All legal documents

Privacy Policy

Version v1.1 · Effective

This document is published by Opacity AI Private Limited (CIN: U62011MH2026PTC468882 ; GSTIN: 27AAFCO0822J1ZI ), a company incorporated under the Companies Act, 2013 and having its registered office in Mumbai, Maharashtra, India , which owns and operates the Pindow platform (pindow.ai / pindow.io).

This Privacy Policy explains how Opacity AI Private Limited ( "Pindow" , "we" , "us" , "our" ) collects, uses, shares, transfers, retains and protects personal data when you access or use the Pindow platform and related services (the "Services" ), and describes your rights and choices. This Policy is incorporated into and forms part of the Pindow Terms and Conditions of Service. Capitalised terms not defined here have the meaning given in the Terms.

1. Introduction and Scope

1.1 Pindow is an India-based AI creative production platform serving users worldwide. We are committed to handling personal data lawfully, fairly and transparently, in accordance with the Digital Personal Data Protection Act, 2023 ( "DPDP Act" ) and the Information Technology Act, 2000 and rules made thereunder in India, and, where applicable to you, the EU General Data Protection Regulation 2016/679 ( "GDPR" ), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ( "CCPA/CPRA" ), and other applicable data-protection laws.

1.2 This Policy applies to personal data we process about visitors, registered users, subscribers, and individuals whose data is included in Content submitted to the Services. It does not apply to third-party services that have their own privacy policies.

2. Who We Are (Data Fiduciary / Controller)

2.1 For the purposes of the DPDP Act, Pindow is the Data Fiduciary that determines the purpose and means of processing your personal data. For the purposes of the GDPR/UK GDPR, Pindow is the controller . Our identity and contact details are:

Opacity AI Private Limited (CIN: U62011MH2026PTC468882 | GSTIN: 27AAFCO0822J1ZI ) Registered Office: Mumbai, Maharashtra, India

Privacy / Data Protection contact: legal@pindow.ai

Grievance Officer: legal@pindow.ai

2.2 When you choose to use a Third-Party Model, that provider independently processes the data routed to it under its own privacy terms and may act as a separate controller or fiduciary for that processing. See Sections 7 and 9.

3. Definitions

3.1 "Personal data" means any data about an individual who is identifiable by or in relation to such data. "Processing" means any operation performed on personal data. "Data Principal" (DPDP Act) or "data subject" (GDPR) means the individual to whom the personal data relates. "Data Processor" means a person who processes personal data on our behalf. "Sensitive personal data" means categories afforded special protection under applicable law (for example, data revealing health, biometric, financial, or similar information, where recognised).

4. Personal Data We Collect

4.1 Account and profile data: name, username, email address, password (stored in hashed form), profile details, organisation or studio name, and role.

4.2 Billing and transaction data: billing name and address, plan and Subscription details, Credit balances and usage, transaction history, and tax identifiers (such as GSTIN where you provide it). Card and bank details are collected and processed directly by our payment processors; we do not store full payment-card numbers.

4.3 Content and creative data: your Inputs (prompts, reference images, video, audio, voice samples and other uploads), your Outputs, projects, Canvas boards, pipelines, presets, and associated metadata. Inputs and uploaded media may themselves contain personal data of you or other individuals (for example, faces or voices in reference media).

4.4 Usage and technical data: log data, device and browser type, operating system, IP address, approximate location derived from IP, identifiers, pages and features used, generation events, timestamps, model selections, and diagnostic and crash data.

4.5 Cookies and tracking data: as described in Section 8.

4.6 Communications data: support requests, grievance complaints, survey responses, and your correspondence with us.

4.7 Marketplace and community data: presets and prompts you publish, ratings, and earnings or payout information where you participate in a creator programme.

4.8 We do not intentionally collect sensitive personal data unless you provide it within Content. Please do not submit sensitive personal data unless necessary, and only where you have a lawful basis to do so.

5. How We Collect Your Data

5.1 We collect personal data: (a) directly from you , when you register, subscribe, submit Content, contact us, or participate in features; (b) automatically , through your use of the Services and through cookies and similar technologies; and (c) from third parties , such as our payment processors, authentication or singlesign-on providers, and analytics providers, in each case consistent with their terms and your choices.

6.1 We process personal data for the following purposes, relying on the legal bases indicated. Under the DPDP Act, we rely on your consent and, where available, on certain legitimate uses permitted by the Act. Under the GDPR/UK GDPR, we rely on one or more of: performance of a contract ; your consent ; our legitimate interests ; and compliance with a legal obligation .

  • To provide the Services (create and manage your Account, run generations, store projects, route requests to Third-Party Models) - contract / consent.

  • To process payments, Credits and taxes and prevent payment fraud - contract / legal obligation.

  • To operate, secure, maintain and improve the Services, debug, and prevent abuse and fraud - legitimate interests / legal obligation.

