you use AI generation features, your data may be temporarily transferred to US servers for processing, then outputs are returned to our EU storage.
We ensure appropriate safeguards for these transfers (see Section 5).
3.4 Fenestra's Guarantee to You
We promise that Fenestra does NOT:
Use your uploaded images, videos, or 3D files to train AI models
Use your text prompts to train AI models
Use your AI-generated outputs to train AI models
Share your content with AI providers for any purpose beyond processing your specific generation request
Retain your content on third-party AI servers beyond necessary processing time (1 hour to 7 days maximum)
Your creative work is yours alone. We are merely providing the infrastructure and tools for you to create it.
4. HOW WE SHARE YOUR INFORMATION
4.1 We Do Not Sell Your Personal Data
Fenestra does not and will never sell, rent, lease, or trade your personal information to third parties for their marketing purposes or any other purpose.
4.2 Service Providers Who Process Data on Our Behalf
We share your information with trusted third-party service providers who help us operate the Platform. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
Cloud Infrastructure and Storage:
Amazon Web Services (AWS)
Purpose: Cloud storage for uploaded content and generated outputs
Location: London, UK (eu-west-2) and Ireland (eu-west-1)
What they receive: Your files, images, videos, 3D models
If you use social login, we share limited data with:
Google (if you use Google login)
Google authenticates your identity and shares basic profile information with us as described in Section 1.3. If you sign in with a one-time email code instead, no third-party login provider is involved.
4.3 Legal and Regulatory Disclosures
We may disclose your information when required or permitted by law:
To comply with legal obligations, court orders, subpoenas, or regulatory requests
To protect our rights, property, or safety, or that of our users or the public
To investigate, prevent, or take action regarding suspected fraud, security incidents, illegal activity, or violations of our Terms
To enforce our Terms and Conditions or other agreements
In connection with legal proceedings, litigation, or regulatory investigations
We will notify you of legal requests for your data unless legally prohibited from doing so.
4.4 Business Transfers
If Fenestra is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction.
We will:
Notify you via email or prominent notice on the Platform before your information is transferred
Ensure any acquiring entity honors this Privacy Policy or obtains your consent for changes
Provide you the option to request deletion of your account before the transfer if you object
4.5 Aggregated and De-Identified Data
We may share aggregated, de-identified, or anonymized data that cannot reasonably identify you, including:
Platform usage statistics ("Fenestra users generated 1 million images last month")
Performance benchmarks and metrics
Industry research and trend analysis
Marketing and promotional materials
This data cannot be used to identify you personally and is not considered personal information under data protection laws.
4.6 With Your Explicit Consent
We may share your information with third parties when you explicitly consent to such sharing, such as:
Participating in partnership programs
Integrating with third-party design tools or platforms
Publishing your work in showcases, galleries, or promotional materials (only with your express written permission)
5. INTERNATIONAL DATA TRANSFERS
5.1 Where Your Data is Primarily Stored
Your data is primarily stored in the European Union for privacy protection and GDPR compliance:
Primary content storage: AWS S3 - London, United Kingdom (eu-west-2)
Database storage: Supabase on AWS Ireland (eu-west-1)
Backups: EU-based AWS regions
5.2 Data Transfers Outside the EU/UK
Some of our service providers operate from or use servers located outside the European Economic Area and United Kingdom, particularly in the United States:
Services Likely Operating from US Infrastructure:
Modal Labs (US-based company) - hosts Fenestra's internal AI processing service
Replicate (US-based company) - AI model hosting platform
Runway ML (US-based company) - video generation API service
Google AI services (global infrastructure, primarily US-based)
Posthog analytics (US-based company)
Data Fast analytics (location varies)
Meta Pixel (US-based Facebook/Meta infrastructure)
Fal.ai (US-based company) - AI model hosting platform
When you use AI generation features, your content is temporarily transferred to these providers' servers for processing (typically seconds to minutes), then outputs are returned to our EU storage. Input data is automatically deleted by AI processors after processing (1 hour to 7 days maximum retention).
