Privacy Policy

Last Updated: February 13, 2025

This Privacy Policy ("Policy") describes how AgenticFruit ("Company", "we", "us", or "our") collects, uses, discloses, and safeguards information obtained from users ("User", "you", or "your") of our artificial intelligence-powered content management platform (the "Service").

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. If you do not agree with the practices described in this Policy, you should discontinue use of the Service immediately.

1. Information We Collect

1.1 Information Provided by Users

Account Information:

  • Email address required for account registration and authentication purposes;
  • Password credentials encrypted and stored securely via Supabase authentication services; and
  • Access passcode validated during registration but not retained in our systems.

User-Submitted Content:

  • Product images, descriptions, and related metadata;
  • Photographs of actors, models, or other individuals;
  • Demographic information voluntarily provided by users, including gender, race, and age group;
  • Text prompts and instructions for artificial intelligence content generation;
  • Social media post drafts, captions, and related content;
  • Calendar events and content strategy documentation; and
  • Reference images for style matching and content generation purposes.

1.2 Automatically Collected Information

Usage Data:

  • Page views, navigation patterns, and user interaction data collected via Vercel Analytics;
  • Device information, including browser type, version, and operating system;
  • Internet Protocol (IP) address and approximate geographic location at the country or regional level;
  • Session duration and timestamps of user interactions; and
  • Feature utilization statistics and engagement metrics.

Technical Data:

  • Application programming interface (API) request logs maintained for rate limiting and abuse prevention purposes;
  • Error logs and debugging information for system maintenance and improvement; and
  • Authentication tokens stored securely with automatic expiration protocols.

1.3 AI-Generated Data

  • Images generated through artificial intelligence image generation services;
  • Videos generated through artificial intelligence video generation services;
  • Text content, including captions and descriptions, generated by artificial intelligence models;
  • Content intent analysis results and recommendations; and
  • Style and mood recommendations generated by artificial intelligence algorithms.

2. How We Use Your Information

The Company processes collected information for the following purposes:

2.1 Service Provision

  • Establishing, maintaining, and administering user accounts;
  • Authenticating user access to the Service;
  • Processing, storing, and managing user-submitted content;
  • Generating artificial intelligence-powered images, videos, and text content;
  • Providing content recommendations and intent analysis services; and
  • Enabling content scheduling and management functionalities.

2.2 Service Improvement

  • Analyzing usage patterns to enhance Service features and functionality;
  • Monitoring and optimizing artificial intelligence model performance;
  • Identifying, diagnosing, and resolving technical issues;
  • Developing new features based on user behavior and feedback; and
  • Conducting internal research and analytics to improve Service quality.

2.3 Security and Compliance

  • Preventing, detecting, and investigating fraud, abuse, and unauthorized access;
  • Enforcing the Terms and Conditions and other applicable policies;
  • Implementing rate limiting measures to prevent service abuse;
  • Protecting against security vulnerabilities, including server-side request forgery (SSRF) attacks; and
  • Complying with applicable legal obligations and regulatory requirements.

2.4 Communication

  • Transmitting account confirmation and verification communications;
  • Providing notifications regarding service updates, security issues, or material changes to this Policy;
  • Responding to user support requests and inquiries; and
  • Sending administrative messages necessary for Service operation.

3. Third-Party Services and Data Sharing

We integrate with third-party services to provide our features. When you use certain features, your data may be shared with these providers:

3.1 Google Gemini AI

Purpose: Image generation and editing

Data Shared:

  • Your text prompts for image generation
  • Product images (converted to base64 format)
  • Reference images for style matching
  • Actor photos (when generating content with specific people)

Provider Policy: Google Gemini API Terms

3.2 OpenAI (ChatGPT)

Purpose: Text generation, caption creation, and content intent analysis

Data Shared:

  • Your text prompts and content descriptions
  • Image URLs and base64-encoded images (for vision analysis)
  • Product descriptions and metadata

Provider Policy: OpenAI Terms of Use | OpenAI Privacy Policy

Note: According to OpenAI's policy, API data is not used to train their models unless you explicitly opt in.