  • To communicate with you about your Account, transactions, security, and changes to the Services - contract / legitimate interests.

  • To provide support and handle grievances - contract / legal obligation.

  • For analytics and product development using aggregated or de-identified data where feasible - legitimate interests / consent.

  • For marketing, where permitted, with the ability to opt out - consent / legitimate interests.

  • To comply with law, respond to lawful requests, and enforce our Terms - legal obligation / legitimate interests.

7. How We Use AI Models and Your Content

7.1 When you generate Content, your relevant Inputs (and, for some operations, your Outputs) are transmitted to the Third-Party Model you select, through our proxied interfaces, so that the request can be fulfilled. These providers may include, among others, model providers for image, video, audio, music and language generation engaged through the Services. The provider processes that data under its own terms and privacy policy.

7.2 Zero training and no sale. Pindow does not use your Inputs, Outputs, projects, workspaces or media assets to train its proprietary foundation models. Your Content is not sold. Some Third-Party Models may, under their own terms, process or retain data for their own purposes unless a no-training or zero-retention option is selected; where supported by the provider, Pindow uses commercially reasonable efforts to enable zero-retention or no-training configurations. We encourage you not to submit confidential or sensitive material you would not wish to share with a model provider.

7.3 Where you upload another individual's image, likeness or voice (including for face or character reference, voice cloning, dubbing or lip-sync), you are responsible for ensuring you have a lawful basis and any required consent, and for complying with personality, publicity and biometric-data laws applicable to you.

7.4 The AI studio assistant may process your project context to provide suggestions, rewrites and answers. Its responses are generated and may be inaccurate; you remain responsible for how you use them.

8. Cookies and Similar Technologies

8.1 We and our service providers use cookies, local storage and similar technologies to operate the Services, remember preferences, maintain sessions, provide security, measure performance, and (where you consent) for analytics and marketing.

8.2 We classify cookies as strictly necessary, functional, analytics and advertising. Strictly necessary cookies do not require consent. Where required by law (for example, in the EEA/UK), we request your consent for non-essential cookies through a consent banner, and you may withdraw or change your choices at any time through the cookie settings. You can also control cookies through your browser settings.

9. How We Share and Disclose Personal Data

9.1 We do not sell your personal data. We share personal data only as described below:

  • Third-Party Model providers, to fulfil generation requests you initiate (Section 7).

  • Service providers / Data Processors who process data on our behalf under contractual confidentiality and data-protection obligations, including cloud hosting and storage, payment processing, communications and email delivery, customer support, security, and analytics.

  • Within a creator programme, limited information necessary to operate marketplace listings, payouts and tax compliance.

  • Legal and safety: to comply with applicable law, court orders or lawful requests by public authorities; to enforce our Terms; to detect, prevent or address fraud, security or technical issues; and to protect the rights, property or safety of Pindow, our users or the public, including reporting unlawful content as required by law.

  • Business transfers: in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to the recipient honouring this Policy.

  • With your consent or at your direction, in other cases you authorise.

9.2 Subprocessors. Pindow maintains a list of the significant subprocessors used in connection with the Services, which may include cloud infrastructure providers, payment processors, analytics providers and AI model providers. We will make the current list available and update it as our subprocessors change.

10. International Data Transfers

10.1 Because Pindow serves a global user base and uses Third-Party Models and infrastructure that may be located outside your country, your personal data may be transferred to, stored in, or accessed from jurisdictions other than your own, including outside India.

10.2 Under the DPDP Act, cross-border transfer is permitted except to countries or territories that the Central Government may restrict by notification; we monitor and comply with any such restrictions.

10.3 For transfers of personal data of individuals in the EEA or UK to countries not recognised as providing adequate protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary measures where required. You may request information about the safeguards used by contacting us.

11. Data Retention

11.1 We retain personal data only for as long as necessary for the purposes set out in this Policy, including to provide the Services, comply with legal, tax and accounting obligations, resolve disputes, and enforce our agreements.

11.2 Account and Content data are generally retained while your Account is active and for a reasonable period thereafter, after which they are deleted or de-identified, subject to legal retention requirements and limited backup or security copies that are deleted on a rolling basis. You can delete projects and Content within the Services; deletion may not be instantaneous across all systems and backups.

11.3 Deletion timelines. Upon deletion of your Account:

  • active records are deleted within thirty (30) days;

  • backup copies are removed within ninety (90) days; and

  • legal, tax or regulatory retention obligations may require longer preservation of certain records.

12. Information Security

12.1 We implement reasonable technical and organisational security measures appropriate to the risk, consistent with the DPDP Act and applicable law, including encryption in transit, access controls, hashing of passwords, network protection, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for the security of devices you use to access the Services.

12.2 Personnel access. Access to user content by our employees and contractors is restricted and granted only on a need-to-know basis, and such persons are bound by written confidentiality obligations.