5.3 How We Protect International Transfers
For data transfers from the EU/UK to countries that do not provide an adequate level of data protection (such as the United States), we implement appropriate safeguards as required by UK GDPR and EU GDPR:
Legal Mechanisms:
Standard Contractual Clauses (SCCs) approved by the European Commission for EU-US data transfers
Data Processing Agreements with all processors handling EU/UK personal data
Adequacy decisions where applicable (for countries deemed adequate by EU Commission)
Technical and Organizational Measures:
Encryption of data in transit (TLS 256-bit encryption) and at rest (AES-256 encryption)
Access controls and multi-factor authentication requirements
Limited data retention by processors (1 hour to 7 days automatic deletion)
Regular security audits of service providers
Contractual commitments requiring processors to maintain data protection standards equivalent to GDPR
Transparency:
We select AI processing providers who automatically delete customer data after processing
Processing is limited to what is strictly necessary to generate requested outputs
Data does not remain on third-party AI servers beyond processing time
5.4 Your Rights Regarding International Transfers
If you are in the UK, EU, or Switzerland, you have the right to:
Request detailed information about the safeguards we use for international transfers
Obtain a copy of the Standard Contractual Clauses or other transfer mechanisms in place
Object to specific international transfers if you believe adequate protection is not in place
Contact your local data protection authority with concerns about international transfers
To exercise these rights or request documentation of international transfer safeguards, contact shaun@fenestra.dev.
6. COOKIES AND TRACKING TECHNOLOGIES
6.1 What Are Cookies and Why We Use Them
Cookies are small text files stored on your device when you visit websites. We use cookies and similar technologies (pixels, web beacons, local storage) to:
Keep you logged in to your account
Remember your preferences and settings
Understand how you use the Platform so we can improve it
Measure advertising effectiveness
Provide security features and prevent fraud
6.2 Types of Cookies We Use
Essential Cookies (Always Active - Cannot Be Disabled):
These cookies are strictly necessary for the Platform to function:
User authentication and session management
Security features and fraud detection
Load balancing and platform functionality
Remembering items in your workspace
Without these cookies, core features of the Platform would not work.
Analytics Cookies (Can Be Controlled):
These cookies help us understand and improve the Platform:
Posthog analytics - Tracks which features you use, how long you spend, navigation patterns. Collects anonymized or pseudonymized data to help us improve user experience, fix bugs, and develop new features.
Data Fast analytics - Monitors Platform performance and identifies technical issues. Helps us optimize loading speeds and identify errors.
These cookies collect anonymized or pseudonymized data. We use insights to improve user experience but cannot directly identify you from this data alone.
Advertising Cookies (Can Be Controlled):
These cookies are used for marketing and advertising:
Meta Pixel - Tracks conversions from Facebook/Instagram ads, enables retargeting to show you relevant ads on social media platforms, measures ad campaign effectiveness. Helps us understand which marketing channels work best and optimize advertising spend.
These cookies help us show you relevant ads and understand ROI on marketing investments.
Preference Cookies (Can Be Controlled):
These cookies remember your choices:
Language preferences
Display settings (dark mode, layout preferences)
Feature customizations
Recently used tools or settings
6.3 Your Cookie Choices and Controls
Managing Cookies:
You can control cookies through:
Browser Settings: Most browsers allow you to:
Block all cookies
Block third-party cookies only
Delete cookies after each session
Receive notifications before cookies are set
Check your browser's help section for instructions (usually found in Settings > Privacy or Security). Note that blocking essential cookies will prevent you from using core Platform features like logging in and saving your work.
Cookie Consent Preferences:
For UK and EU users, we obtain your consent before placing non-essential cookies (analytics and advertising). You can manage your preferences through the cookie consent banner that appears when you first visit the Platform.
Some browsers offer "Do-Not-Track" (DNT) signals that request websites not to track browsing activity. Currently, there is no universal standard for how websites should respond to DNT signals.
