Privacy Policy
Version 1 · Effective 2026-07-27
TL;DR (plain language)
- We do not sell personal data and do not use it for third-party advertising.
- We collect what we need to run a marketplace: your email and OAuth identity, your profile, what you upload, what you buy, and your messages/comments/votes.
- Analytics are cookieless. No ad trackers, no cookie banner needed. The only cookies we set are the session cookies that keep you logged in.
- Payments and identity verification are handled by Stripe — we never see your card number or bank details.
- We record explicit legal consents (Creator Agreement signature, purchase-terms acceptance, EU withdrawal waiver) with timestamp and IP address — they are kept as legal evidence of your acceptance for as long as the agreements matter (limitation periods).
- Delete your account any time: 30-day grace period, then files are deleted and your records are anonymized. Transaction records are kept (anonymized) for tax/legal reasons.
- We’re US-based; your data is processed in the US by our service providers.
1. Who We Are
This policy explains how (“we,” “us”), operator of AgentsOfAI.art, located at , handles personal data. We are the data controller for the Platform. Privacy contact: support@agentsofai.art.
2. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | Email address, OAuth provider identifiers (Google, Discord), username | You / your OAuth provider |
| Profile | Display name, bio, avatar, AI-tool tags, external links | You |
| Content & metadata | Uploaded videos/images, titles, descriptions, keywords, tool tags, prices, technical metadata derived from the file (including a content fingerprint used for duplicate detection) | You |
| Transactions | Purchase history, license records, payout balance and payout history (amounts and status — payment credentials stay with Stripe) | You / Stripe |
| Creator payout identity | Tax and bank details (W-9/W-8BEN, bank account, government ID for KYC) — collected and stored by Stripe, not by us | You → Stripe |
| Communications | In-platform messages, comments, emails you send us | You |
| Community activity | Votes (up/down), flags/reports, appeals | You |
| Consent records | Which document version you accepted, typed-name signature (Creator Agreement), timestamp, IP address (and user agent where captured) — append-only, retained as legal evidence | Generated |
| Moderation & enforcement | Strikes, ban status, DMCA notices (including claimant name/email), content fingerprints of banned content | Generated / complainants |
| Technical & security | IP address and user agent in server logs, bot-check outcomes, rate-limit counters | Generated |
| Analytics | Cookieless page/event data (e.g., pages visited, searches run) | Generated |
We do not collect: passwords (login is OAuth or magic-link only), payment card numbers, or advertising identifiers. We set no third-party advertising or tracking cookies.
3. How and Why We Use Data (Legal Bases)
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Provide the marketplace (accounts, uploads, purchases, downloads, payouts, messaging) | Account, profile, content, transactions, communications | Contract |
| Process payments, taxes, 1099s | Transactions (via Stripe) | Contract; legal obligation |
| Content moderation (automated content screening, reports, strikes, ban enforcement) | Content, moderation records, fingerprints | Legitimate interests; legal obligation |
| DMCA / legal compliance, consent logging | Consent records, DMCA notices, IP addresses | Legal obligation |
| Security, bot prevention, rate limiting | Technical & security data | Legitimate interests |
| Transactional email (welcome, purchase receipts/download links, moderation notices, message notifications) | Email address | Contract |
| Product analytics | Cookieless analytics events | Legitimate interests |
We do not sell personal data and do not use it for third-party advertising.
4. Processors and Recipients
We share data only with the service providers that run the Platform, under their data processing terms.
| Category of provider | Role | Data touched |
|---|---|---|
| Infrastructure & content delivery | Hosting, CDN, file storage, media processing, bot protection, usage telemetry | Content files, technical data, IP addresses, usage-event records (which may reference your account and asset identifiers) |
| Database & authentication | Managed database and sign-in | Account, profile, transaction metadata, consents, moderation records |
| Payments — Stripe | Payments, payouts, KYC/identity verification, tax calculation and forms | Payment and payout data, tax identity (Stripe is an independent controller for its own compliance obligations) |
| Email delivery | Transactional email | Email address, email content |
| AI analysis | Automated content screening of uploads, AI-generated descriptions and tags, and search relevance | Uploaded images and video thumbnails; search-query text; public profile text |
| Product analytics | Cookieless usage analytics | Event data (no advertising identifiers) |
A current list of our named providers is available on request at support@agentsofai.art.