13. Your Rights and Choices

13.1 Rights under the DPDP Act (India). Subject to the Act and applicable conditions, you as a Data Principal have the right to: (a) access a summary of your personal data and processing; (b) correct, complete, update and erase your personal data; (c) grievance redressal; and (d) nominate another individual to exercise your rights in the event of death or incapacity. You may withdraw consent at any time, as easily as it was given; withdrawal does not affect prior lawful processing.

13.2 Rights under the GDPR/UK GDPR (EEA/UK). Subject to applicable conditions, you have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection (including to direct marketing and to processing based on legitimate interests), and the right not to be subject to solely automated decisions producing legal or similarly significant effects. You may also lodge a complaint with your supervisory authority.

13.3 Rights under the CCPA/CPRA (California). Subject to applicable conditions, you have the right to know and access the categories and specific pieces of personal information collected, the right to delete, the right to correct, the right to opt out of the sale or sharing of personal information (we do not sell personal information), the right to limit use of sensitive personal information, and the right not to receive discriminatory treatment for exercising your rights. You may use an authorised agent to submit requests.

13.4 How to exercise your rights. You may exercise your rights through your Account settings where available, or by contacting us at legal@pindow.ai . We will verify your identity before acting and will respond within the timeframes required by applicable law. There is generally no fee unless your request is manifestly unfounded or excessive.

14. Children's Data

14.1 The Services are not intended for, or directed to, children. Consistent with Section 9 of the DPDP Act, we do not knowingly process the personal data of children (individuals under 18 in India) without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you access the Services from another jurisdiction, the local minimum age applies. If we learn that we have collected a child's personal data without the required consent, we will delete it. If you believe a child has provided us personal data, contact us at legal@pindow.ai .

15.1 The Services may link to or integrate with third-party websites and services, including Third-Party Models, payment processors and authentication providers. Their processing of your data is governed by their own privacy policies, which we encourage you to review. We are not responsible for their practices.

16. Automated Processing and Profiling

16.1 We use automated processing to operate the Services (for example, to route generation requests, meter Credits, detect fraud and abuse, and apply content-safety filters). We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and, where required, suitable safeguards and the ability to request human review.

17. Personal Data Breach Notification

17.1 In the event of a personal data breach, we will take steps to contain and remediate it and will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, and the relevant supervisory authority and affected individuals as required under the GDPR/UK GDPR and other applicable laws, within the prescribed timelines.

18.1 You may address any privacy question, request or complaint to our Grievance Officer / privacy contact:

Designation: Grievance Officer (and Data Protection contact) Email: legal@pindow.ai Address: Mumbai, Maharashtra, India

18.2 We will acknowledge grievances within twenty-four (24) hours and endeavour to resolve them within the timelines prescribed under applicable law. Where the DPDP Act requires resolution of a grievance before approaching the Data Protection Board, please raise it with us first.

18.3 As of the effective date, we have not appointed a separate Data Protection Officer or, for the EEA/UK, an Article 27 representative, and registration with a Consent Manager will follow the framework once notified under the DPDP Act. If and when any such appointment or registration is made or becomes required, the relevant contact details will be published in this Policy and on our website.

19. Changes to this Privacy Policy

19.1 We may update this Policy from time to time. We will post the updated Policy with a new effective date and, for material changes, provide reasonable notice. Your continued use of the Services after the changes take effect indicates your acknowledgement, and, where required, we will seek your fresh consent.

20. Region-Specific Disclosures

A. European Economic Area and United Kingdom

The controller is Opacity AI Private Limited . Legal bases are set out in Section 6. You have the rights in Section 13.2 and may lodge a complaint with your local data-protection authority. International transfers are addressed in Section 10. Where applicable, our EU/UK representative is identified in Section 18.3.

B. California, United States

This section supplements the Policy for California residents under the CCPA/CPRA. In the preceding 12 months we may have collected the categories described in Section 4 (identifiers, commercial information, internet/usage activity, audio/visual information within Content, and inferences), for the business purposes in Section 6, and disclosed them to the recipients in Section 9. We do not sell personal information and do not knowingly sell or share the personal information of individuals under 16. Exercise rights as described in Section 13.3 via legal@pindow.ai .

C. Other Jurisdictions

If the data-protection law of your jurisdiction grants you rights or protections not described above, we will honour them to the extent they apply to our processing of your personal data.

21. How to Contact Us

For any questions, requests or complaints regarding this Privacy Policy or your personal data, contact:

Opacity AI Private Limited

Registered Office: Mumbai, Maharashtra, India Privacy / Data Protection: legal@pindow.ai Grievance Officer: legal@pindow.ai

Website: www.pindow.ai

This Privacy Policy should be read together with the Pindow Terms and Conditions of Service and the Acceptable Use Policy.