We currently do not respond to DNT browser signals. If a standardized DNT protocol is established in the future and becomes legally required or widely adopted, we will update our practices accordingly and notify you through this Privacy Policy.
7. DATA RETENTION AND DELETION
7.1 How Long We Keep Your Data
While Your Account is Active:
We retain your account information, Input Content, and Output Content for as long as your account remains active and you wish to keep it. There is no automatic deletion of inactive accounts - your data remains available until you request deletion.
7.2 When You Request Deletion of Specific Content
If you request deletion of individual images, videos, or projects by contacting shaun@fenestra.dev:
Content is removed from active systems within 24-48 hours
Content becomes inaccessible to you and to us immediately upon removal
Content is permanently deleted from backup systems in accordance with our backup rotation schedule, typically within 90 days
Your personal information is deleted from active databases
All Input Content and Output Content is removed from active storage
Your account becomes completely inaccessible
Typically within 90 days:
Content is purged from backup systems in accordance with our backup rotation schedule
All copies are permanently deleted from backup archives
May be retained longer (only as required by law):
Transaction records and billing history (up to 7 years for tax and accounting compliance as required by applicable law)
Information necessary for ongoing legal disputes, regulatory investigations, or compliance with legal holds
De-identified analytics data that cannot identify you personally (may be retained indefinitely)
We will confirm completion of deletion via email once the process is complete.
7.4 Third-Party AI Provider Retention
Your data processed by third-party AI services is retained as follows:
Replicate: Automatically deleted after 1 hour for API usage (verified through Replicate's data retention documentation)
Modal Labs: Automatically deleted after 7 days maximum (verified through Modal's security documentation)
Runway ML: Temporary processing only, not retained after processing is complete
Google (via paid API): Not retained for training purposes when accessed through commercial API services
This means your content does not remain on third-party AI servers after processing is complete. The automatic deletion is enforced by the AI providers' systems and does not require any action from you.
7.5 Inactive Accounts
Currently, we do not automatically delete inactive accounts. Your account and content remain available indefinitely until you request deletion.
If you no longer use Fenestra, we recommend requesting account deletion by emailing shaun@fenestra.dev to remove your data from our systems.
8. HOW WE PROTECT YOUR DATA
8.1 Technical Security Measures
We implement industry-standard security measures to protect your data:
Encryption:
All data encrypted in transit using TLS/SSL protocols (TLS 1.2 or higher with 256-bit encryption)
All data encrypted at rest using AWS S3 server-side encryption (AES-256 encryption standard)
Database encryption through Supabase security features
No password storage of any kind - authentication is handled through Google sign-in or a one-time code sent to your email, so there are no passwords or password hashes held on our systems
Access Controls:
Role-based access control (RBAC) limiting employee access to only what is necessary for their role
Multi-factor authentication required for administrative access to systems
Principle of least privilege (employees only access what's necessary for their specific job function)
Regular access audits and reviews to ensure appropriate access levels
Immediate access revocation upon employee departure
Infrastructure Security:
Automated security monitoring and threat detection systems
Regular vulnerability scanning and security assessments
Intrusion detection and prevention systems (IDS/IPS)
DDoS (Distributed Denial of Service) protection and mitigation
Automated backup systems with geographic redundancy
Firewall protection and network segmentation
Application Security:
Secure coding practices and mandatory code reviews
Regular security updates and patch management
Input validation and sanitization to prevent injection attacks
Protection against common web vulnerabilities (SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF))
Security testing and penetration testing by third-party security experts
Secure API design and authentication mechanisms
8.2 Organizational Security Measures
Personnel:
Background checks for employees with access to customer data (where legally permissible)
Confidentiality and non-disclosure agreements with all staff and contractors
Regular security awareness training for all team members
Strict policies governing data access, handling, and disclosure
Clear incident response roles and responsibilities
Processes:
Documented security incident response plan and procedures
Regular security audits and compliance assessments
Vendor security assessments before integration of new service providers
Change management and approval processes for infrastructure changes
Security review for new features before deployment
Regular backup testing and disaster recovery drills
SOC 2 Type 2 certified (independent annual security audits)
ISO 27001 certified (international information security management standard)
Industry-leading physical security at data centers (24/7 monitoring, biometric access, security personnel)
Advanced network security and DDoS protection
Compliance with international security standards (PCI DSS, HIPAA-eligible infrastructure, and others)
Regular third-party security audits and penetration testing
Supabase:
Built on AWS infrastructure (inherits AWS security standards)
SOC 2 compliance program
Regular security audits and assessments
Open-source codebase allowing for community security review and transparency
Encryption at rest and in transit
Modal Labs:
SOC 2 Type 2 certified
HIPAA-compliant infrastructure available
Advanced container isolation using gVisor sandboxing technology for enhanced security
Explicit policy: "We will never access or use your source code, function inputs/outputs"
8.4 Limitations and Risks
Important Disclosure:
Despite our security measures and those of our service providers, no method of transmission over the internet or electronic storage is 100% secure. We cannot and do not guarantee absolute security.
