Privacy Policy
Last updated: September 10, 2026
InteriorAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered interior design platform.
1. Data Controller
The data controller for this Service is:
- Company Name: InteriorAI
- Registered Address: [To be completed with actual registered address]
- Privacy Contact Email: privacy@interiorai.com
- Data Protection Officer: Not applicable at this time
2. Information We Collect
We collect the following types of information:
2.1 Information You Provide
- Account Information: Name, email address, username, and password (encrypted) when you create an account.
- Profile Information: Any additional details you choose to add to your profile.
- Room Photos: Images you upload to our platform for AI processing and design generation.
- Design Preferences: Style selections, room types, material choices, and furniture preferences you specify.
- Payment Information: Billing details for credit pack purchases. We do not store credit card numbers — card data is handled exclusively by our payment processor (see Section 5).
- Communications: Messages you send to our support team.
2.2 Information Collected Automatically
- Device & Network: IP address, device type, operating system, browser type, and timezone.
- Usage Data: Page visits, features used, design generation counts, session duration, and interaction patterns.
- Logs: Request timestamps, error logs, and performance data.
3. How We Use Your Information
We use your information for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Provide and maintain the Service | Contract performance |
| Billing and payment processing | Contract performance |
| Customer support | Contract performance / Legitimate interests |
| Service notifications (billing, security, policy updates) | Legitimate interests |
| Security and fraud prevention | Legitimate interests |
| Product improvement and analytics | Legitimate interests |
| Legal compliance | Legal obligation |
| Marketing communications (optional) | User consent |
We may aggregate or de-identify data for statistical analysis. Such data cannot identify you.
4. Cookies and Tracking
| Type | Purpose | Can be disabled |
|---|---|---|
| Strictly necessary | Login, core functionality | No |
| Functional | Language preferences, personalized settings | Yes |
| Analytics | Anonymous usage statistics, product improvement | Yes |
| Marketing (optional) | Targeted advertising and performance measurement | Yes |
Analytics tool: [Google Analytics or similar — include privacy policy link]. You can adjust preferences via browser settings or our Cookie Preference Center.
5. How We Share Your Information
We do not sell your personal information, including as defined under applicable laws such as CCPA. We may share your data only in the following circumstances:
- Service Providers: Trusted third-party providers for cloud hosting, payment processing, customer support, and analytics, bound by confidentiality agreements. Payment card data is processed exclusively by Waffo Pancake in compliance with PCI-DSS standards — card data is never stored on our servers.
- AI Processing Partners: Uploaded images are processed by third-party AI infrastructure providers to generate designs. These providers are bound by strict data processing agreements.
- Legal Requirements: We may disclose information when required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred subject to the same protection obligations.
- With Your Consent: For any other purpose with your explicit prior consent.
6. Data Security
We implement the following security measures:
- Encryption in transit: TLS/HTTPS.
- Storage security: Passwords and sensitive data are encrypted or hashed.
- Access controls: Least-privilege principle; employees sign confidentiality agreements.
- Regular audits: Periodic security audits and vulnerability scanning.
If a security breach occurs that affects your rights, we will notify you within 72 hours of discovery, and report to relevant supervisory authorities as required by law.
7. Data Retention
| Data Type | Retention Period | Disposal on Expiry |
|---|---|---|
| Account information | Active period; 90 days after account deletion | Delete or anonymize |
| Transaction records | 7 years (tax/accounting compliance) | Delete or archive |
| Support communications | 3 years | Securely delete |
| Security audit logs | 12 months | Securely delete |
| Uploaded images | Duration of account; 30 days after deletion | Permanently delete |
8. Your Data Rights
To exercise any of these rights, contact us at privacy@interiorai.com. We will respond within 30 calendar days.
| Right | Description |
|---|---|
| Right to access | Request a copy of personal data we hold about you |
| Right to rectification | Request correction of inaccurate or incomplete data |
| Right to erasure | Request deletion of your account and associated personal data |
| Right to restriction | Request suspension of data processing in certain circumstances |
| Right to portability | Request a machine-readable copy of your data |
| Right to object | Object to processing based on legitimate interests or marketing |
| Right to withdraw consent | Withdraw consent for processing based on consent at any time |
If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority.
9. Marketing Communications
With your consent, we may send you marketing emails about our products and services. You can unsubscribe at any time by clicking the unsubscribe link in our emails, adjusting your account settings, or contacting us. Unsubscribing does not affect service-related notifications such as billing or security alerts.
10. International Data Transfers
Our servers and service providers may be located in countries other than your country of residence, including the United States and Singapore. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCC) or equivalent legal mechanisms, in compliance with applicable data protection laws including GDPR.
11. Children's Privacy
InteriorAI is not intended for children under 13 years old. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will promptly delete it. If you believe your child has provided us with personal information, contact us at support@interiorai.com.
12. Third-Party Links
Our Service may contain links to third-party websites or services. This Privacy Policy applies only to data we directly collect. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies before using their services.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you at least 15 days in advance via email or a prominent notice on our website. The "Last updated" date at the top of this page reflects the effective date. Continued use of InteriorAI after changes become effective constitutes acceptance of the updated policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Privacy inquiries: privacy@interiorai.com
- Customer support: support@interiorai.com
- Company: InteriorAI
- Address: [Mailing Address]
- Hours: Monday to Friday, 09:00–18:00 UTC+8