3.3 Kling AI

Purpose: AI video generation

Data Shared:

  • Video generation prompts
  • Frame images and reference materials
  • Video generation parameters (duration, aspect ratio, etc.)

Location: Kling AI processes data in Singapore

Provider Policy: Kling AI Website

International Transfer: By using video generation features, you consent to your data being transferred to and processed in Singapore.

3.4 Supabase

Purpose: Database, authentication, and file storage infrastructure

Data Stored:

  • All account information
  • All uploaded content and files
  • All generated content
  • All application data (posts, products, actors, calendar events)

Provider Policy: Supabase Privacy Policy

3.5 Vercel

Purpose: Hosting and analytics

Data Collected:

  • Anonymous usage analytics (page views, device info, approximate location)
  • Performance metrics

Provider Policy: Vercel Privacy Policy

3.6 Other Disclosures

We may disclose your information:

  • To comply with legal obligations (e.g., court orders, subpoenas)
  • To protect our rights, property, or safety, or that of others
  • In connection with a merger, acquisition, or sale of assets (with notice to you)
  • With your explicit consent

We do not sell your personal information to third parties.

4. Data Storage and Security

4.1 Storage Infrastructure

  • Database: Supabase (PostgreSQL) with encryption at rest
  • File Storage: Supabase Storage with secure bucket policies
  • Hosting: Vercel serverless infrastructure

4.2 Security Measures

We implement industry-standard security practices:

  • Encryption: HTTPS/TLS for data in transit, encryption at rest for stored data
  • Authentication: Secure password hashing (via Supabase Auth)
  • Access Control: Row Level Security (RLS) policies ensure users can only access their own data
  • Rate Limiting: API rate limits prevent abuse (10 requests per minute for AI features)
  • SSRF Protection: URL validation prevents server-side request forgery attacks
  • Regular Updates: Dependencies are regularly updated to patch security vulnerabilities

4.3 Data Retention

  • Active Accounts: Data retained while your account is active
  • Inactive Content: May be deleted after 90 days of inactivity
  • Deleted Accounts: Data deleted within 30 days of account deletion
  • Backups: Data may persist in backup systems for up to 30 days after deletion
  • Legal Holds: Data may be retained longer if required by law

4.4 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you within 72 hours via email and provide information about the breach and steps you can take to protect yourself.

5. Your Privacy Rights

5.1 Access and Portability

Subject to applicable law, Users have the right to request access to personal data maintained by the Company and to receive such data in a portable, machine-readable format. To submit a data access request, Users may contact privacy@agenticfruit.com.

Note: The Company is currently developing automated data export functionality to facilitate User access requests.

5.2 Correction and Rectification

Users may update, modify, or correct account information and user-submitted content directly through the Service interface at any time. For assistance with data corrections, Users may contact privacy@agenticfruit.com.

5.3 Deletion (Right to Erasure)

Subject to applicable law and certain exceptions, Users have the right to request deletion of personal data maintained by the Company. To request account deletion:

  • Submit a deletion request to privacy@agenticfruit.com from the email address associated with your account;
  • The Company will process deletion requests and remove account data within thirty (30) calendar days of receipt; and
  • Personal data may persist in backup systems for up to an additional thirty (30) days following primary deletion.

Note: The Company is currently developing automated account deletion functionality to facilitate User erasure requests.

5.4 Opt-Out of Analytics

Users may opt out of Vercel Analytics tracking through the following methods:

  • Enabling Do Not Track (DNT) settings in your web browser;
  • Utilizing privacy-focused browser extensions or plugins; or
  • Contacting privacy@agenticfruit.com to request manual disablement of analytics for your account.

5.5 Objection to Processing

Subject to applicable law, Users have the right to object to certain types of data processing. Users acknowledge that objecting to processing necessary for artificial intelligence features may limit or prevent use of such features within the Service.