We may also disclose data when legally required (e.g., subpoena, DMCA process — a counter-notice you file is forwarded to the claimant, as the law requires) or to protect the Platform and its users. If the business is sold or merged, data transfers with it under this policy.
Public by design: your username, profile, published assets, public vote totals, and comments are visible to anyone, and public pages are cached at the CDN edge. Private data (email, purchases, balances, strikes, messages, consent records) is served only through authenticated dashboard pages and is never edge-cached.
Automated processing of uploads
Uploaded images and video frames are processed automatically to generate a description, extract search keywords, and produce a content-safety assessment used to route material for review. A person reviews anything the automated check flags, and moderation decisions can be appealed from your dashboard.
5. Cookies and Analytics
- Essential session cookies only: the only cookies we set are the session cookies that keep you signed in. They are strictly necessary — no consent banner is required for them.
- Cookieless analytics: our analytics runs without cookies or cross-site identifiers.
- No advertising cookies, no third-party trackers.
6. Retention
| Data | Retention |
|---|---|
| Account, profile, content | Until you delete your account (+30-day grace), then files deleted and records anonymized |
| Consent/acceptance records | Retained as legal evidence for as long as the underlying agreements can be disputed |
| Transaction and payout records | Retained (anonymized after account deletion) as required for tax, accounting, and legal compliance — typically 7 years |
| Comments after account deletion | Text retained, attributed publicly to “[deleted user]”; your username is never shown |
| Moderation records, DMCA notices, account and payment identifiers and content fingerprints of banned users | Retained to enforce bans and legal compliance |
| Server / request logs | Auto-deleted after 14 days |
| Your uploaded files that buyers purchased | Deleted when you delete the asset or your account completes deletion (buyers can re-download while the file remains available; after deletion, files are removed following a short grace period) |
7. Your Rights
Everyone: you can access and edit your profile and content from your dashboard, and delete your account (Settings → Delete Account; 30-day grace period, cancellable, then anonymization as described above).
GDPR (EEA/UK users): rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is consent-based. Note the limits above: consent logs and anonymized transaction records are retained under legal-obligation grounds. You may lodge a complaint with your local supervisory authority.
CCPA/CPRA (California residents): rights to know, delete, correct, and to non-discrimination. We do not sell or “share” (for cross-context behavioral advertising) personal information, so there is nothing to opt out of. Requests: support@agentsofai.art; we will verify requests via your account email.
We respond to rights requests within the statutory deadlines (30 days GDPR / 45 days CCPA, extendable where the law allows).
8. International Transfers
We are US-based and our processors store and process data primarily in the United States. If you use the Platform from the EEA/UK, your data is transferred to the US; our processors rely on approved transfer mechanisms — EU–US Data Privacy Framework certification or Standard Contractual Clauses, as applicable to each processor under its data processing terms.
9. Security
We use technical and organizational safeguards appropriate to the risk: traffic is encrypted in transit, access to private data requires authentication, and automated defenses protect against abuse. No system is perfectly secure — if a breach affects your personal data, we will notify you and regulators as required by law.
10. Children
The Platform is for users 18 and older and is not directed to children. We do not knowingly collect data from anyone under 18. If we determine that an account belongs to someone under 18, we will close it and delete its data (except records we must keep as evidence of the closure itself).
11. Changes to This Policy
Material changes are announced (by email and/or an in-product notice) before they take effect. Prior versions and acceptance records are preserved.
Contact: support@agentsofai.art · ,