Risks include:
Potential unauthorized access by sophisticated attackers or nation-state actors
Data breaches affecting third-party service providers beyond our control
Vulnerabilities in internet infrastructure or protocols
User device compromises, malware, or stolen credentials
Social engineering attacks targeting users
Zero-day exploits in software or systems
You transmit data to and from the Platform at your own risk. We strongly recommend:
Securing the email account you use to sign in to Fenestra, since access to that inbox means access to your sign-in codes
Enabling two-factor authentication on that email account and on your Google account
Never forwarding or sharing a one-time sign-in code with anyone
Accessing the Platform from secure, trusted networks (avoid public WiFi for sensitive work)
Keeping your devices and software updated with latest security patches
Using antivirus and anti-malware software on your devices
Logging out when using shared or public devices
8.5 Security Breach Notification
In the unlikely event of a security breach that affects your personal information:
We will:
Notify you by email to the address associated with your account within 72 hours of becoming aware of the breach (as required by UK GDPR and EU GDPR)
Inform relevant data protection authorities as required by applicable law (Information Commissioner's Office in UK, relevant supervisory authority in EU)
Describe the nature of the breach and what categories of information were affected
Explain the likely consequences and potential risks to you
Detail the steps we are taking to address the breach, contain damage, and prevent recurrence
Provide recommendations for steps you can take to protect yourself (such as securing your email account, monitoring accounts)
You should:
Secure the email account linked to your Fenestra account immediately if it may be compromised
Review recent sign-in activity on that email account and on your Google account
Monitor your accounts and credit reports for suspicious activity
Be alert for phishing attempts that may reference the breach
We take security incidents very seriously and will work diligently to protect your information and minimize any harm.
9. YOUR PRIVACY RIGHTS
The privacy rights available to you depend on where you live. This section explains your rights under various privacy laws around the world.
9.1 Rights for UK and EU Users (UK GDPR / EU GDPR)
If you are located in the United Kingdom, European Economic Area, or Switzerland, you have the following rights under data protection law:
Right of Access (Article 15 GDPR):
You can request a copy of the personal data we hold about you. We will provide:
Confirmation of whether we process your personal data
A copy of your personal data in a commonly used electronic format
Information about how we use your data, who we share it with, how long we keep it, and what rights you have
Details about the source of the data (if not collected directly from you)
Information about automated decision-making or profiling (if applicable)
Right to Rectification (Article 16 GDPR):
You can request correction of inaccurate or incomplete personal data. We will update or correct your information promptly upon verification of the correct information.
Right to Erasure / "Right to be Forgotten" (Article 17 GDPR):
You can request deletion of your personal data in certain circumstances:
The data is no longer necessary for the purposes for which it was collected
You withdraw consent (where processing is based on consent) and there is no other legal basis for processing
You object to processing and there are no overriding legitimate grounds for continued processing
The personal data has been unlawfully processed
Deletion is required to comply with a legal obligation under EU or UK law
We will delete your data unless we have a legal obligation to retain it (such as for tax records, legal proceedings, or regulatory compliance).
