Privacy Policy
Last updated: 15 July 2026This Privacy Policy explains how rIMAGEx (VAT no. 02828050738, Italy) collects, uses, and protects your personal data when you visit rimagex.com or use the application at app.rimagex.com.
1. Data we collect
- Account data: name, email address, billing details when you sign up.
- Uploaded content: still-life garment photos, reference images, and any prompts you submit to generate AI fashion shoots.
- Generated outputs: the images produced by rIMAGEx on your behalf.
- Usage data: log files, IP address, browser type, pages viewed (collected automatically).
- Product analytics: inside the application we use PostHog (EU-hosted, served through our own domain) to collect usage events — which features are opened, generations started, downloads — so we can fix issues and improve the product. We do not record your screen or your sessions.
- Website analytics: on rimagex.com we use Vercel Web Analytics (aggregated, cookieless) and a first-party script that remembers how you arrived at the site (e.g. the referring campaign).
- Cookies & local storage: essential cookies for authentication and session management, plus the analytics described above. We do not use advertising cookies.
2. How we use your data
- To deliver the service: your uploads and prompts are sent to our AI providers (listed in Section 5) solely to run the generations you request; outputs are rendered and stored for you.
- To bill you: process payments via Stripe (Stripe is the data controller for payment information).
- To improve the service: usage analytics (PostHog), reviewed to understand how features are used and where they fail.
- To contact you: transactional emails (account confirmations, billing, support) and, only with your opt-in, product news.
We do not sell your data, share it with advertising networks, or use your uploaded content to train public AI models.
3. Legal basis (GDPR)
We process your data on the following legal bases under the EU General Data Protection Regulation:
- Contract: to deliver the service you signed up for.
- Legitimate interest: to secure the platform and prevent abuse.
- Consent: for any optional communications (marketing emails — opt-in only).
- Legal obligation: for tax records and compliance with applicable law.
4. Data retention
We retain account data for as long as your account is active. Generated images and uploaded content are retained until you delete them or close your account. Closed-account data is deleted within 90 days, except where law requires longer retention (e.g. invoices: 10 years EU).
5. Data sharing
We share data only with the processors needed to operate the service:
- Supabase — authentication, database, and file storage (EU region)
- Stripe — payment processing
- Google Cloud (Vertex AI) — image generation (receives your uploads and prompts to run generations)
- OpenRouter — AI analysis of images and prompts (routes requests to model providers such as Anthropic)
- fal.ai — image processing (segmentation, object removal)
- Replicate — image generation for selected features
- PostHog — product analytics (EU-hosted)
- Resend — transactional email delivery
- Vercel — hosting and website analytics
Our AI providers process your content to deliver the service; we do not permit them to use it to train publicly available models.
Each processor is bound by a Data Processing Agreement (DPA).
6. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to processing or withdraw consent
- Lodge a complaint with your local data protection authority
Email info@rimagex.com to exercise any of these rights.
7. International transfers
Some processors (Google, Stripe, OpenRouter, fal.ai, Replicate, Resend, Vercel) may transfer data outside the EU. We rely on Standard Contractual Clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework for such transfers.
8. Security
We use HTTPS for all traffic, encryption at rest for stored data, and access controls restricted to authorized personnel. We notify affected users within 72 hours of any data breach involving personal data, as required by GDPR.
9. Changes to this policy
We will post any material changes to this policy here, and notify active users via email if the changes affect how their data is processed.
10. Contact
Data Controller: rIMAGEx — VAT no. 02828050738 (Italy)
Email: info@rimagex.com