5.6 Withdrawal of Consent

Where the Company processes personal data based on User consent, Users have the right to withdraw such consent at any time. Withdrawal of consent shall not affect the lawfulness of processing conducted prior to withdrawal.

6. International Data Transfers

The Service is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to, stored, and processed in the United States.

Specific International Transfers:

  • Singapore: Video generation data is processed by Kling AI in Singapore
  • European Union: We do not have EU-specific data centers; EU users' data is processed in the U.S.

By using the Service, you consent to these international data transfers. We implement appropriate safeguards to protect your data in accordance with this Privacy Policy and applicable laws.

7. Children's Privacy

The Service is not directed to, and the Company does not knowingly collect personal information from, individuals under the age of thirteen (13) years, or such higher age as required by applicable law in certain jurisdictions. If the Company becomes aware that personal information has been collected from an individual under the applicable minimum age without verified parental consent, the Company will take immediate steps to delete such information from its systems.

If you have reason to believe that the Company has collected personal information from an individual under the applicable minimum age, please contact us immediately at privacy@agenticfruit.com with relevant details, and we will investigate and take appropriate action in accordance with applicable law.

8. Cookies and Tracking Technologies

8.1 Cookies We Use

Essential Cookies:

  • Authentication: Session tokens to keep you logged in (Supabase Auth)
  • Security: CSRF tokens to prevent cross-site attacks

Analytics Cookies:

  • Vercel Analytics: Anonymous usage tracking (page views, performance metrics)

8.2 Your Cookie Choices

  • Essential cookies are required for the Service to function
  • You can disable analytics cookies through browser settings or Do Not Track
  • Disabling cookies may limit Service functionality

8.3 Third-Party Tracking

We do not use third-party advertising networks or tracking pixels. The only third-party tracking is Vercel Analytics for service improvement purposes.

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

9.1 Right to Know

You have the right to request:

  • The categories of personal information we collect
  • The sources of the personal information
  • Our business purpose for collecting or selling personal information
  • The categories of third parties with whom we share personal information
  • The specific pieces of personal information we have collected about you

9.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions.

9.3 Right to Opt-Out of Sale

We do not sell your personal information. Therefore, there is no need to opt out of sale.

9.4 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

9.5 How to Exercise Your Rights

To exercise your CCPA rights, contact us at privacy@agenticfruit.com. We will verify your identity and respond within 45 days.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

10.1 Legal Basis for Processing

We process your data based on:

  • Contract: To provide the Service you signed up for
  • Consent: For analytics and optional features
  • Legitimate Interests: For service improvement and security
  • Legal Obligations: To comply with applicable laws

10.2 Your GDPR Rights

  • Right of Access: Request a copy of your data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Restriction: Limit how we process your data
  • Right to Portability: Receive your data in a portable format
  • Right to Object: Object to certain processing activities
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your data protection authority

10.3 Data Protection Officer

For GDPR-related inquiries, contact our data protection contact at: privacy@agenticfruit.com

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.

For material changes, we will notify you by:

  • Sending an email to the address associated with your account
  • Displaying a prominent notice on the Service

Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

AgenticFruit Privacy Team

Email: privacy@agenticfruit.com
General Support: support@agenticfruit.com
GDPR/Data Protection: privacy@agenticfruit.com
CCPA Requests: privacy@agenticfruit.com

We will respond to your inquiry within 30 days (or 45 days for CCPA requests).

Summary of Key Points

  • We collect your email, content uploads, and usage data
  • We use AI services (Google Gemini, OpenAI, Kling AI) that process your data
  • We do not sell your personal information
  • You can request access, correction, or deletion of your data
  • Data is stored securely with encryption and access controls
  • Some data is processed internationally (U.S. and Singapore)
  • You have rights under GDPR (if in EU) and CCPA (if in California)
  • Contact privacy@agenticfruit.com for privacy questions or requests