Right to Restrict Processing (Article 18 GDPR):
You can request that we limit how we use your data in certain situations:
You contest the accuracy of the personal data (while we verify accuracy)
Processing is unlawful but you don't want erasure
We no longer need the data for our purposes but you need it for establishment, exercise, or defense of legal claims
You've objected to processing (while we verify whether our legitimate grounds override your interests)
When processing is restricted, we will store the data but not use it further without your consent (except for legal claims, protecting another person's rights, or important public interests).
Right to Data Portability (Article 20 GDPR):
You can request to receive your personal data in a structured, commonly used, machine-readable format and have the right to transmit that data to another service provider.
We will provide:
Your account information and settings
Your uploaded content (images, videos, 3D files) in original formats
Your generated outputs
Your project structure and metadata
Your text prompts and generation history
In formats such as JSON for structured data, ZIP archives for files, or other commonly-used formats
This right applies to data you provided to us and where processing is based on consent or contract and carried out by automated means.
Right to Object (Article 21 GDPR):
You can object to:
Processing based on legitimate interests (we will stop unless we have compelling legitimate grounds that override your interests)
Direct marketing at any time (we will stop immediately upon receiving your objection)
Profiling related to direct marketing
Processing for scientific, historical research, or statistical purposes (unless necessary for public interest reasons)
Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR):
If we make any significant decisions about you based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you, we will:
Inform you that such processing is taking place
Explain the logic, significance, and consequences of the automated decision
Provide a meaningful way for you to contest the decision and request human review
Implement suitable safeguards including the right to obtain human intervention
Currently, we do not make automated decisions that have legal or similarly significant effects on you. AI content generation is based on your explicit requests and creative direction, not automated profiling decisions.
Right to Withdraw Consent:
Where our processing is based on your consent (such as marketing emails or non-essential cookies), you can withdraw that consent at any time. Withdrawal is simple:
Switzerland: Federal Data Protection and Information Commissioner (FDPIC) Website: edoeb.admin.ch
We encourage you to contact us first at shaun@fenestra.dev so we can address your concerns directly. We take privacy complaints seriously and will work to resolve issues promptly.
9.2 Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Right to Know:
You can request information about:
Categories of personal information we collect about you
Categories of sources from which we collect personal information
Business or commercial purposes for collecting or selling personal information
Categories of third parties with whom we share personal information
Specific pieces of personal information we've collected about you
We will provide this information for the 12-month period preceding your request.
Right to Delete:
You can request deletion of your personal information that we have collected from you, subject to certain exceptions allowed by law such as:
Completing the transaction for which the personal information was collected
Detecting security incidents or protecting against fraudulent or illegal activity
Complying with legal obligations
Internal uses reasonably aligned with your expectations based on your relationship with us
Right to Correct:
You can request correction of inaccurate personal information we maintain about you. We will use commercially reasonable efforts to correct the information upon verification.
Right to Opt-Out:
You can opt out of:
"Sale" of personal information (Note: We do not sell personal information)
"Sharing" of personal information for cross-context behavioral advertising
Targeted advertising based on your personal information
To opt out, contact shaun@fenestra.dev or adjust cookie settings in your browser.
Right to Limit Use of Sensitive Personal Information:
We do not collect or process sensitive personal information as defined by CCPA (such as precise geolocation, racial or ethnic origin, religious beliefs, genetic data, biometric data, health data, sex life, or sexual orientation).
Right to Non-Discrimination:
We will not discriminate against you for exercising your CCPA rights. We will not:
Deny goods or services to you
Charge you different prices or rates, including through granting discounts or other benefits, or imposing penalties
Provide you a different level or quality of goods or services
Suggest that you may receive a different price, rate, level, or quality of goods or services
However, we may offer financial incentives permitted by law that can result in different prices, rates, or quality levels. Any such incentives will be reasonably related to the value of your personal information.
Authorized Agents:
You may designate an authorized agent to make requests on your behalf. The authorized agent must:
Provide written proof of authorization signed by you
Verify their own identity to us
Verify your identity
We may deny requests from authorized agents who do not submit proof of valid authorization.
9.3 Rights for Residents of Other US States
If you reside in Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have similar privacy rights under your state's privacy laws.
These generally include rights to:
Access your personal information (confirm what data we have about you)
Correct inaccurate information
Delete your personal information (subject to legal exceptions)
Obtain a copy of your personal data in a portable format
Opt out of targeted advertising
Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects
Opt out of sale of personal information (we do not sell personal information)
Specific rights and procedures may vary slightly by state. Contact shaun@fenestra.dev to exercise rights under your state's privacy law.
9.4 Rights for Australian and New Zealand Users
Under Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020:
Right to Access:
Right to request access to personal information we hold about you
Right to receive explanation of how we use your information
We may charge a reasonable fee for access requests (we will inform you in advance)
Right to Correction:
Right to request correction of inaccurate or incomplete personal information
We will take reasonable steps to correct information or, if we disagree, attach a statement from you noting the claimed inaccuracy
Right to Complain:
Right to complain to Office of the Australian Information Commissioner (oaic.gov.au) if you're in Australia
Right to complain to Office of New Zealand Privacy Commissioner (privacy.org.nz) if you're in New Zealand
If we deny a request for access or correction, we will provide you with written reasons for the denial and information about how to complain.
Email address associated with your Fenestra account
Specific right you wish to exercise (access, deletion, correction, opt-out, data portability, etc.)
Any additional details needed to locate your account and verify your identity
Preferred method for receiving response (email is standard; postal mail available upon request)
Our Response Process:
We will acknowledge receipt of your request within 5 business days
We may request additional information to verify your identity (this is required to protect your privacy and prevent unauthorized access to your data)
We will respond substantively within 30 days (or 45 days for complex requests requiring additional time to process)
We will explain our decision if we cannot fully comply with your request and inform you of your right to appeal or complain to supervisory authorities
There is no fee for requests unless they are manifestly unfounded, excessive, or repetitive
Verification:
To protect your privacy and ensure we provide information only to the correct person, we must verify your identity before processing requests. We may ask you to:
Confirm your email address through a verification link sent to your registered email
Provide additional account information (such as recent generation history, subscription tier, or account creation date)
Answer security questions about your account
Provide government-issued identification in rare cases where identity cannot be verified through other means
We will only use the information provided in your request to verify your identity and process the request. We will not use it for any other purpose.
Authorized Agents:
You may authorize another person or entity to submit privacy requests on your behalf. The authorized agent must:
Provide written and signed proof of authorization from you
Verify their own identity to us
Comply with our identity verification process
For California residents, we may require the authorized agent to provide a power of attorney or we may require you to directly confirm with us that you provided the agent authorization.
9.6 Opting Out of Marketing Communications
To stop receiving marketing and promotional emails from Fenestra:
Click the "Unsubscribe" link at the bottom of any marketing email (this is the fastest method)
Update your communication preferences in your account settings (when available)
You will be removed from marketing lists within 10 business days.
Note: You will continue to receive essential service-related communications such as:
One-time sign-in codes and account security notifications
Billing and payment confirmations
Important changes to our Terms or Privacy Policy
Service disruption notifications
Responses to your support requests
These transactional emails cannot be opted out of while you maintain an active account, as they are necessary for us to provide the Services and fulfill our contract with you.
10. CHILDREN'S PRIVACY
10.1 Age Restriction
The Platform is not intended for, and we do not knowingly collect personal information from, anyone under the age of 18.
By using the Platform, you represent and warrant that you are at least 18 years old or the age of majority in your jurisdiction, whichever is greater.
10.2 If We Discover a Child's Information
If we become aware that we have inadvertently collected personal information from someone under 18 without proper parental consent:
We will immediately deactivate the account
We will delete all associated personal data from our active systems within 24 hours
We will purge the data from backup systems
We will take reasonable steps to prevent future access by that individual
10.3 Parental Notice
If you are a parent or guardian and believe your child under 18 has provided personal information to Fenestra without your consent, please contact us immediately at shaun@fenestra.dev with "Underage Account" in the subject line.
We will promptly investigate and take appropriate action, including account deletion and data removal. Please provide:
The child's name and email address used
Your relationship to the child
Your contact information
11. LEGAL BASES FOR PROCESSING (UK/EU USERS)
If you are located in the United Kingdom, European Economic Area, or Switzerland, data protection law requires us to have a valid legal basis for processing your personal information.
We rely on the following legal bases under Article 6 of the UK GDPR and EU GDPR:
11.1 Contractual Necessity (Article 6(1)(b) GDPR)
Processing is necessary to perform our contract with you (the Terms and Conditions) and provide the Platform services you have subscribed to, including:
Creating and managing your user account
Authenticating your identity and managing login sessions
Processing AI generation requests you submit
Storing your content and projects on our servers
Processing subscription payments and managing billing
Providing customer support and responding to your inquiries
Delivering the features and functionality you have paid for or registered to use
Without this processing, we cannot provide the Services to you.
11.2 Consent (Article 6(1)(a) GDPR)
Where you have given us explicit, informed, and freely-given consent to process your personal data for specific purposes:
Sending marketing and promotional emails about new features, offers, or updates
Placing and using non-essential analytics cookies to understand usage patterns
Placing and using advertising cookies (Meta Pixel) for targeted advertising and campaign measurement
Collecting social media login data when you choose to register via Google
Participation in optional user research, surveys, or beta testing programs
Using your content for marketing or promotional purposes (only if you explicitly agree in writing)
You can withdraw your consent at any time by:
Clicking "Unsubscribe" in marketing emails
Adjusting cookie preferences in your browser or through our cookie consent tool
Withdrawing consent does not affect the lawfulness of processing that occurred before consent was withdrawn. It also does not affect processing based on other legal grounds (such as contractual necessity).
11.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process data when necessary for our legitimate business interests, provided those interests do not override your fundamental rights and freedoms:
Platform Security and Fraud Prevention:
Detecting and preventing unauthorized access, account takeovers, or credential stuffing attacks
Monitoring for security threats, vulnerabilities, and suspicious activity
Investigating suspected fraud, abuse, or violations of our Terms
Protecting our systems and infrastructure from cyber attacks
Our legitimate interest: Protecting our Platform, users, and business from security threats and fraud.
Service Improvement:
Analyzing anonymized usage patterns to improve features and user experience
Conducting internal research and development for new capabilities
Testing and optimizing Platform performance, speed, and reliability
Understanding which features provide the most value to users
A/B testing new features with anonymized user groups
Our legitimate interest: Improving our Platform to better serve users and remain competitive.
Business Operations:
Maintaining business records and financial analytics
Managing customer relationships and communication
Planning business strategy, operations, and resource allocation
Analyzing market trends and competitive positioning
Our legitimate interest: Operating a sustainable and efficient business.
Direct Marketing to Existing Customers:
Sending information about new features, updates, or related services to current users (where permitted by law such as under the "soft opt-in" provisions in UK law)
Our legitimate interest: Informing existing customers about relevant Platform developments.
Before relying on legitimate interests, we conduct a balancing test to ensure our interests do not override your rights and freedoms. We ensure processing is necessary, proportionate, and that you have appropriate safeguards and opt-out rights.
11.4 Legal Obligation (Article 6(1)(c) GDPR)
We process data where required to comply with legal or regulatory obligations under EU or UK law:
Tax and accounting record-keeping requirements (retaining transaction records for up to 7 years)
Responding to valid legal process (court orders, subpoenas, or warrants)
Cooperating with regulatory investigations or audits by competent authorities
Anti-money laundering (AML) and know-your-customer (KYC) obligations (if applicable)
Mandatory data breach notifications to supervisory authorities within 72 hours
Responding to lawful requests from law enforcement or government agencies
11.5 Vital Interests (Article 6(1)(d) GDPR)
In rare and exceptional circumstances, we may process data to protect vital interests:
Preventing imminent harm to any person's life, health, or safety
Changes to our service providers or infrastructure
12.2 How We Notify You of Changes
When we make changes to this Privacy Policy:
The "Last Updated" date at the top of this Policy will be revised to reflect the date of the most recent changes
For material changes that significantly affect your rights or how we handle your data, we will provide prominent notice on the Platform (such as a banner notification, dashboard alert, or pop-up) or send email notification to your registered email address
We will provide a reasonable period (typically 30 days) for you to review changes before they take effect
We may highlight specific changes in the notification so you understand what has changed
What constitutes a "material change":
Significant changes to data collection practices
New purposes for using your data
Sharing data with new categories of third parties
Reducing your privacy rights or protections
Changes to data retention periods
Changes to international data transfer practices
12.3 Your Acceptance of Changes
Continued use of the Platform after the effective date of changes constitutes your acceptance of the revised Privacy Policy.
If you do not agree with changes:
You should discontinue use of the Platform
You should request deletion of your account and data before changes take effect by emailing shaun@fenestra.dev
We will honor deletion requests submitted before the effective date of changes under the previous policy terms
We encourage you to review this Privacy Policy periodically (we recommend at least annually or when you receive a change notification) to stay informed about our privacy practices and your rights.
13. CONTACT US
13.1 Privacy Questions and Requests
For questions about this Privacy Policy or to exercise your privacy rights:
Subject Line: "Privacy Inquiry" or "Privacy Rights Request"
Postal Address: Designtree AI LLC Sharjah Media City Sharjah, United Arab Emirates
13.2 Data Protection Inquiries
For inquiries specifically related to UK or EU data protection compliance, GDPR questions, or international data transfers, you may direct correspondence to the email address above with subject line "GDPR Inquiry" or "Data Protection Question."
13.3 Response Time
We aim to respond to:
General privacy questions within 5 business days
Formal privacy rights requests within 30 days (or 45 days for complex requests requiring additional time, in which case we will notify you of the extension and reasons)
Security incident reports within 24 hours
Urgent matters within 48 hours
13.4 What to Include in Your Request
To help us process your request efficiently and verify your identity:
State clearly which right you wish to exercise (access, deletion, correction, opt-out, etc.)
Provide your full name and email address associated with your account
Describe your request in sufficient detail
Provide any information that will help us locate your account and verify your identity
Indicate your preferred format for response (email, postal mail, electronic file download)
13.5 Complaints and Concerns
If you have concerns about how we handle your personal information, please contact us first at shaun@fenestra.dev. We take privacy concerns seriously and will work to resolve issues promptly and transparently.
We will:
Acknowledge your complaint within 5 business days
Investigate the issue thoroughly
Provide a substantive response within 30 days
Explain our findings and any corrective actions taken
Inform you of your right to escalate to supervisory authorities if you remain unsatisfied
If you are not satisfied with our response, you have the right to contact your local data protection authority:
UK: Information Commissioner's Office (ICO) - ico.org.uk
EU: Your national Data Protection Authority
US States: Your state Attorney General's office
Australia: Office of the Australian Information Commissioner - oaic.gov.au
New Zealand: Office of New Zealand Privacy Commissioner - privacy.org.nz
APPENDIX A: TECHNICAL DATA PROCESSING DETAILS
This appendix provides detailed technical information for enterprise customers, compliance officers, IT professionals, and those conducting vendor security assessments.
A.1 Data Storage Infrastructure
Primary Storage Infrastructure:
Component: Content Storage (Images, Videos, 3D Files, AI Outputs)
Provider: Amazon Web Services (AWS) S3
Location: London, United Kingdom (eu-west-2 region)
Purpose: Primary storage for all user uploads and AI-generated content
Encryption: AES-256 encryption at rest, TLS 1.2+ in transit